Methodology
How we decide what to tell you
Every report is built from evidence — measurable facts, detected warning signals, honest unknowns — and the score is computed by a deterministic algorithm, not by an AI's opinion. This page documents exactly how, generated from the same signal registry the scanner runs.
What we check
- Domain history — registration and expiry dates via public RDAP registry data, registrar, privacy-proxy use, internationalized-name (homograph) risks, suspicious name patterns.
- Technical & security — HTTPS and certificate validity (direct TLS inspection), redirect behavior, security headers, DNS mail configuration (MX, SPF, DMARC) via DNS-over-HTTPS.
- Company identity — company details published on the site (imprint, contact, terms, privacy pages), cross-page consistency, contact quality, and verification against official registers: the Swiss Zefix index, UK Companies House, and EU VIES VAT validation. Jurisdictions without a supported register are reported as Unknown, never as negative.
- Website consistency — essential policies, placeholder content, mixed currencies or languages, pressure tactics, copied legal text.
- Reputation — independent web mentions, classified conservatively into counts of positive and negative experiences. Scored only when a search provider is configured; otherwise shown as ⚪ Unknown.
- Offer plausibility — not scored yet; appears as ⚪ Unknown and is excluded from the score entirely rather than silently counted.
How the score works
Each finding maps to a signal with a fixed impact between −1 and +1 and a confidence factor (low 0.35, medium 0.7, high 1.0). Per category:
category = clamp(0.5 + Σ(impact × confidence × 0.35), 0, 1) score = weighted mean over evaluated categories × 100 (trust-score-v1)
0.5 is the neutral baseline. Categories with no evaluable signals are excluded from the weighted mean — an unknown never lowers a score. The algorithm version is stored with every scan so older reports remain interpretable.
80–100🟢 Strong trust signals
60–79🟢 Generally trustworthy
40–59🟡 Proceed with caution
20–39🟠 Significant concerns
0–19🔴 High risk
Every signal we score
46 signals in trust-score-v1. Positive impacts add trust; negative impacts reduce it; zero-impact entries only document unknowns.
| Signal | Category | Impact |
|---|---|---|
| DOMAIN_AGE_VERY_NEW | Domain history | -0.9 |
| DOMAIN_AGE_NEW | Domain history | -0.5 |
| DOMAIN_AGE_RECENT | Domain history | -0.2 |
| DOMAIN_AGE_ESTABLISHED | Domain history | +0.4 |
| DOMAIN_AGE_MATURE | Domain history | +0.8 |
| DOMAIN_EXPIRY_SOON | Domain history | -0.3 |
| DOMAIN_IDN_HOMOGRAPH | Domain history | -0.7 |
| DOMAIN_SUSPICIOUS_PATTERN | Domain history | -0.4 |
| DOMAIN_PRIVACY_PROXY | Domain history | -0.1 |
| DOMAIN_AGE_UNKNOWN | Domain history | 0 |
| HTTPS_MISSING | Technical & security signals | -1 |
| CERT_INVALID_OR_EXPIRED | Technical & security signals | -0.9 |
| HTTPS_VALID | Technical & security signals | +0.6 |
| CERT_ORG_VALIDATED | Technical & security signals | +0.4 |
| REDIRECT_CHAIN_SUSPICIOUS | Technical & security signals | -0.6 |
| SECURITY_HEADERS_PRESENT | Technical & security signals | +0.2 |
| DNS_MX_MISSING | Technical & security signals | -0.2 |
| DNS_SPF_DMARC_PRESENT | Technical & security signals | +0.15 |
| IDENTITY_COMPLETE | Company identity | +0.7 |
| IDENTITY_PARTIAL | Company identity | +0.2 |
| IDENTITY_MISSING | Company identity | -0.8 |
| IDENTITY_INCONSISTENT_NAMES | Company identity | -0.9 |
| IDENTITY_VAT_FORMAT_VALID | Company identity | +0.3 |
| IDENTITY_REG_NUMBER_PRESENT | Company identity | +0.3 |
| CONTACT_FREEMAIL_FOR_COMPANY | Company identity | -0.3 |
| CONTACT_PHONE_PRESENT | Company identity | +0.15 |
| IDENTITY_COPYRIGHT_MISMATCH | Company identity | -0.4 |
| IDENTITY_REGISTRY_VERIFIED | Company identity | +0.8 |
| IDENTITY_REGISTRY_NOT_FOUND | Company identity | -0.5 |
| IDENTITY_VAT_VERIFIED | Company identity | +0.4 |
| IDENTITY_VAT_INVALID | Company identity | -0.5 |
| IDENTITY_UNVERIFIED_NO_REGISTRY | Company identity | 0 |
| REPUTATION_NO_MENTIONS | Reputation | -0.2 |
| REPUTATION_LIMITED | Reputation | -0.1 |
| REPUTATION_ESTABLISHED | Reputation | +0.6 |
| REPUTATION_MIXED | Reputation | -0.3 |
| REPUTATION_NEGATIVE_PATTERN | Reputation | -0.7 |
| POLICY_PAGES_PRESENT | Website consistency | +0.5 |
| POLICY_MISSING_ESSENTIAL | Website consistency | -0.6 |
| POLICY_COMPANY_MISMATCH | Website consistency | -0.8 |
| CONTENT_PLACEHOLDER_TEXT | Website consistency | -0.7 |
| CONTENT_MIXED_CURRENCY_LANGUAGE | Website consistency | -0.3 |
| CONTENT_URGENCY_SCARCITY | Website consistency | -0.4 |
| CONTENT_COPIED_LEGAL_TEXT | Website consistency | -0.3 |
| CONTENT_STRUCTURE_PROFESSIONAL | Website consistency | +0.3 |
| CONTENT_ANALYSIS_UNAVAILABLE | Website consistency | 0 |
Where AI is involved — and where it isn't
AI does
- extract company details from page text
- classify content red flags into fixed categories
- describe visual patterns in images
- write the plain-language summary
AI never
- sets or adjusts the trust score
- determines domain age, DNS or certificates
- declares anything a scam
- overrides collected evidence
AI-image analysis
“Is This AI?” verdicts follow a strict evidence hierarchy: cryptographically verified C2PA Content Credentials outrank generator metadata (Midjourney, Stable Diffusion, Firefly, DALL-E markers), which outrank coherent camera EXIF, which outranks visual observations by a vision model. Visual observations alone can never produce more than “Probably AI-generated” at medium confidence, and results are never presented as proof. Detector placeholders that are not configured are clearly marked and ignored by the verdict.
Limitations & independence
- A high score is evidence-based reassurance, not a guarantee; a low score is a set of concerns, not an accusation.
- Some registries (certain country domains) don't expose registration data — those lookups become Unknown, not negative.
- Sites behind aggressive bot protection may only be partially analysable; reports say so explicitly.
- Trust scores cannot be bought. There is no paid way to improve a score, and there never will be.
- Site owners can dispute findings — contact us with verifiable documentation and we'll re-examine the evidence.