Methodology

How an Evidence Dossier is built

Evidesa converts a token mint address into explainable findings using deterministic rules. The same evidence always produces the same scores — language models are not used to decide any score.

Last reviewed June 25, 2026

The five scored categories

Each investigation evaluates five categories. Every category produces a 0–100 score from rule-based findings, and each finding carries a fixed point contribution and a severity:

  • Technical controls — token program, mint and freeze authority state, and Token-2022 extensions read from the mint account.
  • Holder concentration — supply share held by the largest returned token accounts, plus owner-authority mapping when available.
  • Liquidity structure — selected-pair depth, valuation-to-liquidity, and returned-pair distribution from third-party market data.
  • Social / narrative identity — completeness of project-provided metadata (links, description) and whether token identity is mutable.
  • Market behavior — selected-pair price movement, turnover relative to liquidity, pair age, and transaction mix.

How Overall Risk is aggregated

Overall Risk (v0) is the maximum of the five category scores — not an average. Averaging would dilute a single critical category when the others are low, so the highest category drives the overall signal. This is conservative and appropriate for an early-stage risk product.

Scores map to bands: 0–25 Low, 26–50 Medium, 51–75 High, 76–100 Critical. A band is a score range, not a verdict. A Low band can still contain a notable individual finding, so the Top Signals and detailed findings should be read alongside the number.

Evidence statuses and score contributions

Findings are generated only from evidence that was actually collected. Each scored finding states its point contribution (for example, “+10 to Holder Concentration Risk”) and the evidence behind it. Category scores are capped at 100. Findings are ranked into Top Signals by severity, then score impact, then category importance and data confidence.

Point-in-time and deterministic

An Evidence Dossier is a point-in-time snapshot, not continuous monitoring. On-chain controls, holder distribution, liquidity, market data, and metadata can all change after a report is generated. Server-side timing shown in a report is observed during that run and is not a service-level guarantee.

Creator evidence is excluded from scoring

Creator / Deployer Evidence and the bounded, on-demand Creator Launch History are evidence-only and experimental. They never contribute to any category score or to Overall Risk. Related-wallet clustering and transfer-graph analysis are not implemented. The earliest observed transaction is not proof of the creation transaction, and an observed fee payer is not proof of the real creator or team.

Optional and non-scored data

The Data Sources & Confidence section, server-side timing, identity metadata shown for usability, and the local Price Snapshot History are informational and non-scored. They do not change category scores, thresholds, severities, or Overall Risk aggregation.

When evidence is incomplete

Missing or unavailable evidence is presented as insufficient evidence, kept visible, and is never interpreted as evidence of low risk. For example, unavailable holder data is shown as insufficient evidence rather than broad distribution.

See also the data sources and limitations this analysis is built on.