Methodology

Last reviewed June 25, 2026

How an Evidence Dossier is built

Evidesa converts a token mint address into explainable findings using deterministic rules. The same evidence always produces the same scores — language models are not used to decide any score.

WholeThe dossier's architecture: 3 evidence sources feeding 5 scored categories, every category fed by every source it can read.DrawnThe bracket on the right is the overall signal: one derivation over all five categories together, by fixed rules.Not drawnNo meter, no fill level, no needle — a gauge partly full would read as a score, and a band is a range, not a verdict. This draws the deriving, never a result, and no token's evidence is drawn here.

The five scored categories

Each investigation evaluates five categories. Every category produces a 0–100 score from rule-based findings, and each finding carries a fixed point contribution and a severity:

  • Technical controls — token program, mint and freeze authority state, and Token-2022 extensions read from the mint account.
  • Holder concentration — supply share held by the largest returned token accounts, plus owner-authority mapping when available.
  • Liquidity structure — selected-pair depth, valuation-to-liquidity, and returned-pair distribution from third-party market data.
  • Social / narrative identity — completeness of project-provided metadata (links, description) and whether token identity is mutable.
  • Market behavior — selected-pair price movement, turnover relative to liquidity, pair age, and transaction mix.

How Overall Risk is aggregated

Overall Risk (v0) is not an average of the five categories. Averaging would dilute a single critical category whenever the others are low, so no combination of quiet categories can pull down a loud one. The most elevated category sets the result, and the report names which one it was.

Corroboration then matters on top of that: risk that appears independently in several categories is stronger evidence than the same risk in one, and the result reflects that. The effect is bounded, so breadth can sharpen a conclusion but never manufacture one. The report states whether corroboration was applied.

A category’s band can never contradict the evidence beneath it — a category carrying a high-severity finding does not report Low. That rule only ever raises a result, never lowers one.

A category with insufficient evidence is not counted at all, so missing data can neither raise a score nor lower it. A band is a score range, not a verdict, and when some categories could not be evaluated it is a floor rather than a conclusion — the report says so, because an unevaluated category could only have raised the result.

Evidence statuses and score contributions

Findings are generated only from evidence that was actually collected. Every scored finding in a report states what it contributed to its category and the evidence behind it, so any individual report can be read back and checked line by line.

The full table of weights, thresholds and severities is not published. What a reader needs in order to trust a report is the evidence it cites and the arithmetic it shows for that token, and both are on the page. Scoring is deterministic: the same evidence produces the same result.

Point-in-time and deterministic

An Evidence Dossier is a point-in-time snapshot: on-chain controls, holder distribution, liquidity, market data, and metadata can all change after a report is generated. Reporting that change is the watch's job, not the dossier's — a kept mint is re-observed on a schedule and what moved comes back as an explained incident. The dossier itself never updates in place. Server-side timing shown in a report is observed during that run and is not a service-level guarantee.

Creator evidence is excluded from scoring

Creator / Deployer Evidence and the bounded, on-demand Creator Launch History are evidence-only and experimental. They never contribute to any category score or to Overall Risk. Related-wallet clustering and transfer-graph analysis are not implemented. The earliest observed transaction is not proof of the creation transaction, and an observed fee payer is not proof of the real creator or team.

Optional and non-scored data

The Data Sources & Confidence section, server-side timing, identity metadata shown for usability, and the local Price Snapshot History are informational and non-scored. They do not change category scores, thresholds, severities, or Overall Risk aggregation.

When evidence is incomplete

Missing or unavailable evidence is presented as insufficient evidence, kept visible, and is never interpreted as evidence of low risk. For example, unavailable holder data is shown as insufficient evidence rather than broad distribution.

See also the data sources and limitations this analysis is built on.