Reading a risk assessment — and this platform's flag points

What this platform's flag points actually compute, which seven factors they know, why they no longer assign a bucket, and which risks they explicitly do not see.

This lesson has had no expert review. It was written for this platform and against the evidence it cites; nobody has gone through it independently.

Learning objectives

  • You can name the seven factors behind the flag points and explain the point thresholds.
  • You can explain why a low flag-point total — even zero — is not proof of safety.

Check your prior knowledge

Answer these for yourself before reading on. Wherever you hesitate is where this lesson pays off.

Core concept

Fact

Seven factors, additive, disclosed

The evaluation adds points across seven factors: deposited capital, chain maturity, the asset's type together with its exposure and IL risk, dependence on reward emissions, the protocol's track record, the statistical outlier marking, and data completeness. Every branch that fires appears as a named data flag, and the total as flag points — at most 13, because only one branch per factor can fire. Since 2026-09-21 no class (“low”/“medium”/“high”) is derived from it — the example further down says why.

Assumption

Two factors are lists, not measurements

Chain maturity and protocol track record rest on maintained allowlists — currently 9 chains and 36 protocols. That is an assumption, not a measurement: a new, carefully built protocol is not on the list and takes a point; a listed protocol keeps its status after an incident until someone edits the list. Using the score means adopting that assumption.

Risk

What the score does not see

No code review, no admin rights, no upgrade paths, no oracle design, no governance concentration, no legal classification. A protocol with unlimited admin rights and a manipulable oracle can be unremarkable in all seven factors and come out with zero flag points. The score is a pre-sort by observable market data — not a substitute for dimensions 4, 8 and 11 of the analysis framework.

Definitions

Heuristic
An approximation that yields a usable pre-sort without examining the underlying facts.
Flag points in the glossary
Here: this platform's internal, disclosed heuristic — data flags and their total. Explicitly not a risk rating, not an audit and not a guarantee.
Allowlist
A maintained list standing in for a property that cannot be measured.

Model

  1. Deposited capital (TVL)

  2. Chain maturity — allowlist

  3. Asset, exposure and IL risk

  4. Dependence on reward emissions

  5. Protocol track record — allowlist

  6. Statistical outlier marking

  7. Data completeness

The seven factors in the order they are computed — Steps 2 and 5 are list decisions, not measurements. Step 5 is suspended for RWA issuers and awards no point there — suspended does not mean met.

Formulas

Flag points

Flag points = sum of the points of all triggered flags (0–13) | filter threshold of the narrow selection: <= 2
Flag points
sum across the seven factors

Limit: The total adds up the factors with fixed point values per factor (at most 3, 2, 2, 2, 1, 2 and 1), without that weighting having been empirically grounded or calibrated. It does not order pools and supports no ranking.

TVL factor

>= USD 50m: 0 | >= 10m: +1 | >= 1m: +2 | below: +3
TVL
the pool's deposited capital in USD

Limit: The factor measures size, not quality — and TVL itself has two drivers, quantity and price (see the lesson “Reading TVL”).

Worked example

Why the bucket was dropped

Pool A
0 points: large TVL, established chain and protocol, stablecoin, barely any rewards
Pool B
2 points: two flags triggered
Former display
both “Niedrig” (low)

Both sat at or below the 2-point threshold and received the same bucket, although two flags had triggered for pool B and none for pool A.

The same bucket, different flags — and different reasons behind them.

Reading: That is exactly why this platform has shown the flags instead of a bucket since 2026-09-21. A word like “low” over a named product is a verdict; the list of triggered flags is an observation anyone can recompute.

Retrieval

No data flag has fired for a pool — zero flag points. What does that evidence?
Why do “chain maturity” and “track record” need particularly careful reading?

Exercise on real data

Compare the factors described there with the seven above and record which limits the methodology page names itself.

Read the methodology in the original →

Open a market and read the individual flags, not just the total. Find two markets with the same flag points where different flags fired.

Look at a market's factor list →

Application

Your organization wants to use this platform's flag points as a filter in an internal process, say “at most 2 points”. What do you advise?

Related case studies

Institutional reading

Bank
Which internal requirements for a risk model does a disclosed heuristic meet — and which not?
Advisory
How is a client told that a low flag-point total is a pre-sort and not an assurance?

Metrics in this lesson

Key takeaways

Evidence