How scoring works — in full.
The platform surfaces two scores: the Trust Score — the headline, 0–100, higher is safer — and the Vulnerability Score, the breach exposure of an organization’s own people. The Trust Score is a deterministic, 100-point model built from five weighted factors and a drift penalty; there is no hidden model in the scoring path. This page documents every factor, weight, and threshold exactly as the engine applies them — so your compliance team can validate it independently.
Advisory only — not a guarantee. The enterprise makes the final decision.
Two scores — and which way each one runs
Only one number goes up when things are good. Everything the pipeline learns folds into a single headline — the Trust Score — while the Vulnerability Score measures a different thing entirely: how exposed the organization’s own people are on the dark and surface web.
Trust Score
The composite verdict on the organization. Every check — IRS, sanctions, documents, the organization model, people screening, drift, applicant context — folds into this one number.
Vulnerability Score
Breach / dark-web exposure of the organization’s own contacts, driven by the worst-affected person. A liability signal, not a legitimacy one.
The rest of this page documents the Trust Score model in full, then the Vulnerability Score at the end.
Verification gate: auto-reject, review, or approve
Before any score is computed, every application passes through four free checks. The outcome of those checks determines whether it is automatically rejected, sent to a human reviewer, or advanced to scoring and paid verification.
Auto-reject
ANY check returns a confirmed disqualification (fail_confirmed).
Only a definitive "no" — a revoked/suspended IRS status, a non-501(c)(3) subsection, or an exact OFAC match — triggers an automatic rejection. Paid checks never run and the application is stopped.
Manual review
No confirmed failure, but ANY check is inconclusive.
Anything the system cannot definitively confirm — a typo, a fuzzy OFAC match, a name mismatch, an EIN missing from the public dataset, or an upstream service error — routes to a human reviewer. Service/API errors NEVER auto-reject.
Approve to advance
ALL checks pass.
The application clears the free gate, paid identity/bank verification unlocks, and the Trust Score below is computed. The final funding decision always remains with the enterprise.
| Check | Pass | Review | Auto-reject |
|---|---|---|---|
EIN format Confirms the EIN matches the XX-XXXXXXX pattern. | Well-formed EIN. | Malformed EIN — treated as a likely typo; applicant is asked to re-enter. | — |
IRS 501(c)(3) status Looks up the EIN against IRS/ProPublica records, confirms active 501(c)(3) status, and matches the legal name. | Active 501(c)(3) and the legal name matches the IRS record. | EIN not found in the public dataset (church/school/hospital exemptions), status pending/unknown, or name mismatch. | IRS status REVOKED or SUSPENDED, or the org is a different subsection (e.g. 501(c)(4)/(6)) — confirmed ineligible. |
OFAC sanctions screening Screens the organization name and every named officer and board member on the submission against the OFAC SDN sanctions list. | No sanctions match on any screened name. | Fuzzy / potential match (85–96% similarity) on any screened name (org or individual) — routed to a reviewer. | Exact / high-confidence match (≥ 97% similarity) on any screened name (org or individual) — confirmed sanctioned party. |
Document validation Hashes and validates uploaded documents (allowed file type, ≤ 25 MB). | All documents valid (or none required at this stage). | One or more documents failed validation — replace and resubmit. | — |
Five weighted factors
Each factor contributes a capped number of points. Points are summed, then adjusted for drift, then clamped to a 0–100 final score.
IRS 501(c)(3) status
25 pts / 100Confirms the organization is an active, IRS-recognized tax-exempt entity. This is the single strongest signal of legitimacy.
Address consistency
20 pts / 100Compares the address on file with the IRS to the operating business address. A match reduces the likelihood of a shell or diverted entity.
Contact verification
20 pts / 100Measures how many listed contacts have been verified, plus whether a verified contact is authorized to make banking changes (separation-of-duties signal).
Banking verification
20 pts / 100Confirms bank account ownership and weights the result by recency — a verification from last week is worth more than one from six months ago.
Data freshness
15 pts / 100Rewards recently synced IRS data. Stale data is a risk in itself because an org’s status can change between syncs.
Drift penalty & risk tiers
Drift penalty
After the five factors are summed, a penalty is subtracted when our drift detector flags a meaningful change in the organization’s profile or behavior.
Risk tiers
The final score is clamped to 0–100 and bucketed into a tier. Tiers are advisory inputs to the enterprise’s own policy — they do not auto-approve or auto-decline.
The Trust Score ledger — every disclosed deduction
Each application carries exactly one headline number: its Trust Score, 0–100, higher is safer. It starts at 100 and applies only the disclosed deductions below — the organization model above, the Klaw people screening, and every automated check are contributors to that one number, never rival scores on their own scales. The full factor ledger ("what moved this score") is stored with every run and shown to reviewers beside the score itself.
| Contributor | Deduction / credit |
|---|---|
| EIN format | invalid −25 |
| IRS 501(c)(3) | not active −30 · lookup unavailable −10 |
| OFAC / sanctions | potential match −40 · screening unavailable −5 |
| Documents | none uploaded −10 · one fails validation −8 |
| Organization score (model above) | below 70 −10 · below 40 −20 |
| People screening (Klaw, worst-case group) | group trust below 75 −10 · below 55 −20 · fail or below 35 −30 · inconclusive −5 |
| Drift | −5 per record, capped at −20 |
| Online presence | strong +5 · weak −8 · none −15 · red flags −5 each, capped at −20 |
| Applicant context | VPN −12 · IP outside the US −15 · IP changed −8 · country/state/city mismatch −20/−10/−4 |
| Organization age | under 2 years −10 · under 5 −5 · unknown −3 |
| AI recommendation | reject −25 · review −10 |
| The people-screening contributor takes Klaw's group verdict — the most exposed person's score, never the group's average — so one badly exposed officer cannot be diluted by clean colleagues. An inconclusive screening (a contact that could not be checked) costs points rather than passing silently. The result is clamped to 0–100 and bucketed by the same 80/50 tiers published above. | |
The Vulnerability Score
Separate from the Trust Score, a dark web & surface web scan (powered by Klaw) checks the organization’s own contacts against known breach corpora and produces a 0–100 exposure score per person — higher is worse. The organization’s Vulnerability Score is the worst-exposed contact, never the average, so one badly breached officer is not diluted by clean colleagues.
It answers a different question than the Trust Score: not “is this organization legitimate?” but “how much liability is attached to its people if it ever becomes a payout target?” The same signal also feeds the people-screening contributor to the Trust Score above. The evidence behind it — which breach each address appeared in, and the categories of data exposed — is shown beside the score; no leaked credential value is ever displayed.
Free on every plan and on by default. An applicant can see their own exposure; the composite Trust Score stays reviewer-only.
How you can validate it
A score is only as trustworthy as your ability to check it. These four properties make the model auditable rather than a black box.
Deterministic & reproducible
The same inputs always produce the same score. No randomness, no opaque model in the scoring path — the logic is a fixed set of documented rules that can be recomputed and audited at any time.
Every computation is logged
Each score is written to an immutable TrustEvent record with the full factor breakdown, the before/after value, the actor (system), and a timestamp. Nothing is computed off the record.
Independently inspectable
The factor weights on this page are generated from the same source of truth the engine uses. A reviewer can trace any submission’s score back to the specific factors that produced it.
No scoring/billing coupling
The scoring engine has no access to billing status. An organization’s score is identical whether the enterprise is on a trial, current, or past-due plan — eliminating any incentive conflict in the verdict.
Model governance
The weights are expert-set, not yet fit to a labeled fraud dataset. That is a deliberate, disclosed starting point — so here is exactly who owns the model, how often it is reviewed, and how it moves toward empirical validation.
Who owns the model
company-heldThe model is owned by Penusila Digital Solutions LLC, which is accountable for every weight, threshold, and disclosed limitation. We are an early-stage company. Accountability sits with one named, reachable company rather than a fabricated org chart.
- Buyer audit rights: every enterprise customer can request the full change log, the factor-by-factor scoring of any organization, and the version of the model in force on any date. The methodology is intentionally public so it can be audited without our cooperation.
- Version-locked change control: no weight changes silently. Each revision is version-stamped, dated, the prior version retained, and the public methodology updates in the same release.
On reaching $25M in cumulative grant value verified, or on execution of any enterprise contract that requires it, we commit to appointing a dedicated independent compliance reviewer with formal sign-off authority.
Review schedule
QuarterlyFrom expert-set to empirically validated
RoadmapWe do not claim the weights are statistically optimized against fraud outcomes — they are informed judgment on a transparent scale. Here is the path to validating them with data.
- 01Today (v1): weights are expert-set and fully transparent. Every score is logged with its factor breakdown, building the labeled history needed for empirical calibration.
- 02In progress: confirmed outcomes (auto-rejects, reported/banned orgs, enterprise-confirmed fraud) are captured as ground-truth labels against historical scores.
- 03Next: back-test weights against that labeled history, measure each factor’s real predictive lift, and re-weight where the evidence diverges from the current judgment.
- 04Ongoing: publish the model version and its last-validated date so buyers always know which calibration generation they are relying on.
Limitations we disclose
- 01The Trust Score is a decision-support signal, not a guarantee of an organization’s legitimacy or future conduct.
- 02It reflects only the data available at computation time; it cannot detect fraud that leaves no data trail.
- 03A high score does not remove the enterprise’s own due-diligence obligations. The final grant/payment decision always rests with the enterprise.
- 04The current factor weights are expert-set, not yet empirically fit to a labeled dataset of confirmed grant-fraud outcomes. They encode informed judgment about which signals matter, on a transparent, auditable scale — not statistically optimized coefficients. See "Model governance" for the owner, review cadence, and the path to empirical calibration.