Reading a report · updated
Risk score vs confidence score
Two numbers that answer different questions, and why reading one without the other misleads.
In short
- Risk answers 'what was found'. Confidence answers 'how much could be checked'.
- Missing data lowers confidence and never lowers risk.
- Low risk with low confidence means unknown, not fine.
Two different questions
The risk score summarises the findings: which warning signs were observed, in which categories, at what severity, weighted by the methodology. Higher means more observed risk.
The confidence score summarises the examination itself: how many of the intended checks completed, whether sources agreed, and how much had to be reported as unavailable. Higher means the report is built on more complete information.
They are independent. A high-risk, high-confidence report is a thorough examination that found serious problems. A high-risk, low-confidence report found serious problems while barely being able to look — which usually deserves more concern, not less.
The asymmetry that makes it work
Every check that cannot run lowers confidence and never lowers risk. This single rule is what stops the model rewarding opacity.
Without it, a contract with no verified source, no holder data and an unreachable security provider would score better than one that was fully examined and had one flaw — because it would have fewer findings. Missing data would become a strategy. Making absence cost confidence rather than credit risk removes the incentive entirely.
Reading them together
The combination worth learning to spot is low risk with low confidence. It looks like the best result on the page and it is the least informative one available: the scan did not find problems, and the scan could not look very hard.
The report lists which checks were unavailable and why. That list is the useful part of a low-confidence result — it tells you exactly what you would need to verify by hand to turn an unknown into an answer.