Methodology

How CARIO investigates, and why it sometimes refuses a number.

Scoring model 2.0.0

Usable evidence is the count of collector payloads with at least one meaningful field (excluding metadata keys queries and categories), plus the number of distinct registrable publisher domains actually cited. If that count is zero, Trust, Risk and Confidence are null and the investigation status is NO_RESULTS. Risk starts at 0. A clean, well-corroborated subject scores risk 0 / trust 100. Risk only rises from named adverse categories with citations.

Confidence ceilings

Identity, source, evidence, match and coverage are independently nullable. An ambiguity ceiling caps common names. A single-publisher ceiling caps source confidence. Contradictions penalise. Overall confidence can never exceed identity confidence. AI models may explain a score. They may never produce one.

Lawful source fabric

DNS over HTTPS, RDAP, crt.sh, Wayback, Wikidata, OpenAlex, GitHub, GLEIF, OpenSanctions, GDELT, Nominatim, Finnish PRH/YTJ v3, Suomi.fi PTV, TED. User-Agent identifies CARIO. Robots are respected for crawls. HIBP is clearance-gated and, without a key, recorded as NOT_CHECKED — never as clean.

What we refuse

Credential access, scraping behind authentication, CAPTCHA bypass, purchased dumps, Tor marketplaces, facial recognition against non-public images, stalking and doxxing use cases. The assistant says no, and says why.