A verifiable trust layer for Web3
A manipulation-resistant, multi-dimensional reputation system — the design, and why it resists gaming from both sides.
Abstract
Ratify is an open reputation platform where individuals — founders, developers, designers, collab managers, moderators, community builders — present themselves, register their projects, and build a credible trust profile from traceable, weighted reviews. It provides the reliable trust layer Web3 chronically lacks: who is genuinely reputable, who delivers, who pays, which projects are ambitious and transparent — and which are not.
The central claim — and the central technical challenge — is two-sided manipulation resistance: nobody may inflate their own score (Sybil attacks, bought reviews, collusion rings), and nobody may unfairly destroy another's (review-bombing, retaliation, extortion). This is a high-level overview of the model engineered for exactly that; the precise scoring parameters are kept confidential as an anti-gaming measure.
Contents
1. The problem
In Web3, trust is expensive and badly distributed:
- Service providers are a black box. Founders engage people they can barely vet. Vanished managers, poor work, and outright fraud are the norm, not the exception.
- Reputation isn't portable. Good work on one project leaves no verifiable trace you can carry into the next.
- Existing rating systems are trivially gamed. Star averages, Discord "vouches", and Twitter clout can be faked with fake accounts, bought followers, and arranged endorsements within hours.
- There is no fair counter-direction. Providers are themselves exposed to clients who don't pay, expand scope endlessly, or threaten bad reviews.
Ratify addresses both sides of this market at once: trustworthiness as a two-sided, verifiable quantity.
2. Solution & vision
Ratify provides the trust layer Web3 otherwise solves informally and unreliably through social networks. Four building blocks:
- Profiles — each person presents themselves, links wallets and social identities, and registers their projects.
- Reputation — a multi-dimensional, weighted score per person and per project, visualised as a traffic light.
- Market — founders post jobs, providers apply, and engagements run through the platform.
- Settlement — payment for a service runs (optionally, but recommended) through the platform; the completed, paid interaction is the basis of the highest-weighted reviews.
The vision: Ratify becomes the standard proof that you are a reliable partner in Web3 — transparent, fair, multi-dimensional, and contestable in the hands of the rated.
3. The reputation system
This is the heart of the platform. A naive star average would be faked in minutes; Ratify uses a layered model in which each layer neutralises a concrete class of attack. The sections below describe the principles — not the exact weights.
3.1 Design principles
- Reputation is earned, not claimed. Only verifiable interactions move the score meaningfully.
- The source counts more than the volume. One review from a trusted person outweighs a hundred from nobodies.
- When in doubt, neutral. Little or weak data yields "grey" — neither good nor bad. New accounts never appear trustworthy automatically.
- Symmetry. Manipulation upward and downward is made hard by the same mechanisms.
- Right of reply. The rated can respond publicly and contest unjustified reviews.
- Rehabilitation. Old reviews lose weight; recent behaviour dominates.
3.2 Identity levels (root defence against Sybil)
Every account has a verification level that determines how much its reviews weigh:
| Level | Requirement | Effect |
|---|---|---|
| L0 | Read-only. Reviews do not count. | |
| L1 | Wallet signature + 1 linked social (X / Discord / GitHub) | Low weight. |
| L2 | Multiple socials + at least one interaction settled through the platform | Normal weight. |
| L3 | KYC-verified identity (required to receive payments) | Highest weight, "Verified Identity" badge. |
Account standing draws on the age and activity of linked identities — an old but empty or bought account contributes little. Identity alone can only lift an account out of grey; it is a precondition for trust, never trust itself.
In-person verified. Separately from the L0–L3 ladder — and across it, not above it — an account can earn an "in-person verified" badge: a trusted member or the team met the person physically (at an event or meetup) and vouched for their identity. It is a different kind of proof than KYC and one of the strongest anti-Sybil signals, since you cannot fake a thousand people who actually showed up. The voucher is accountable for who they vouch for.
3.3 Provenance & mutually confirmed relationships
Every review hangs on a relationship (an engagement). A relationship appears on a profile only when it is confirmed — by both parties, or by payment proof. This prevents faking association: nobody can unilaterally claim to have worked with a reputable person to borrow their credibility.
Crucial decoupling: what is confirmed is the fact of the relationship, never the judgement. Both parties confirm existence, then review independently and double-blind — positively or negatively. Confirmation raises a review's weight independent of sentiment: a confirmed negative review weighs exactly as much as a confirmed positive one. What is rewarded is verifiability, not goodwill.
Reviews are weighted by provenance, in descending order: verified (mutually confirmed and payment-backed) → attested (mutually confirmed) → unconfirmed (one-sided, clearly labelled) → open reference (no claimed relationship, shown separately as community sentiment). Actively contested reviews are hidden pending moderation.
Solving the veto problem. A pure "both must confirm" rule would give the rated a veto over criticism. Three mechanisms prevent that: a real payment proves the relationship by itself; silence is not a veto (no response makes a relationship "unconfirmed" at reduced weight, not invisible); and only an active dispute hides a review, sending it to moderation where evidence decides.
3.4 Trust graph & weighting
From verified interactions we build a directed trust graph. A reviewer's influence is proportional to the trust they have themselves earned in that graph, propagated from a set of platform-verified anchor nodes (established, reputable founders/organisations). Why this beats Sybil: fake accounts have no incoming trust from legitimate nodes, so their influence stays negligible no matter how many there are. Mass without earned trust is worthless.
3.5 Double-blind reviews
After an engagement, both parties review each other independently. Neither sees the other's review until both submit or a window expires. This neutralises retaliation ("you gave me two stars, so here's two back") and extortion ("rate me well or else") — which fail when you cannot see, and can no longer change, the other verdict.
3.6 Multi-dimensional score & the traffic light
Instead of one easily-gamed number, Ratify rates several dimensions.
For people: reliability · communication · quality · payment behaviour (for clients) · professionalism.
For projects: ambition · transparency · delivery vs roadmap · team · community.
A composite is derived and shown via the traffic light:
| Colour | Meaning |
|---|---|
| Grey | Neutral — or too little data to judge |
| Red | Poor |
| Yellow | Mediocre |
| Green | Good |
| Blue | Outstanding |
Multi-dimensionality raises the bar for manipulation: you'd have to fake consistently across many axes, which is more conspicuous.
3.7 The grey default & confidence
Scores are smoothed toward a neutral default so a handful of reviews don't swing wildly, and every score carries a confidence based on the number and diversity of verified reviews. Below a minimum confidence the profile stays grey, regardless of the raw value. A fresh account cannot appear instantly blue, and a Sybil swarm moves nothing — its reviews carry almost no weight and the confidence from genuine sources is absent.
Proof-of-Economy. A strong, separate signal is the breadth of verified payment history: what matters is the number of distinct, independently reputable paying counterparties — not transaction count or volume — so reputation can't be bought, and paying yourself in circles buys nothing.
3.8 Time decay & rehabilitation
Reviews lose weight over time, so recent behaviour dominates. This enables rehabilitation and reduces the incentive to abandon a "burned" account for a fresh one.
3.9 Anti-collusion & whitewashing
Densely interlinked groups that mostly review each other, sudden review/upvote bursts, and circular ("wash") payment flows are detected and discounted; repeated interactions between the same pair count for steadily less. Whitewashing gains little either: new accounts start grey, receiving payments requires a verified identity that can't be trivially re-minted, and rebuilding verified history is the deterrent. Suspicious patterns trigger a flag for review, not an automatic verdict.
3.10 Disputes & right of reply
The rated person can respond publicly to any review. Reports go to moderation and, where relevant, arbitration; for verified engagements the escrow/milestone history serves as evidence. Reviews that lack a genuine business contact with a named person can be removed.
3.11 Invite-based onboarding
Access is deliberately scarce and tied to trust. The first 100 accounts ("Founding Members") sign up directly; after that Ratify is invite-only — every new member is vouched in by an existing, trusted one. An invitation is itself a trust edge, and inviters are accountable: who you bring in reflects back on you. Mass-inviting fake accounts becomes costly and conspicuous.
3.12 On-chain & portable (Solana)
Ratify is Web3-native: your reputation is anchored on Solana so it's verifiable and portable beyond ratify.cc. The score is still computed off-chain — the manipulation-resistant engine and its parameters stay private — but each score snapshot is published as a non-transferable ("soulbound") attestation other Solana apps can read, to gate access, weight governance, or vet a counterparty. Crucially, only cryptographic commitments (hashes) go on-chain, never personal data or review text: the proof is tamper-evident and portable while the underlying data stays editable and deletable (right of reply, correction, and erasure remain intact). Attestations are issuer-updatable, so decay and corrections are reflected.
4. Project reputation
Projects are their own entities, linked to one or more profiles and rated along their own dimensions (ambition, transparency, delivery, team, community). A founder's reputation and their projects' are linked but kept separate: a project that fails with honest communication should hurt the personal score less than a rug pull.
5. Distribution & integrations
Reputation is valuable where Web3 actually talks: on X, Discord, and Telegram. Rather than forcing people onto ratify.cc, Ratify brings the score to them:
- Browser extension — overlays X, Discord, and Telegram web alike: every avatar gets a traffic-light ring, every profile a hover card.
- Native bots — in the apps, a slash command (/ratify @handle) posts a live verdict card, with an inline mode for quick lookups.
Both read only public profile data.
6. Business model
The platform is free for users. Funding comes from two pillars:
- Transaction fee: 2% on services settled through the platform.
- Premium membership: a reduced fee of 1% instead of 2%, plus one featured listing per month, with further perks over time.
The reduced fee makes Premium economical for active users: above a certain monthly volume, it pays for itself through fee savings alone.
7. Settlement
Ratify never custodies funds. Payment runs either through a licensed marketplace payment provider (which handles custody, KYC/AML, and the licence) or through a non-custodial on-chain escrow that releases stablecoins by milestone — with Ratify's fee taken as an application fee or program-side. The data model carries the necessary fields from day one, so settlement can be added without a rewrite.
8. Governance & transparency
A reputation system must balance transparency (so users trust the score) with opacity (so the algorithm can't be trivially gamed). Ratify's approach: principles public, exact weights and parameters not; per-profile explainability (what a score draws on — verified vs. open sources, number of sources, confidence) without revealing anti-manipulation thresholds; and curated anchor nodes, expanded over time by transparent criteria.
Reputation profiles of real people are personal data, and scoring is a form of profiling. Ratify is built around the corresponding rights — lawful basis, data minimisation, right of reply, correction, deletion — and around meaningful information about the logic of the score, while keeping the exact formula confidential.
9. Roadmap
- Phase 1 — Reputation core: profiles, projects, identity levels L0–L2, invite-based onboarding, double-blind reviews, the reputation engine, the traffic light, jobs & applications, search, right of reply & moderation, SEO-ready public profiles.
- Phase 2 — Settlement & monetisation: non-custodial escrow, KYC/L3, premium membership, featured listings, the fee logic, payment-backed verified reviews and Proof-of-Economy.
- Phase 3 — Hardening & scale: browser extension & chat bots, live collusion detection, dispute arbitration, online trust-graph computation, anchor-node governance, and on-chain attestations on Solana — portable, soulbound reputation.