// Methodology

HOW WE
DECIDE.

Every TrustSniffer verdict is built the same way: collect evidence, weigh it with documented rules, produce a score, and land on a clear band, with the reasons shown. No mystery numbers. Here's the method behind both the website and the wallet engines.

// Evidence to verdict

Signals in, one honest score out.

Scoring engine
weighted · deterministic · evidence-backed
Archive & age
+14
TLS certificate
+7
DNS & infra
−9
Behavior sandbox
−16
Threat intel · VT/GSB
−31
Reputation · IP
−6
Trust score
0
/ 100
HIGH
MOD
LOW
CRIT
REVIEW

Illustrative example, sample signals and weights, not a real report.

// Website verdicts

Capture, rules, score, verdict.

01

Capture

Eight modules collect evidence, page, behavior, archive, DNS, certificate/WHOIS, threat intel, and more. See coverage.

02

Rules

Deterministic, documented rules weigh each signal. It is not a single black-box AI call, the logic is repeatable.

03

Score

Signals combine into a 0–100 trust score plus a confidence level, with the contributing reasons retained.

04

Verdict

The score lands on a band and a plain-English verdict, published with the evidence behind it.

Website trust bands (0–100)
HIGH
≥ 75
MODERATE
50–74
LOW
25–49
CRITICAL
< 25
NEEDS REVIEW
blocked / thin

A blocked, challenged, or content-thin capture is graded NEEDS REVIEW, never CRITICAL, a temporarily unavailable but legitimate site is never mislabeled a scam. Scoring today is rule-based; machine-learning calibration is held until its dataset is ready.

// Wallet verdicts

Roots, taint, exposure.

How a wallet is scored

We start from known bad roots, sanctioned and scam-linked addresses and issuer-freeze records, then trace how funds flow to and from an address (taint propagation and exposure). Verdicts land on CLEAR · CAUTION · WARN · DANGER · BLOCK, with the connecting evidence (paths, amounts, distance) attached.

Flag vs. confirmed

A flag is an early risk signal, high exposure or a freeze candidate, often ahead of any freeze. A confirmed freeze/unfreeze is an on-chain issuer event with transaction and block evidence. Monitoring alerts on both. A freeze reflects status at a point in time and an issuer can reverse it.

// Principles

The rules behind the rules.

Evidence-first

Every verdict cites the reasons behind it. If we can't show why, we don't assert it.

Deterministic

The same evidence yields the same logic. AI assists wording, not the hard verdict.

Fail-safe

Missing or blocked evidence lowers confidence and routes to review, it never invents a harsh verdict.

Fresh & re-checked

Results can change as new on-chain events, source data, and re-scans arrive.

// What a verdict is not

A TrustSniffer result is a probabilistic, informational assessment from the evidence we could collect at the time, not proof of fraud, not a guarantee of safety, and not legal, financial, or compliance advice. Read it alongside our disclaimer, and see exactly what we support on the coverage page.

See the method in action.

Run a check and read the reasons behind the verdict for yourself.