Every Torii industry page shares one layout and one section order. Only the content changes from one industry to the next: the headline framing, the customer proof, the benchmark figures, and the three pressures in "What your customers make you prove." The structure is fixed on purpose. It is ordered by evidence, not by art direction.
The application counts, the shadow-IT rate and the AI-spend growth all come from Torii's own internal data, aggregated and anonymized. Torii's 2026 SaaS Benchmark is one example of that data; in other cases a figure is sourced live, from current discovery rather than a fixed reporting window.
We count applications found through browser activity, OAuth grants and direct sign-ups, not only the ones visible in spend or SSO, which is why our figures run higher than licence-based benchmarks. Where a figure is an all-industry average rather than a software-specific one, we label it that way on the page itself.
Every content element on the page is tagged with one of three scopes. This is what changes, and what never does:
Every standard, framework or contract term we quote links to a primary source, and carries the date we last verified it. Three rules we hold ourselves to:
Torii produces and maintains the inventory these obligations start from. It does not file your register or write your subprocessor list. It will not find the infrastructure your engineers chose, such as hosting, telemetry, or the model API your backend calls, because no employee "uses" those. What it finds is the other half: the tools your own staff adopted, increasingly AI tools, that touch customer data and are not on the list you published.
These figures are averages, not a promise about your environment. Your numbers are what the two-week, read-only discovery is for.