Scoring

How scoring works — in full.

The platform surfaces two scores: the Trust Score — the headline, 0–100, higher is safer — and the Vulnerability Score, the breach exposure of an organization’s own people. The Trust Score is a deterministic, 100-point model built from five weighted factors and a drift penalty; there is no hidden model in the scoring path. This page documents every factor, weight, and threshold exactly as the engine applies them — so your compliance team can validate it independently.

v1.0 · updated Jun 8, 2026

Advisory only — not a guarantee. The enterprise makes the final decision.

The scores

Two scores — and which way each one runs

Only one number goes up when things are good. Everything the pipeline learns folds into a single headline — the Trust Score — while the Vulnerability Score measures a different thing entirely: how exposed the organization’s own people are on the dark and surface web.

Trust Score

0–100 · higher is safer

The composite verdict on the organization. Every check — IRS, sanctions, documents, the organization model, people screening, drift, applicant context — folds into this one number.

Seen by: Reviewers

Vulnerability Score

0–100 · higher is worse

Breach / dark-web exposure of the organization’s own contacts, driven by the worst-affected person. A liability signal, not a legitimacy one.

Seen by: Reviewers & the applicant (their own)

The rest of this page documents the Trust Score model in full, then the Vulnerability Score at the end.

The decision

Verification gate: auto-reject, review, or approve

Before any score is computed, every application passes through four free checks. The outcome of those checks determines whether it is automatically rejected, sent to a human reviewer, or advanced to scoring and paid verification.

Auto-reject

ANY check returns a confirmed disqualification (fail_confirmed).

Only a definitive "no" — a revoked/suspended IRS status, a non-501(c)(3) subsection, or an exact OFAC match — triggers an automatic rejection. Paid checks never run and the application is stopped.

Manual review

No confirmed failure, but ANY check is inconclusive.

Anything the system cannot definitively confirm — a typo, a fuzzy OFAC match, a name mismatch, an EIN missing from the public dataset, or an upstream service error — routes to a human reviewer. Service/API errors NEVER auto-reject.

Approve to advance

ALL checks pass.

The application clears the free gate, paid identity/bank verification unlocks, and the Trust Score below is computed. The final funding decision always remains with the enterprise.

CheckPassReviewAuto-reject
EIN format
Confirms the EIN matches the XX-XXXXXXX pattern.
Well-formed EIN.Malformed EIN — treated as a likely typo; applicant is asked to re-enter.
IRS 501(c)(3) status
Looks up the EIN against IRS/ProPublica records, confirms active 501(c)(3) status, and matches the legal name.
Active 501(c)(3) and the legal name matches the IRS record.EIN not found in the public dataset (church/school/hospital exemptions), status pending/unknown, or name mismatch.IRS status REVOKED or SUSPENDED, or the org is a different subsection (e.g. 501(c)(4)/(6)) — confirmed ineligible.
OFAC sanctions screening
Screens the organization name and every named officer and board member on the submission against the OFAC SDN sanctions list.
No sanctions match on any screened name.Fuzzy / potential match (85–96% similarity) on any screened name (org or individual) — routed to a reviewer.Exact / high-confidence match (≥ 97% similarity) on any screened name (org or individual) — confirmed sanctioned party.
Document validation
Hashes and validates uploaded documents (allowed file type, ≤ 25 MB).
All documents valid (or none required at this stage).One or more documents failed validation — replace and resubmit.
The model

Five weighted factors

Each factor contributes a capped number of points. Points are summed, then adjusted for drift, then clamped to a 0–100 final score.

IRS 501(c)(3) status

25 pts / 100

Confirms the organization is an active, IRS-recognized tax-exempt entity. This is the single strongest signal of legitimacy.

IRS status = active+25
IRS status = unknown or pending+5
IRS status = revoked / suspended+0

Address consistency

20 pts / 100

Compares the address on file with the IRS to the operating business address. A match reduces the likelihood of a shell or diverted entity.

IRS and business city/state match+20
Both addresses present but differ+8
Only one address available+12
No address data+0

Contact verification

20 pts / 100

Measures how many listed contacts have been verified, plus whether a verified contact is authorized to make banking changes (separation-of-duties signal).

Proportion of contacts verified (up to 15 pts)+15
Verified contact authorized for banking changes+5
No contacts on file+0

Banking verification

20 pts / 100

Confirms bank account ownership and weights the result by recency — a verification from last week is worth more than one from six months ago.

Verified < 30 days ago+20
Verified < 90 days ago+15
Verified < 180 days ago+10
Verified > 180 days ago+5
Pending verification+5
Unverified+0

Data freshness

15 pts / 100

Rewards recently synced IRS data. Stale data is a risk in itself because an org’s status can change between syncs.

IRS data synced < 30 days ago+15
Synced < 90 days ago+10
Synced < 365 days ago+5
Synced > 365 days ago / never+0
Adjustment & banding

Drift penalty & risk tiers

Drift penalty

After the five factors are summed, a penalty is subtracted when our drift detector flags a meaningful change in the organization’s profile or behavior.

high drift−20
medium drift−10
low drift−3
none drift0

Risk tiers

The final score is clamped to 0–100 and bucketed into a tier. Tiers are advisory inputs to the enterprise’s own policy — they do not auto-approve or auto-decline.

Low risk80–100
Medium risk50–79
High risk0–49
One number

The Trust Score ledger — every disclosed deduction

Each application carries exactly one headline number: its Trust Score, 0–100, higher is safer. It starts at 100 and applies only the disclosed deductions below — the organization model above, the Klaw people screening, and every automated check are contributors to that one number, never rival scores on their own scales. The full factor ledger ("what moved this score") is stored with every run and shown to reviewers beside the score itself.

ContributorDeduction / credit
EIN formatinvalid −25
IRS 501(c)(3)not active −30 · lookup unavailable −10
OFAC / sanctionspotential match −40 · screening unavailable −5
Documentsnone uploaded −10 · one fails validation −8
Organization score (model above)below 70 −10 · below 40 −20
People screening (Klaw, worst-case group)group trust below 75 −10 · below 55 −20 · fail or below 35 −30 · inconclusive −5
Drift−5 per record, capped at −20
Online presencestrong +5 · weak −8 · none −15 · red flags −5 each, capped at −20
Applicant contextVPN −12 · IP outside the US −15 · IP changed −8 · country/state/city mismatch −20/−10/−4
Organization ageunder 2 years −10 · under 5 −5 · unknown −3
AI recommendationreject −25 · review −10
The people-screening contributor takes Klaw's group verdict — the most exposed person's score, never the group's average — so one badly exposed officer cannot be diluted by clean colleagues. An inconclusive screening (a contact that could not be checked) costs points rather than passing silently. The result is clamped to 0–100 and bucketed by the same 80/50 tiers published above.
Exposure

The Vulnerability Score

Separate from the Trust Score, a dark web & surface web scan (powered by Klaw) checks the organization’s own contacts against known breach corpora and produces a 0–100 exposure score per person — higher is worse. The organization’s Vulnerability Score is the worst-exposed contact, never the average, so one badly breached officer is not diluted by clean colleagues.

It answers a different question than the Trust Score: not “is this organization legitimate?” but “how much liability is attached to its people if it ever becomes a payout target?” The same signal also feeds the people-screening contributor to the Trust Score above. The evidence behind it — which breach each address appeared in, and the categories of data exposed — is shown beside the score; no leaked credential value is ever displayed.

Free on every plan and on by default. An applicant can see their own exposure; the composite Trust Score stays reviewer-only.

Closing the validation gap

How you can validate it

A score is only as trustworthy as your ability to check it. These four properties make the model auditable rather than a black box.

Deterministic & reproducible

The same inputs always produce the same score. No randomness, no opaque model in the scoring path — the logic is a fixed set of documented rules that can be recomputed and audited at any time.

Every computation is logged

Each score is written to an immutable TrustEvent record with the full factor breakdown, the before/after value, the actor (system), and a timestamp. Nothing is computed off the record.

Independently inspectable

The factor weights on this page are generated from the same source of truth the engine uses. A reviewer can trace any submission’s score back to the specific factors that produced it.

No scoring/billing coupling

The scoring engine has no access to billing status. An organization’s score is identical whether the enterprise is on a trial, current, or past-due plan — eliminating any incentive conflict in the verdict.

Ownership & calibration

Model governance

The weights are expert-set, not yet fit to a labeled fraud dataset. That is a deliberate, disclosed starting point — so here is exactly who owns the model, how often it is reviewed, and how it moves toward empirical validation.

Who owns the model

company-held

The model is owned by Penusila Digital Solutions LLC, which is accountable for every weight, threshold, and disclosed limitation. We are an early-stage company. Accountability sits with one named, reachable company rather than a fabricated org chart.

Checks that hold today — no headcount required
  • Buyer audit rights: every enterprise customer can request the full change log, the factor-by-factor scoring of any organization, and the version of the model in force on any date. The methodology is intentionally public so it can be audited without our cooperation.
  • Version-locked change control: no weight changes silently. Each revision is version-stamped, dated, the prior version retained, and the public methodology updates in the same release.
Independent oversight trigger

On reaching $25M in cumulative grant value verified, or on execution of any enterprise contract that requires it, we commit to appointing a dedicated independent compliance reviewer with formal sign-off authority.

Review schedule

Quarterly
QuarterlyScheduled review of factor weights, thresholds, and tier bands against the prior quarter’s outcomes. Every change is version-stamped, logged, and dated; the public methodology updates in the same release.
Event-drivenAn out-of-cycle review is triggered by any confirmed fraud that the model scored as low-risk, a regulatory change, or a data-source change (e.g. an IRS/OFAC schema change).
AnnualFull methodology re-attestation: Penusila Digital Solutions LLC re-approves the entire model and the disclosed limitations for the year.

From expert-set to empirically validated

Roadmap

We do not claim the weights are statistically optimized against fraud outcomes — they are informed judgment on a transparent scale. Here is the path to validating them with data.

  1. 01Today (v1): weights are expert-set and fully transparent. Every score is logged with its factor breakdown, building the labeled history needed for empirical calibration.
  2. 02In progress: confirmed outcomes (auto-rejects, reported/banned orgs, enterprise-confirmed fraud) are captured as ground-truth labels against historical scores.
  3. 03Next: back-test weights against that labeled history, measure each factor’s real predictive lift, and re-weight where the evidence diverges from the current judgment.
  4. 04Ongoing: publish the model version and its last-validated date so buyers always know which calibration generation they are relying on.
Model version: v1.0Last reviewed: 2026-06-08
What it is — and isn’t

Limitations we disclose

  1. 01The Trust Score is a decision-support signal, not a guarantee of an organization’s legitimacy or future conduct.
  2. 02It reflects only the data available at computation time; it cannot detect fraud that leaves no data trail.
  3. 03A high score does not remove the enterprise’s own due-diligence obligations. The final grant/payment decision always rests with the enterprise.
  4. 04The current factor weights are expert-set, not yet empirically fit to a labeled dataset of confirmed grant-fraud outcomes. They encode informed judgment about which signals matter, on a transparent, auditable scale — not statistically optimized coefficients. See "Model governance" for the owner, review cadence, and the path to empirical calibration.

Have your compliance team validate it.