Trust Methodology

Exactly how DYOE verifies trust.

We're the safety check an AI agent runs before it pays. Trust only works if you can see how it's earned — so here's every signal we use, what our verdicts mean, where our limits are, and how we handle mistakes. No black box.

The one job

Before an autonomous agent (or a person) trusts, pays, or transacts with an unknown website, wallet, or store, DYOE answers one question: is this safe? We return a clear verdict, the evidence behind it, and a cryptographic signature so anyone can verify we really said it.

The signals we check

Every verdict is built from hard, independently-checkable facts — not opinion, not a hidden model.

SignalSourceWhy it matters
Domain ageRDAP registry (authoritative)A brand-new domain (<30 days) is the #1 scam signal.
HTTPS & reachabilityLive fetchReal businesses secure and serve their site.
Content & contact signalsThe page itselfLegit sites are contactable and coherent; bot-protection is treated as neutral, not guilt.
OFAC sanctions (wallets)US Treasury SDN listAn agent must never pay a sanctioned address — legal and safety-critical.
On-chain footprint (wallets)Public blockchain RPCAn empty, never-used address is a disposable-wallet red flag.
Reputation historyDYOE's own logged assessmentsA track record that compounds — a credit score for counterparties.
Human vouchDYOE's verified-human registryThe highest signal: a real, accountable person stands behind it.

What the verdicts mean

safe / proceed  Hard anchors check out (established domain, HTTPS, no sanctions/flags). Reasonable to proceed.

caution  Something's unproven or thin — new domain, couldn't fully read the site, or an amount over policy. Slow down; consider a human sign-off.

avoid / stop  A hard red flag — no HTTPS, brand-new + broken, or an OFAC-sanctioned wallet. Do not proceed.

Every verdict is verifiable — that's the point

Each result is returned as a signed attestation (EIP-191, secp256k1). Anyone can recover the signature to DYOE's published authority address and prove we issued that exact verdict — it can't be forged or altered. Pin our signer at /authority; check any credential at /credential/verify. We publish the methodology and the proof.

Our limits — stated plainly

Our automated trust score is a signal, not a guarantee. It's built from real facts, but a sophisticated scammer can age a domain and add HTTPS to look legitimate on a cheap check. We will never tell you something is "certified safe." That honesty is the point — and it's exactly why the highest tier is a real human who reviews the consequential decisions and signs their name to it. Cheap automated checks for volume; a human for what matters.

How we handle mistakes

We will get calls wrong. When we do: the verdict is timestamped and signed, so it's auditable; reputation updates as new evidence comes in (a verdict is a point-in-time read, not a permanent label); and a human review can override an automated verdict. We'd rather be transparent and correctable than confidently wrong.

Priced on consequence

A trust check costs pennies because an agent runs it constantly. A human sign-off costs more because a person is accountable for it. You pay for the level of certainty the decision deserves — not a flat fee for a black box.