Skip to content

Version 1.1.0-draft · not in force · sha256 7e86fe581eedbbf7…

Rating Methodology & Independence Policy

DRAFT — REQUIRES REVIEW BY QUALIFIED COUNSEL IN [JURISDICTION] BEFORE USE. Not legal advice. Not a substitute for a lawyer. Unlike the other documents here, this one is intended to be published in full — it is the source of the mark's credibility.

Version: 1.1.0-draft · Status: not in force · Baseline: GDPR-grade


1. The rubric is public

The full rubric — dimensions, weights, criteria, evidence requirements, bands, gates and the certification threshold — is published at /methodology and versioned in this repository. Every report and every badge names the exact rubric version used. A rubric change never retroactively alters a score that has already been issued, and material changes are announced with notice before they take effect.

2. How a score is reached

Each of the six dimensions starts at 100. Every published finding subtracts its severity penalty, scaled by a confidence multiplier. Dimension scores are clamped to 0–100 and combined by weight. Gates are applied last and can only lower a result — a single critical security or privacy finding caps the overall score below the certification threshold regardless of how strong the other dimensions are.

3. What payment does and does not buy

Payment buys depth of assessment, re-testing, monitoring and support.

Payment does not buy a score, the suppression of a finding, a delay to a badge suspension, or preferential placement in any listing. This is not a promise about our conduct; it is a property of how the system is built:

  • The scoring function receives a data structure that has no field for a plan, a price, a spend, a marketing relationship or an account age. A build-time assertion fails compilation if such a field is ever added.
  • Our test suite constructs a maximally-paying customer with an active marketing-services contract and a free-tier customer, gives them identical applications and identical evidence, and asserts that their scores are identical. That test failing blocks every change.
  • Cost and margin data is not readable by reviewers. A reviewer with a commercial signal in front of them is not an independent reviewer.

4. Human review and overrides

Every assessment is reviewed by a human before publication and before any badge issues. A reviewer may confirm, adjust or reject. Adjustments require a written reason, and are stored in an append-only log with the reviewer's identity, the previous scores and the new scores. The database rejects an override with no reason. Reviewers must declare and recuse themselves from any application in which they have a commercial, employment or ownership interest.

5. Disclosure of paid relationships

Any customer who has purchased marketing services from us is labelled as such wherever their rating appears, including on the verification page and, from the point the directory exists, on their listing. If paid placement is ever introduced in the directory, it will be visually and textually labelled as advertising and will never alter organic ordering.

6. When somebody else pays for the assessment

A platform, marketplace or app store may want every application it lists to be assessed, and may want to pay for that itself. It is a reasonable thing to want and it changes two things at once: the person paying is no longer the person being assessed, and one customer can become a large share of our income. Both have to be answered before the first conversation, not after it.

  • Authorisation is never transferable. Only the owner of an application may authorise testing of it. A platform's terms with its own sellers are between them and their sellers; they are not an authorisation to us, and no payment creates one. This is enforced in the database rather than promised here: an assessment row cannot exist without pointing at a verified authorisation record for that application.
  • The subject sees it first. Results go to the application's owner. A platform that pays does not receive an unpublished assessment of somebody else's application before its owner has it, and receives nothing at all about an application whose owner has not agreed to share it.
  • Payment may never depend on the answer. No arrangement in which we are paid only for applications that pass, paid more for a higher score, paid less for a failure, or repaid when a listing is refused. An assessor whose income moves with the result is not an assessor.
  • A platform cannot have somebody else's badge removed. A badge is suspended by drift, by expiry, by its owner, or by us with a stated reason and the appeals policy in force. That a platform stopped paying, or delisted a seller, is not one of those.
  • Concentration is disclosed. Where any single customer accounts for more than 20% of revenue in a financial year, that fact is published on the methodology page for as long as it remains true. Twenty is a judgement rather than a rule anybody has set for us, and it is written down so that it cannot be quietly revised upward by whoever is negotiating.
  • Recusal covers the relationship, not only the application. Anybody who negotiates or manages a platform relationship may not review assessments of applications listed on that platform.
  • Termination is not leverage. If a platform stops paying, badges already issued stand for their term. The mark belongs to the application's owner, who earned it, and not to whoever paid the invoice.

7. What a customer may do

You may decline to publish a report, appeal a finding, request a re-test after remediation, and opt out of any public listing entirely while remaining certified. You may not purchase a change to a score.

8. Refusal and revocation

We may refuse to assess or decline to certify. We may revoke a badge. In each case we state a reason and the Appeals & Corrections Policy applies.