Three independent outputs
CHECKED never compresses identity, danger, and certainty into one unexplained score. The source status describes the relationship to the claimed project. The risk status describes detected danger. Confidence describes how complete and mutually reinforcing the evidence is.
| Dimension | States | Meaning |
|---|---|---|
| Source status | Verified match · Partial match · Source mismatch · Unknown | Whether the submitted entity belongs to the claimed project. |
| Risk status | No known risk · Caution · High risk · Confirmed threat | The severity of technical, identity, behavioural, and threat-intelligence signals. |
| Confidence | High · Medium · Low | How complete, current, attributable, and consistent the evidence is. |
Relationship before reputation
The verification engine prioritises direct control proofs and relationship evidence: DNS challenges, wallet signatures, Telegram administrator challenges, X account control, contract deployer or owner relationships, multisig approvals, and published project records. Threat feeds and community reports add context but do not automatically create a verdict.
| Layer | Examples |
|---|---|
| Identity | X accounts, Telegram identities, domains, support roles, operators. |
| Claim consistency | Contracts, wallets, deadlines, destinations, migration or claim language. |
| Onchain | Deployer, owner, proxy, permissions, multisig, token movement. |
| Continuity | Profile changes, DNS changes, redirects, admin or signer changes. |
| Threat intelligence | Known malicious addresses, phishing infrastructure, attack fingerprints. |
AI does the reading
Models extract claims, identify entities, compare wording, cluster known scam templates, translate submissions, and explain technical evidence in plain language. Model output is never treated as a source. A factual finding must resolve to stored evidence or remain explicitly uncertain.
No “safe” guarantee
CHECKED uses “no known risk detected” rather than “safe.” Public data can be incomplete, projects can change, security providers can disagree, and malicious behaviour can appear after a result is issued. Every report includes evidence freshness, coverage, and material unknowns.
Minimum necessary context
Guest checks retain only the context required to resolve the submission. Private Telegram messages are not automatically published. Public case pages redact personal information and expose only evidence that is lawful, attributable, and necessary for the conclusion.
Corrections remain visible
Material public findings support project response, correction requests, human review, version history, and visible retractions. A trust product earns credibility by documenting how it changes its mind.
