CoverageReportsCalendarReproducibilityContactVerlumia Intelligence ES EN FR
verlumia Support
Doctrine · principles & method · doesn't change monthly

Sources & Criteria

Where our figures come from

Every number in the index comes from an official source we name. And we do something unusual: we also publish the sources we evaluated and decided not to use, with the criterion that left them out.

In one line

Three institutions, zero invention

Today three Mexican state institutions feed the index: the SESNSP, INEGI and CONDUSEF. No figure comes from anything else —not a market estimate, not artificial intelligence—. And unlike almost everyone, we also publish what we evaluated and did not use: that is the part that gives certainty to what we do publish.

Where each figure comes from

Each pillar, with its source

Every figure you'll see has a clearly identified source. This is where each one comes from:

Citizen fraud monthly Grade A · measured truth
The source

SESNSP · RNID — headline. The national registry of fraud investigation case files.

CONDUSEF — contrast. Its complaints index (open CSV) is checked once a year against the trend.

In plain words

The fraud number is the official count of investigation case files that SESNSP publishes each month. It is a counted fact, not an estimate — that's why it's the only one painted teal.

Cyberbullying annual Grade B · survey (CI90)
The source

INEGI · MOCIBA — headline. The Cyberbullying Module, the national survey with which INEGI measures how many people experienced cyberbullying. Comparable series 2021–2024.

In plain words

The cyberbullying figure comes from MOCIBA, a survey. That's why it's an estimate with a stated margin, not a count — and it's not painted teal. Saying "survey" instead of "count" is part of the honesty.

Data exposure · Defense pending in incubation
The source

No stable official source that meets the criterion, after the wind-down of INAI and the IFT.

In plain words

These two dimensions still have no reliable source that can support measurement. We say so openly instead of forcibly filling them in: a declared gap is more honest than an invented number.

One more dimension, direct cyber-harm (remote crimes: extortion by other means and identity impersonation), is already measured from its 2026 baseline (grade A, RNID) but is not yet published: the category is new in the official registry and has no comparable series. It will be published as ICC/2.0 once enough time has passed to support a meaningful comparison. To measure is not to publish.

The criterion

Criteria a source must meet

Being a government source is necessary, but not enough: to feed a figure, a source must also be reproducible and comparable. It enters only if it meets all five inclusion criteria; it is set aside —and the reason documented— if it meets any exclusion criterion.

Inclusion · meet all

  1. Official status or clear license. Official source or open data with an explicit license, cited in the lineage.
  2. Reproducibility. Anchorable by hash and in a processable format. A PDF is not a data source.
  3. Comparable universe. Declared, stable base population; if it changes, it is documented and continuity is not forced.
  4. Neutral aggregability. Data aggregable at the system level, without scoring individual entities.
  5. Institutional continuity. The stability of the producer is evaluated; if at risk, it is admitted with a caveat, never in silence.

Exclusion · any one suffices

  1. No institutional continuity (the institution dissolved or ceased production).
  2. Format not auditable as data (e.g. PDF only, with no processable, anchorable series).
  3. Non-comparable universe (experimental methodology or incompatible denominator).
  4. Generative AI as a source — it violates the first principle and is never allowed.
  5. Neutrality risk (it would force scoring or exposing entities on the public face).
Why it enters here and not there

Three bodies, three questions

The same official institution may enter the index with one product and stay out with another. The deciding factor is never the institution's name or prestige, but a concrete question about the file it publishes.

CONDUSEFCan it be reproduced?

It publishes two different things. Its complaints index comes in an open, processable file: it can be sealed with its digital fingerprint and recomputed anytime — that's why it enters, as an annual fraud contrast. Its quarterly cyber-fraud bulletin comes as a PDF only: there is no series to anchor or recompute — that's why that product does not enter the data, even though it comes from exactly the same body. What separated one from the other was not CONDUSEF; it was whether that specific file can be audited.

The source that can be reproduced enters, not the one with the better letterhead.

INEGI · MOCIBACan it be compared over time?

INEGI has run its cyberbullying survey several times. The 2021 to 2024 editions ask about the same population and with the same time window: they are comparable to each other, so they form the series we publish. Those of 2015 to 2017 were experimental exercises with a different base; mixing them would break the year-over-year comparison. It's not that they are "bad" — it's that they don't line up. That's why the same survey enters with some editions and not others.

A figure is only worth something if it can be compared with last year's.

INAIWill it keep existing?

INAI recorded personal-data breaches — precisely the Exposure dimension we lack today. But the body was dissolved in 2025: there is no longer anyone producing that data continuously. Here a product is not set aside for its format; the entire source is lost. That's why Exposure remains a declared gap —open, in plain sight— until another institution takes up that measurement. It is the only case in which a whole body is set aside.

We measure series, not stray snapshots; without continuity there is no series.

Three bodies, three different questions — can it be reproduced? can it be compared over time? will it keep existing? None is answered by looking at the institution's logo. That is, exactly, the criterion in action.

The complete register — Mexico

What we use, what we discard, what we await

The real registry, sealed in v1.0 of the criterion (ACTA-031). The same institution may feed the index with one product and be set aside on another: what is evaluated is the specific file, not the institution's name.

Included — they feed the index3
SESNSP · RNID A
Registry of fraud investigation case files. Monthly headline of the fraud pillar.
CONDUSEF · complaints index
CSV with an open license (CC-BY). Annual fraud contrast, not additive with the RNID.
INEGI · MOCIBA 2021-2024 B
National cyberbullying survey. Annual headline of the cyberbullying pillar, with a 90% confidence interval.
Discarded — with documented reason4
INAI
Data exposure (breach notifications). No institutional continuity — the institution dissolved in 2025. Permanent discard. It is the only case in which a whole institution is set aside, not a product.
CONDUSEF · "Cyber fraud" channel
Quarterly product. Format not auditable — PDF, no anchorable series. CONDUSEF itself does feed the fraud contrast with its complaints index.
INEGI · MOCIBA 2015-2017
Cyberbullying, historical editions. Non-comparable universe — experimental exercises that don't line up with the series. The same MOCIBA 2021-2024 is the current cyberbullying pillar.
INEGI · MOCIBA 2019-2020
Cyberbullying, intermediate editions. Legacy format (.xls) + unverified universe.
Declared gap — awaiting a source2
Exposure · Defense
Two sub-dimensions of the index with no stable official source after the wind-down of INAI and the IFT. Declared in incubation; not published nor forcibly filled. A partial, honest index is worth more than a complete, forced one (principle 5).

Every figure and decision at Verlumia is governed by five guiding principles. This register puts the third principle into practice: auditability runs end to end, from source selection to the figure — shown as method, "this we use, this we don't, and why," never as a superlative. The same criterion applies in every country that replicates the index. Want the explained version? Read "Which sources we use and which we discard" (grade C · outreach).