METHODOLOGY · Q3 2026

How the index works

A reproducible framework for translating public evidence into a bounded control score—without filling in the unknowns.

01

Core principles

  • Only publicly observable controls and documentation are evaluated.
  • Unknown controls are never inferred; absence of evidence is not evidence of absence.
  • Customer or commercial status has no effect on scoring, and using Decoda does not increase a score.
  • Evidence coverage is reported independently from the controls score.

02

Score calculation

Each control has a published weight and an evidence-state multiplier. The score is the weighted points earned divided by the total applicable weight, multiplied by 100 and rounded to the nearest whole number.

Score = round( Σ(weight × multiplier) / Σ(applicable weight) × 100 )

Controls marked NOT_APPLICABLE are removed from both numerator and denominator. The total score is calculated across all controls; category scores apply the same formula only to controls in that category. Totals are generated from the underlying controls—not entered editorially.

03

Evidence states

VERIFIED

Direct public evidence supports the control.

SUPPORTED BY DOCUMENTATION0.75×

Published documentation supports the claim, without direct technical verification.

NOT OBSERVED

The review looked for the control but did not observe it in the cited public scope.

UNVERIFIED

Available evidence is insufficient to verify the control.

NOT APPLICABLEExcluded

The control does not apply and is excluded from numerator and denominator.

04

Control categories

Privileged / Admin

Role design, access separation, and privileged authority.

Emergency / Upgrade

Emergency response, pause, and upgrade mechanisms.

Supply / Transfer

Mint, burn, supply, and transfer restrictions.

Asset Integrity

Backing, custody, valuation, and reconciliation signals.

Assurance / Observability

Audits, monitoring, disclosures, and operational visibility.

05

Evidence coverage

Evidence coverage is the percentage of applicable controls with at least one cited source. It is displayed separately and does not add points. A high coverage percentage means more claims are traceable; it does not by itself mean stronger controls.

Publication checks

Before publication, automated validation recomputes totals and category scores, requires evidence and an HTTPS URL for every scored claim, and requires observation dates. Any failure blocks the build.

IMPORTANT CONTEXT

Scores measure publicly observable technical controls and documentation at the stated snapshot date. They are not smart-contract audits, credit ratings, investment recommendations, or assessments of an organization's complete security posture.