01
Core principles
- Only publicly observable controls and documentation are evaluated.
- Unknown controls are never inferred; absence of evidence is not evidence of absence.
- Customer or commercial status has no effect on scoring, and using Decoda does not increase a score.
- Evidence coverage is reported independently from the controls score.
02
Score calculation
Each control has a published weight and an evidence-state multiplier. The score is the weighted points earned divided by the total applicable weight, multiplied by 100 and rounded to the nearest whole number.
Controls marked NOT_APPLICABLE are removed from both numerator and denominator. The total score is calculated across all controls; category scores apply the same formula only to controls in that category. Totals are generated from the underlying controls—not entered editorially.
03
Evidence states
Direct public evidence supports the control.
Published documentation supports the claim, without direct technical verification.
The review looked for the control but did not observe it in the cited public scope.
Available evidence is insufficient to verify the control.
The control does not apply and is excluded from numerator and denominator.
04
Control categories
Role design, access separation, and privileged authority.
Emergency response, pause, and upgrade mechanisms.
Mint, burn, supply, and transfer restrictions.
Backing, custody, valuation, and reconciliation signals.
Audits, monitoring, disclosures, and operational visibility.
05
Evidence coverage
Evidence coverage is the percentage of applicable controls with at least one cited source. It is displayed separately and does not add points. A high coverage percentage means more claims are traceable; it does not by itself mean stronger controls.
Publication checks
Before publication, automated validation recomputes totals and category scores, requires evidence and an HTTPS URL for every scored claim, and requires observation dates. Any failure blocks the build.