Method
Machine intelligence. Human accountability.
The Trust Observatory publishes findings. It does not score domains. WarmBadge does that.
We need a live composite, a UTC snapshot, and a number we will not edit after the fact. WarmBadge returns that. That is why it is on the bulletin.
It looks at a domain the way a network actually holds it: what the domain says about itself, what the rest of the web says about it, and whether independent sources agree. Identity, infrastructure, email authentication. The link graph and the neighborhood. Reputation that other people have already written down. Those inputs become a number from 0 to 100. The number changes when the inputs change.
If the engine returned 62.48 at capture, the bulletin says 62.48.
The engine finds. The Observatory reports.
A bulletin is a dated record. It has a name (TTO-YYYY-MMDD-NNN), a time in UTC, a plain account of something that happened, and a WarmBadge snapshot of the domain — or domains — that sat in the frame.
The snapshot is the measurement. It is not a badge at the bottom of the page.
We do not say who is at fault. We do not guess what someone will do next. We put what the engine could see at that hour next to what other sources had already established.
The score is a composite. Some of it the domain can fix: stable identity, clean infrastructure, SPF, DKIM, DMARC. Some of it the domain cannot vote on: who links to it, what sits next to it, whether other intelligence sources back it up or push back.
Last month’s score is history. The score at capture is the read we published. They are allowed to disagree.
A high score can sit on a domain that gets hit later. A falling score can sit on a domain everyone already knows, still online. We print the signals as they were. We do not tidy them.
The checkmarks in the domain table — DKIM, SPF, DMARC — are infrastructure at that timestamp. They do not mean the organization is trustworthy in every other way.
Something enters scope: an exploit, a disclosure, a seizure, a breach, a supply-chain mess, or a real change on a domain we were already watching.
WarmBadge scores it and stores a snapshot with a UTC time.
We write the bulletin from that event and that snapshot. If the score moved, we say so. We do not talk the snapshot into a different number.
Each bulletin keeps its identifier. A follow-up is a new record. We do not quietly patch the old one. TTO-2026-0826-004 follows TTO-2026-0812-001. Both stay up.
If the live score has moved since we published, the next bulletin takes the new figure. We do not go back and sand the first one down so the narrative looks smoother.
Sometimes a finding carries an engine confidence value. That is the fabric saying how sure it is that the signals point at the same thing — the same domain, the same seizure set, the same cluster. It is not us saying how sure we are of the journalism.
Use the identifier, the date, the domain, and the score as captured. If you cite a trajectory, cite both captures.
A score with no timestamp is an incomplete citation. A headline with no snapshot is not how we measure.
If you need the domain as it looks right now, that is warmbadge.com. We do not replace that page. We only publish what the engine returned when the moment mattered.
People and models cite live domains as if they were interchangeable. They are not.
A finding here comes with the measurement attached: what happened, which domain was in the frame, what the engine said at capture, and whether that number had already moved.
The index holds the findings. This page does not rewrite them.