Privacy and suppression

The Index publishes only pooled aggregates, suppresses small cohorts, and withholds figures that could expose one peer.

Last updated September 22, 2026

The Pytheus Index becomes available to your organization once your cohort has enough participants for the comparison to be anonymous. Until then the surface may not appear in your dock. Your Pytheus contact can tell you where your cohort stands.

The Pytheus Index is built so that contributing to a peer cohort never exposes your posture to anyone else, and so that no other organization's posture is exposed to you.

Pooled aggregates only

When the Index compares you to your cohort, it shows pooled aggregates: a median, quartiles, a distribution shape. No peer's individual scores, capabilities, or spend are ever shown. No peer identity leaves the aggregation layer. The comparison flows from the group to you, never from one organization to another.

Suppression below a minimum sample

A cohort is suppressed until it reaches a minimum number of participating organizations. This protects the members of small cohorts, where a handful of records could otherwise be teased apart. A cohort can also raise its own threshold above the default, never lower it.

Withholding the extremes

Even within a live cohort, the exact minimum and maximum scores are not published, because at small cohort sizes the extremes are effectively two individual organizations' numbers. The Index publishes the median and quartiles and a distribution, which describe the group without revealing its edges.

Labeled and dated

Every comparison carries the date of the underlying snapshot and the methodology version behind it, so you always know how current and how derived a figure is.

Anonymization is not just a promise here. It is enforced by suppression thresholds and by withholding the figures that could single a peer out.

The cohort construction that this protects is described in How cohorts are built. For the broader tenant boundary, see Benchmark privacy.