Whitepaper · light

A verifiable trust layer for Web3

A manipulation-resistant, multi-dimensional reputation system — the design, and why it resists gaming from both sides.

Version 0.1 · June 2026 · Living document

Abstract

Ratify is an open reputation platform where individuals — founders, developers, designers, collab managers, moderators, community builders — present themselves, register their projects, and build a credible trust profile from traceable, weighted reviews. It provides the reliable trust layer Web3 chronically lacks: who is genuinely reputable, who delivers, who pays, which projects are ambitious and transparent — and which are not.

The central claim — and the central technical challenge — is two-sided manipulation resistance: nobody may inflate their own score (Sybil attacks, bought reviews, collusion rings), and nobody may unfairly destroy another's (review-bombing, retaliation, extortion). This is a high-level overview of the model engineered for exactly that; the precise scoring parameters are kept confidential as an anti-gaming measure.

Contents

1. The problem

In Web3, trust is expensive and badly distributed:

Ratify addresses both sides of this market at once: trustworthiness as a two-sided, verifiable quantity.

2. Solution & vision

Ratify provides the trust layer Web3 otherwise solves informally and unreliably through social networks. Four building blocks:

  1. Profiles — each person presents themselves, links wallets and social identities, and registers their projects.
  2. Reputation — a multi-dimensional, weighted score per person and per project, visualised as a traffic light.
  3. Market — founders post jobs, providers apply, and engagements run through the platform.
  4. Settlement — payment for a service runs (optionally, but recommended) through the platform; the completed, paid interaction is the basis of the highest-weighted reviews.

The vision: Ratify becomes the standard proof that you are a reliable partner in Web3 — transparent, fair, multi-dimensional, and contestable in the hands of the rated.

3. The reputation system

This is the heart of the platform. A naive star average would be faked in minutes; Ratify uses a layered model in which each layer neutralises a concrete class of attack. The sections below describe the principles — not the exact weights.

3.1 Design principles

  1. Reputation is earned, not claimed. Only verifiable interactions move the score meaningfully.
  2. The source counts more than the volume. One review from a trusted person outweighs a hundred from nobodies.
  3. When in doubt, neutral. Little or weak data yields "grey" — neither good nor bad. New accounts never appear trustworthy automatically.
  4. Symmetry. Manipulation upward and downward is made hard by the same mechanisms.
  5. Right of reply. The rated can respond publicly and contest unjustified reviews.
  6. Rehabilitation. Old reviews lose weight; recent behaviour dominates.

3.2 Identity levels (root defence against Sybil)

Every account has a verification level that determines how much its reviews weigh:

LevelRequirementEffect
L0EmailRead-only. Reviews do not count.
L1Wallet signature + 1 linked social (X / Discord / GitHub)Low weight.
L2Multiple socials + at least one interaction settled through the platformNormal weight.
L3KYC-verified identity (required to receive payments)Highest weight, "Verified Identity" badge.

Account standing draws on the age and activity of linked identities — an old but empty or bought account contributes little. Identity alone can only lift an account out of grey; it is a precondition for trust, never trust itself.

In-person verified. Separately from the L0–L3 ladder — and across it, not above it — an account can earn an "in-person verified" badge: a trusted member or the team met the person physically (at an event or meetup) and vouched for their identity. It is a different kind of proof than KYC and one of the strongest anti-Sybil signals, since you cannot fake a thousand people who actually showed up. The voucher is accountable for who they vouch for.

3.3 Provenance & mutually confirmed relationships

Every review hangs on a relationship (an engagement). A relationship appears on a profile only when it is confirmed — by both parties, or by payment proof. This prevents faking association: nobody can unilaterally claim to have worked with a reputable person to borrow their credibility.

Crucial decoupling: what is confirmed is the fact of the relationship, never the judgement. Both parties confirm existence, then review independently and double-blind — positively or negatively. Confirmation raises a review's weight independent of sentiment: a confirmed negative review weighs exactly as much as a confirmed positive one. What is rewarded is verifiability, not goodwill.

Reviews are weighted by provenance, in descending order: verified (mutually confirmed and payment-backed) → attested (mutually confirmed) → unconfirmed (one-sided, clearly labelled) → open reference (no claimed relationship, shown separately as community sentiment). Actively contested reviews are hidden pending moderation.

Solving the veto problem. A pure "both must confirm" rule would give the rated a veto over criticism. Three mechanisms prevent that: a real payment proves the relationship by itself; silence is not a veto (no response makes a relationship "unconfirmed" at reduced weight, not invisible); and only an active dispute hides a review, sending it to moderation where evidence decides.

3.4 Trust graph & weighting

From verified interactions we build a directed trust graph. A reviewer's influence is proportional to the trust they have themselves earned in that graph, propagated from a set of platform-verified anchor nodes (established, reputable founders/organisations). Why this beats Sybil: fake accounts have no incoming trust from legitimate nodes, so their influence stays negligible no matter how many there are. Mass without earned trust is worthless.

3.5 Double-blind reviews

After an engagement, both parties review each other independently. Neither sees the other's review until both submit or a window expires. This neutralises retaliation ("you gave me two stars, so here's two back") and extortion ("rate me well or else") — which fail when you cannot see, and can no longer change, the other verdict.

3.6 Multi-dimensional score & the traffic light

Instead of one easily-gamed number, Ratify rates several dimensions.

For people: reliability · communication · quality · payment behaviour (for clients) · professionalism.
For projects: ambition · transparency · delivery vs roadmap · team · community.

A composite is derived and shown via the traffic light:

ColourMeaning
GreyNeutral — or too little data to judge
RedPoor
YellowMediocre
GreenGood
BlueOutstanding

Multi-dimensionality raises the bar for manipulation: you'd have to fake consistently across many axes, which is more conspicuous.

3.7 The grey default & confidence

Scores are smoothed toward a neutral default so a handful of reviews don't swing wildly, and every score carries a confidence based on the number and diversity of verified reviews. Below a minimum confidence the profile stays grey, regardless of the raw value. A fresh account cannot appear instantly blue, and a Sybil swarm moves nothing — its reviews carry almost no weight and the confidence from genuine sources is absent.

Proof-of-Economy. A strong, separate signal is the breadth of verified payment history: what matters is the number of distinct, independently reputable paying counterparties — not transaction count or volume — so reputation can't be bought, and paying yourself in circles buys nothing.

3.8 Time decay & rehabilitation

Reviews lose weight over time, so recent behaviour dominates. This enables rehabilitation and reduces the incentive to abandon a "burned" account for a fresh one.

3.9 Anti-collusion & whitewashing

Densely interlinked groups that mostly review each other, sudden review/upvote bursts, and circular ("wash") payment flows are detected and discounted; repeated interactions between the same pair count for steadily less. Whitewashing gains little either: new accounts start grey, receiving payments requires a verified identity that can't be trivially re-minted, and rebuilding verified history is the deterrent. Suspicious patterns trigger a flag for review, not an automatic verdict.

3.10 Disputes & right of reply

The rated person can respond publicly to any review. Reports go to moderation and, where relevant, arbitration; for verified engagements the escrow/milestone history serves as evidence. Reviews that lack a genuine business contact with a named person can be removed.

3.11 Invite-based onboarding

Access is deliberately scarce and tied to trust. The first 100 accounts ("Founding Members") sign up directly; after that Ratify is invite-only — every new member is vouched in by an existing, trusted one. An invitation is itself a trust edge, and inviters are accountable: who you bring in reflects back on you. Mass-inviting fake accounts becomes costly and conspicuous.

3.12 On-chain & portable (Solana)

Ratify is Web3-native: your reputation is anchored on Solana so it's verifiable and portable beyond ratify.cc. The score is still computed off-chain — the manipulation-resistant engine and its parameters stay private — but each score snapshot is published as a non-transferable ("soulbound") attestation other Solana apps can read, to gate access, weight governance, or vet a counterparty. Crucially, only cryptographic commitments (hashes) go on-chain, never personal data or review text: the proof is tamper-evident and portable while the underlying data stays editable and deletable (right of reply, correction, and erasure remain intact). Attestations are issuer-updatable, so decay and corrections are reflected.

4. Project reputation

Projects are their own entities, linked to one or more profiles and rated along their own dimensions (ambition, transparency, delivery, team, community). A founder's reputation and their projects' are linked but kept separate: a project that fails with honest communication should hurt the personal score less than a rug pull.

5. Distribution & integrations

Reputation is valuable where Web3 actually talks: on X, Discord, and Telegram. Rather than forcing people onto ratify.cc, Ratify brings the score to them:

Both read only public profile data.

6. Business model

The platform is free for users. Funding comes from two pillars:

The reduced fee makes Premium economical for active users: above a certain monthly volume, it pays for itself through fee savings alone.

7. Settlement

Ratify never custodies funds. Payment runs either through a licensed marketplace payment provider (which handles custody, KYC/AML, and the licence) or through a non-custodial on-chain escrow that releases stablecoins by milestone — with Ratify's fee taken as an application fee or program-side. The data model carries the necessary fields from day one, so settlement can be added without a rewrite.

8. Governance & transparency

A reputation system must balance transparency (so users trust the score) with opacity (so the algorithm can't be trivially gamed). Ratify's approach: principles public, exact weights and parameters not; per-profile explainability (what a score draws on — verified vs. open sources, number of sources, confidence) without revealing anti-manipulation thresholds; and curated anchor nodes, expanded over time by transparent criteria.

Reputation profiles of real people are personal data, and scoring is a form of profiling. Ratify is built around the corresponding rights — lawful basis, data minimisation, right of reply, correction, deletion — and around meaningful information about the logic of the score, while keeping the exact formula confidential.

9. Roadmap

← back to ratify.cc