Methodology
How we decide what to tell you
Every report is built from evidence — measurable facts, detected warning signals, honest unknowns — and the score is computed by a deterministic algorithm, not by an AI's opinion. This page documents exactly how, generated from the same signal registry the scanner runs.
What we check
- Domain history — registration and expiry dates via public RDAP registry data, registrar, privacy-proxy use, internationalized-name (homograph) risks, suspicious name patterns.
- Technical & security — HTTPS and certificate validity (direct TLS inspection), redirect behavior, security headers, DNS mail configuration (MX, SPF, DMARC) via DNS-over-HTTPS.
- Company identity — company details published on the site (imprint, contact, terms, privacy pages), cross-page consistency, contact quality, and verification against official registers: the Swiss Zefix index, UK Companies House, and EU VIES VAT validation. Jurisdictions without a supported register are reported as Unknown, never as negative.
- Website consistency — essential policies, placeholder content, mixed currencies or languages, pressure tactics, copied legal text.
- Reputation — independent web mentions, classified conservatively into counts of positive and negative experiences. Scored only when a search provider is configured; otherwise shown as ⚪ Unknown.
- Offer plausibility — not scored yet; appears as ⚪ Unknown and is excluded from the score entirely rather than silently counted.
How the score works
Each finding maps to a signal with a fixed impact between −1 and +1 and a confidence factor (low 0.35, medium 0.7, high 1.0). Per category:
category = clamp(0.5 + Σ(impact × confidence × 0.35), 0, 1) score = weighted mean over evaluated categories × 100 (trust-score-v1.4)
0.5 is the neutral baseline. Categories with no evaluable signals are excluded from the weighted mean — an unknown never lowers a score. The algorithm version is stored with every scan so older reports remain interpretable.
80–100🟢 Strong trust signals
60–79🟢 Generally trustworthy
40–59🟡 Proceed with caution
20–39🟠 Significant concerns
0–19🔴 High risk
Every signal we score
57 signals in trust-score-v1.4. Positive impacts add trust; negative impacts reduce it; zero-impact entries only document unknowns.
| Signal | Category | Impact |
|---|---|---|
| BUYER_IDENTITY_CONFLICT | Company identity | 0 |
| BUYER_REGISTRY_CONFLICT | Company identity | 0 |
| BUYER_IDENTITY_COMPARISON | Company identity | 0 |
| BUYER_REGISTRY_COMPARISON | Company identity | 0 |
| BUYER_DETAILS_REUSE | Company identity | 0 |
| BUYER_DETAILS_SEARCH | Company identity | 0 |
| DOMAIN_AGE_VERY_NEW | Domain history | -0.9 |
| DOMAIN_AGE_NEW | Domain history | -0.5 |
| DOMAIN_AGE_RECENT | Domain history | -0.2 |
| DOMAIN_AGE_ESTABLISHED | Domain history | +0.4 |
| DOMAIN_AGE_MATURE | Domain history | +0.8 |
| DOMAIN_EXPIRY_SOON | Domain history | -0.3 |
| DOMAIN_IDN_HOMOGRAPH | Domain history | -0.7 |
| DOMAIN_SUSPICIOUS_PATTERN | Domain history | -0.4 |
| DOMAIN_PRIVACY_PROXY | Domain history | -0.1 |
| DOMAIN_AGE_UNKNOWN | Domain history | 0 |
| HTTPS_MISSING | Technical & security signals | -1 |
| CERT_INVALID_OR_EXPIRED | Technical & security signals | -0.9 |
| HTTPS_VALID | Technical & security signals | +0.6 |
| CERT_ORG_VALIDATED | Technical & security signals | +0.4 |
| REDIRECT_CHAIN_SUSPICIOUS | Technical & security signals | -0.6 |
| SECURITY_HEADERS_PRESENT | Technical & security signals | +0.2 |
| DNS_MX_MISSING | Technical & security signals | -0.2 |
| DNS_SPF_DMARC_PRESENT | Technical & security signals | +0.15 |
| THREAT_LISTED | Technical & security signals | -1 |
| SITE_BLOCKS_AUTOMATED_CHECKS | Technical & security signals | 0 |
| THREAT_CHECK_CLEAR | Technical & security signals | 0 |
| IDENTITY_COMPLETE | Company identity | +0.7 |
| IDENTITY_PARTIAL | Company identity | +0.2 |
| IDENTITY_MISSING | Company identity | -0.8 |
| IDENTITY_INCONSISTENT_NAMES | Company identity | -0.5 |
| IDENTITY_VAT_FORMAT_VALID | Company identity | +0.3 |
| IDENTITY_REG_NUMBER_PRESENT | Company identity | +0.3 |
| CONTACT_FREEMAIL_FOR_COMPANY | Company identity | -0.3 |
| CONTACT_PHONE_PRESENT | Company identity | +0.15 |
| IDENTITY_COPYRIGHT_MISMATCH | Company identity | -0.4 |
| IDENTITY_REGISTRY_VERIFIED | Company identity | +0.8 |
| IDENTITY_REGISTRY_NOT_FOUND | Company identity | -0.3 |
| IDENTITY_VAT_VERIFIED | Company identity | +0.4 |
| IDENTITY_VAT_INVALID | Company identity | -0.5 |
| IDENTITY_CERT_ORG_REGISTERED | Company identity | +0.6 |
| IDENTITY_UNVERIFIED_NO_REGISTRY | Company identity | 0 |
| REPUTATION_NO_MENTIONS | Reputation | -0.2 |
| REPUTATION_LIMITED | Reputation | -0.1 |
| REPUTATION_ESTABLISHED | Reputation | +0.6 |
| REPUTATION_MIXED | Reputation | -0.3 |
| REPUTATION_NEGATIVE_PATTERN | Reputation | -0.6 |
| POLICY_PAGES_PRESENT | Website consistency | +0.5 |
| POLICY_MISSING_ESSENTIAL | Website consistency | -0.6 |
| POLICY_MISSING_NON_SHOP | Website consistency | -0.15 |
| POLICY_COMPANY_MISMATCH | Website consistency | -0.8 |
| CONTENT_PLACEHOLDER_TEXT | Website consistency | -0.7 |
| CONTENT_MIXED_CURRENCY_LANGUAGE | Website consistency | -0.3 |
| CONTENT_URGENCY_SCARCITY | Website consistency | -0.4 |
| CONTENT_COPIED_LEGAL_TEXT | Website consistency | -0.3 |
| CONTENT_STRUCTURE_PROFESSIONAL | Website consistency | +0.3 |
| CONTENT_ANALYSIS_UNAVAILABLE | Website consistency | 0 |
Where AI is involved — and where it isn't
AI does
- extract company details from page text
- classify content red flags into fixed categories
- describe visual patterns in images
- write the plain-language summary
AI never
- sets or adjusts the trust score
- determines domain age, DNS or certificates
- declares anything a scam
- overrides collected evidence
AI-text analysis
“Is This AI?” text verdicts come from three independent signals, each shown transparently in the report:
- Statistical analysis — burstiness (variation in sentence length; human writing varies more), vocabulary diversity, repeated phrases, punctuation variety, and the density of AI-typical stock phrases.
- Language-model perplexity — we run a small language model (distilgpt2) on our own servers and measure how predictable the text is to it. AI-generated text is typically far more predictable than human writing. English only; other languages report as inconclusive rather than guessing.
- Style review — a language model checks for characteristics commonly associated with AI-assisted writing.
One signal alone never produces more than “Some AI-like characteristics”; the strongest verdict requires independent signals to agree, and no percentage scores are ever shown. Text AI detection must not be the sole basis for academic, employment, legal or disciplinary decisions.
AI-image analysis
“Is This AI?” verdicts follow a strict evidence hierarchy: cryptographically verified C2PA Content Credentials outrank generator metadata (Midjourney, Stable Diffusion, Firefly, DALL-E markers), which outrank coherent camera EXIF, which outranks visual observations by a vision model. Visual observations alone can never produce more than “Probably AI-generated” at medium confidence, and results are never presented as proof. Detector placeholders that are not configured are clearly marked and ignored by the verdict.
Sources we verify against
Every company-identity and domain check resolves against these public registers and specifications. We link them so you can repeat any check yourself.
- RDAP (Registration Data Access Protocol) — registration and expiry dates, registrar, privacy-proxy use
- Zefix — Swiss Central Business Names Index — Swiss company register verification
- UK Companies House — UK company register verification
- EU VIES VAT validation — EU VAT number validation
- C2PA Content Credentials — cryptographically signed provenance for AI-image checks
- DNS-over-HTTPS (RFC 8484) — MX, SPF and DMARC mail configuration lookups
Limitations & independence
- A high score is evidence-based reassurance, not a guarantee; a low score is a set of concerns, not an accusation.
- Some registries (certain country domains) don't expose registration data — those lookups become Unknown, not negative.
- Sites behind aggressive bot protection may only be partially analysable; reports say so explicitly.
- Trust scores cannot be bought. There is no paid way to improve a score, and there never will be.
- Site owners can dispute findings — contact us with verifiable documentation and we'll re-examine the evidence.