Trust & Safety

Our guidelines for maintaining a fair, transparent, and accurate threat intelligence network.

1. Our Threat Verification Process

To ensure the integrity of our threat intelligence database, every scam report submitted via `/report-scam-email` undergoes automatic and manual verification:

  • AI Pre-Screening: Natural Language Processing (NLP) models evaluate report text to detect spam, duplicates, and abuse of the report form.
  • Evidence Verification: Screenshots and headers are reviewed by cybersecurity analysts to verify the legitimacy of the threat claim.
  • Aggregated Scoring: A single report does not label a domain as high-risk. Senders are evaluated using aggregate indicators to protect against targeted trolling.

2. Privacy & Redaction Standards

Our trust model rests on strict privacy compliance. We strive to protect targets from unwarranted exposure:

  • Cryptographic Hashes: We hash reported email addresses and phone numbers. The original details are not searchable via search engines.
  • 脱敏掩码 (Masking): We mask target addresses inside feeds. This ensures the sender is recognizable to victims while preventing massive target harvesting.
  • No Victim Data: Under no circumstances do we display names or contact details of victims. All victim info is stripped during analysis.

3. Fighting False Positives

False positives can disrupt legitimate businesses and personal communication. InboxRisk uses dynamic data decaying to reduce false positives over time:

  • Confidence Score Decay: If a reported domain or sender receives no new scam reports or matches no further threat vectors, its risk score naturally decays back to low status over a 90-day period.
  • Trusted Domain Exclusions: Verified public services, transaction networks, and primary email providers are blocklisted from direct system blocks to prevent wide-scale outages.

4. Open Dispute & Appeal Channels

If your personal account or corporate domain is reported in error, we provide an open, transparent dispute resolution process:

  1. Submit an appeal detailing your domain credentials, organization registration, or evidence of a clean reputation.
  2. Our analysts review the dispute logs within 2 business days.
  3. If approved, the database hash is updated, the target is whitelist-locked, and all legacy reports are marked resolved/hidden from public directories.

Reporting Abuses of Our Platform

If you identify anyone manipulating our scoring systems, publishing private details, or submitting false entries, please report them to safety@inboxrisk.com.