# Privacy-services' scoring model for non-techies (playbook)

By [Web3Privacy Now](https://paragraph.com/@web3privacy-now) · 2023-11-07

---

Imagine that you want to check if the web3 service is private or not. But you can’t “trace the transaction” or “understand technical documentation”. _Where would you start?_

The Web3privacy now community proposes to use this **_simple & actionable playbook for non-techies_**. It helps to:

*   perform check-ups if projects claiming privacy features are legit
    
*   filter out high-risk services
    
*   boost web3, privacy & security knowledge base.
    

![](https://storage.googleapis.com/papyrus_images/a879cb73b6966875a22602f7764bb5884b57582b84564ecf5c5f955095416335.png)

Playbook is a part of the future “IMDb/Metacritic for privacy” platform. That’s why our story should start with [database](https://github.com/web3privacy/web3privacy) & [scoring](https://github.com/web3privacy/web3privacy/tree/main/Web3privacynowplatform/scoringmodel).

Please, review our scoring approach below. We tried to make it as simple as possible, so non-technical people would understand it with ease.

![](https://storage.googleapis.com/papyrus_images/f9b7a41516d2ed4da03f94f146f8fdf100f4d5a58124a0655a7badcd70e030eb.png)

Part 1: Private or not private: that’s the question
---------------------------------------------------

These simple actions help non-techies to do a quick test if the project is alive, open-source & open for a third-party audit.

### Github

> [GitHub](https://github.com/) is a website and cloud-based service that helps developers store and manage their code, as well as track and control changes to their code.

_Action plan_

*   Visit the official website.
    
*   Find a link to a Github page
    
*   Follow the link
    
*   Check if it’s “alive”: when were the last updates?
    

**How to score**

1.  _Availability_
    
    1.  Available (+),
        
    2.  Missing (-)
        
2.  Activity:
    
    1.  Active (+): there’s an activity within the last 6 months.
        
    2.  Not (-): The GitHub account is silent.
        

_out of the score, but nice to check_: monthly # of activity (general consistency): if the project is updated bimonthly, biweekly or once in a while (1 in 3 months, for example).

![](https://storage.googleapis.com/papyrus_images/415868f1086cc486e978cf515c51df61dc05418056b043296a18fee7d89540a2.png)

**Example**

Here protocol has a GitHub account, but only a landing page is deployed. Solutions architecture, smart contracts, and code base are missing. Note also the last update date.

![https://github.com/Hurricane-Protocol](https://storage.googleapis.com/papyrus_images/513925613aafb8b13edf544a06a2f9c77e7ae1ffc6f268b940bc7264b43acb08.png)

https://github.com/Hurricane-Protocol

### Docs

> Comprehensive documentation ensures that people can effectively leverage the project's capabilities, troubleshoot issues, and find answers to their questions.  
>   
> Documentation is the foundation for collaboration within the open-source community.

_Action plan_

*   Go to the official website.
    
*   Find the link to a Documents page
    
*   Follow the link
    
*   Analyse available information
    

**How to score**

1.  _Availability_:
    
    1.  Available (+)
        
    2.  Missing (-)
        
2.  _Open-source_
    
    1.  Technical (+): written for technical specialists
        
    2.  Marketing (-): use marketing language, lacks tech specs, lots of token narrative
        
3.  _Fullness_ (# of pages)
    
    1.  More than 5 pages (+)
        
    2.  2-3 pages (-)
        

![](https://storage.googleapis.com/papyrus_images/248d87c656093a1d129d62fb4f8c5e224c2a170bc73abea1639188cc23972d13.png)

It’s hard for a non-technical person to understand documentation. But if it’s heavily token-centric (where the token has no proper utility) - it’s a “red flag”.

![https://shadecash.gitbook.io/shadecash/token/token-and-distribution](https://storage.googleapis.com/papyrus_images/5579314d38c09f80d681bb2e851e66fc55963ea8fca0a260f6c39bf875ce3228.png)

https://shadecash.gitbook.io/shadecash/token/token-and-distribution

The same works for visual explainers without technical schemes, infographics, and code base review.

![https://shadecash.gitbook.io/shadecash/get-started/how-to-withdraw-relayer](https://storage.googleapis.com/papyrus_images/a4160f83fce5095d60d9e088806abbd591b8318763b3d65deb061447f4ace1fd.png)

https://shadecash.gitbook.io/shadecash/get-started/how-to-withdraw-relayer

✅ **Development-centric documentation**: [Webb](https://docs.webb.tools/docs/tangle-network/build/deploy-using-hardhat/)

### Third-party audit

> Security audits performed by competent agencies or individuals ensure the level of project security features. Usually, it stands for critical bugs, centralisation features or just badly written code findings.

Third-party security assessment usually decreases risks associated with the project usage. Companies stake their reputation by claiming that the project: a) has vulnerabilities; and b) is secured.

**Note**: it’s not a silver bullet, because mistakes happen or the project could audit a small feature, but it’s a perfect hygienic method for privacy services.

_Action plan_

*   Go to the official website.
    
*   Find the link to a third-party audit (if not on the website - check the official blog)
    
*   Follow the link
    
*   Check it’s actual date
    

**How to score**

1.  _Availability_
    
    1.  Available (+): separate PDF file or landing; available to read/download.
        
    2.  Missing (-): no audit available.
        
2.  _Relevance_
    
    1.  Up to date (+): audited within the last 1 year.
        
    2.  Outdated (-): last audit - 1 year+
        

![](https://storage.googleapis.com/papyrus_images/5c1bdb492298247ea57d915ea0becf2e1d5ee78875077c59a079e2eabccf2c0a.png)

Having many audits - check, outdated audits - check. DeFiner Protocol’ dates (image below) signify the security features of the project. Literally: in 2020 maybe it was secured (depending on audit findings & if issues were fixed), while in 2023 - no data.

![https://docs.definer.org/v/copy-of-definer.org/security/audits](https://storage.googleapis.com/papyrus_images/99866ba4381a9d69b6aad88436551443253b0567957f5c30c5db489fd6ff1222.png)

https://docs.definer.org/v/copy-of-definer.org/security/audits

✅ **Up to date audit**: [Railgun\_](https://assets.railgun.org/docs/audits/)

### Team

> Reputation is a marker of trust. The public team clearly “stakes” its reputation in front of any possible privacy challenge. While anon team could be used as a trick to avoid responsibility over poor privacy features’ execution.

Anonymous engineering could be a mass phenomenon in the future. But now educating about deliberately absent team on the webpage & hidden GitHub contributors vs “cat avatar hardcore developer with tons of public commits” should be well articulated.

Especially, when there's room for anon or sudo-anon reputation: public research, essays, well-written documentation & so on.

_Action plan_

*   Go to the official website.
    
*   Find the link to a Team page
    
*   Explore Team profiles on Twitter, in official Telegram or Discord
    
*   Check if they are public & active
    

**How to score**

*   **Public** (+): the team is public, with active social media &/or GitHub accounts (note: digital avatars are ok if people are actively contributing to the project & actively communicate in socials: [dcbuilder example](https://twitter.com/DCbuild3r))
    
*   **Anon** (-): weird names, no/or obscure avatars, no socials or GitHub links
    

![](https://storage.googleapis.com/papyrus_images/3586e415276af57b6667a26bf20093319d8cdc295aba95b076519baf874676f7.png)

Sometimes teams use “Guy Fawkes” or another pop-anon culture avatars - it’s hard to say who’s behind the project & why you should trust in it.

![](https://storage.googleapis.com/papyrus_images/f55ab50960cd6e28e86747d5fc50badb1f3143de16b7d0c913222c4370b1f528.png)

✅ **Public team @ LinkedIn**: [Elusiv](https://www.linkedin.com/search/results/people/?currentCompany=%5B%2280778213%22%5D&origin=COMPANY_PAGE_CANNED_SEARCH&sid=s_%40)

### Product-readiness

> Refers to the stage of product development from prototypes (early stages) to mainnet (live). Directly correlates with privacy maturity & responsibility of the core team.  
>   
> The live product is expected to be very stable, relatively bug-free and ready for use.

**dApps & protocols have different product versions**:

_dApps_: pre-mature: MVP & beta; mature - alpha  
_protocols_: pre-mature: testnet, mature - mainnet

_Action plan_

*   Launch project website - try to find the state of the product: explicit description
    
*   If the website fails to provide information - use Duduckgo or Brave search: “project name + mainnet”. Analyse search results & their proofs.
    
*   An additional source of truth: official Twitter or blog
    

**How to score**

**live** (+): explicit mainnet for protocols or beta/alpha for dApps communication with additional privacy features maturity level (based on previous testing cycles).  
  
**test-net or prototype** (-): missing “mainnet” explicit description for protocols, or the latest product version for dApps; explicit “testnet” or MVP/prototype product-readiness communication.

![](https://storage.googleapis.com/papyrus_images/ca0180aac4e2c28fdd74d3797e587663316fd687d01f057c6e98b5e03d29682d.png)

✅ Shade transparently describes mainnet deployment (note: of the specific product feature).

![https://shadeprotocol.io/blog/shadeswap-live-on-mainnet](https://storage.googleapis.com/papyrus_images/4c37cef55e8079fbe4220cf588bbceb9bc38b7758ca6061ffa735440488b0d3d.png)

https://shadeprotocol.io/blog/shadeswap-live-on-mainnet

> “Under Construction” (the project isn’t live) is the biggest exclusion factor standing for a non-private service.

![](https://storage.googleapis.com/papyrus_images/a48e4002ad64ce5a5e56683ced242f1dbe0bb8fdadfd6e9b34c3d09ad49485ab.png)

![https://app.xata.fi/#/swap](https://storage.googleapis.com/papyrus_images/1b1cef9835b4dbebe08aa836032eb2038f5bba41ee4d791e319214fe22c26147.png)

https://app.xata.fi/#/swap

_Good privacy ethics_: the project highlights the early version & notifies that usage of this project could be risky.

Summary
-------

This scoring model is the first version of its kind. If you use these simple check-ups - you will empower your privacy experience. But remember that complex assessment and attention to detail ensures that you won’t be tricked by false privacy promises.

![](https://storage.googleapis.com/papyrus_images/22777cea5a41f41cec32b9a9c92d507902b858d9f20b0762e7fb501a8e0e926c.png)

Part 2: Sunset
--------------

> “Sunset” means that the project has been shut down for various reasons: financial challenges, regulatory landscape or weak business model. Here it means that the project team can’t back up privacy features, so it’s a high risk to use it.

_Sunsetting could be_

*   **conscious**: when the project informs about terminated operations in advance: [Aztec Connect example](https://medium.com/aztec-protocol/sunsetting-aztec-connect-a786edce5cae)
    
*   **hidden:** when suddenly a website doesn’t work, support is silent, socials are dead.
    

![http://coinbook.app](https://storage.googleapis.com/papyrus_images/db43b93632f447e134384f1b61fe7b781b2f66282ea74030f6981175cce0abca.png)

http://coinbook.app

✅ [XATA](https://app.xata.fi/#/swap) informed people that they will finish supporting “swap” products & also provided a support line to answer all additional questions.

![https://app.xata.fi/#/swap](https://storage.googleapis.com/papyrus_images/ac6e88e5b4770e951dc4944187aaa186510d570d65d759e53d9f2787d72e1cd3.png)

https://app.xata.fi/#/swap

How can you spot a “hidden” sunset?

*   _Check socials_: when were the last updates?
    
*   _Check support_ (Discord, TG): is the core team active?
    

Lack of updates, news & team support usually indicated that the project is “on hold” - leaning towards sunset. Usually, a 3-6 months public hiatus should be a “red flag” for everyone planning to use such privacy-centric projects.

Appendix
--------

Playbook is based on the [DeFi category test](https://github.com/web3privacy/web3privacy/blob/main/Web3privacynowplatform/scoringmodel/DeFi%20category%20prototype.md) made by the Web3Privacy Now team.  
Project is a part of the “l2beat for privacy” platform: a description is available [here](https://github.com/web3privacy/web3privacy/tree/main/Web3privacynowplatform).

Do you have additional questions? Reach us on Twitter: [here](https://twitter.com/web3privacy).

---

*Originally published on [Web3Privacy Now](https://paragraph.com/@web3privacy-now/privacy-services-scoring-model-for-non-techies-playbook)*
