Rating methodology
Method before conclusions. This page spells out exactly how a score is produced — indicators, weights, bands, evidence levels, review and appeals. You can apply it to any provider yourself. If your result differs from ours, then either our method or our judgement is wrong, and we want to hear about it.
Indicators & weights
The seven pillars come from our published RAP framework v1.0. The weights aren't arbitrary: attribution and enforcement are what decide whether money leaves at all, so they carry the most weight. Privacy and interoperability matter, but they don't determine whether a payment clears, so they weigh less.
| Pillar | The question it answers | Weight |
|---|---|---|
| Mandate & limits | Are spending boundaries enforced by a system outside the agent | 21 |
| Attribution | Can we establish who is paying and which entity is accountable | 26 |
| AML screening | Is the counterparty screened against sanctions and risk signals | 16 |
| Firewall | Are non-compliant payments actually stopped before settlement | 21 |
| Privacy | Is compliance achieved without over-collecting data | 4 |
| Interoperability | Does it work across protocols and rails rather than locking in | 6 |
| Auditability | Can what happened be reconstructed after the fact | 11 |
| Total | 105 | |
How each pillar is scored
Each pillar scores 0–3. The bands are defined so a third party can reproduce them; otherwise a score is just an impression. Note the gap between 2 and 3: 'it exists' and 'we actually tested it' are not the same claim.
- 0
Absent
- 1
Stated
- 2
Implemented
- 3
Verified
How the grade is set
The weighted score is only a sorting aid. The grade is set by human review, because one fatal gap should not be averaged away by high scores elsewhere. A subject scoring 0 on attribution is graded L0 regardless of how it performs on the rest.
- Trustworthy
- Usable
- Limited
- Non-compliant
- Not rated
Evidence levels
Every piece of supporting evidence is labelled by level. Secondary reporting alone can't support a score — it can point us at something worth checking, but it never becomes a score by itself.
Review cycle, re-review and appeals
- Cycle: routine re-review every 180 days, plus an immediate re-review whenever the subject materially changes — a new release, a licence, or a security incident.
- Change log: every grade change is recorded on the subject's profile page with the before, the after and the reason. Past ratings are never erased.
- Notice before publication: for a named rating we notify the subject before publication where possible and offer a response window. Their reply is published verbatim on the profile page; if they decline or don't respond, we say so.
- Appeals: a subject may dispute a factual finding by submitting evidence; we respond within two weeks and publish the outcome. Facts can be disputed; conclusions cannot be requested.
Conflict-of-interest policy
OceanAlt accepts commercial partnerships and commissioned assessments, but commercial relationships do not influence our rating conclusions; all such relationships are disclosed on the relevant rating pages.
- Any commercial, investment or personnel relationship with a subject is disclosed at the top of its profile. If a relationship can't be disclosed, we don't rate that subject.
- Our own products are always marked self-attested, are never ranked alongside third-party ratings, and get no benefit of the doubt: the current self-rating is L2 precisely because we have not had a third-party security audit.
- As of this page's last update, OceanAlt has no outside investors and no commercial agreement with any rated subject. This sentence will be updated as that changes.
This methodology may itself be wrong. How the weights are set and where the line between a 2 and a 3 falls are judgements, not facts. If you think we've got it wrong, tell us — revisions to the method are versioned and logged too.

