Korat
How a badge earns its meaning

Badges that state evidence, never a verdict

A trust badge is a claim a platform makes about a person to a stranger. Most platforms make that claim far larger than their evidence supports. This page is the argument for why ours are smaller, and what we refused to build.

Trust has one design that every social product eventually proposes: let people vouch for each other. It is cheap to build, it produces a satisfying number, and it makes a profile feel alive. We rejected it on the record, for a single reason worth stating plainly, because it governs everything else on this page. A count anyone can add to is a count anyone can fake. An open vouch button measures nothing except how many accounts somebody was willing to create. Ten accounts made in an afternoon produce a profile that reads as more trustworthy than a real person with three genuine friends, and the badge has then done worse than nothing — it has laundered a stranger.

Only a party with something to lose may vouch

The replacement follows directly from the diagnosis. If the problem with an open vote is that a voter risks nothing, then the fix is to restrict vouching to a party that does. Only a business can vouch for a person on Korat. A business has a name, a physical address, a public page, a sales history and a body of reviews attached to it — all things that get worse if it hands out endorsements carelessly. It is not that shops are more honest than people; it is that a shop's vouch is attached to something it cannot cheaply abandon, and that attachment is the mechanism.

This is also why the badge label is written the way it is. It reads "vouched for by 3 shops" — a statement of what happened — rather than "trusted" or "verified", which are conclusions the reader is entitled to draw or not draw. The distinction sounds pedantic until you notice that every trust badge scandal has the same shape: a platform stated a conclusion its evidence could not carry, and users reasonably believed it.

The four rows, ordered by what it costs to fake them

A profile can carry four kinds of evidence, and they are displayed in a fixed order: strongest first, where strongest means hardest and most expensive to fabricate.

  1. Vouched for by N shops. The most expensive to fake, because it requires the cooperation of a business with a reputation attached to its name.
  2. N real paid visits across N shops. Money actually changed hands, and the platform recorded it. Faking this means spending real money at real businesses, which is a fraud with a genuine cost per unit.
  3. A device-bound passkey. Proves possession of a specific device with a hardware-held private key. Cheap for a legitimate user, awkward to scale across a farm of fake accounts.
  4. A verified email. The weakest row, and last for that reason. It proves control of an inbox and nothing more.

Every one of those badges is tappable, and tapping it opens a breakdown showing what the number is made of — which shops, how many visits, when. A badge you cannot inspect asks for faith. A badge that opens into its own evidence asks you to check, and the checking is the point.

What the sheet says out loud

The breakdown sheet states plainly that no ID document has been checked. There is no eKYC on Korat, no passport upload, no government database lookup, and nothing anywhere in the product says "verified identity". Someone with all four badges has shown that shops will vouch for them, that they have spent money in the real world, that they hold a particular device and that they control an inbox. They have not shown their legal name, and we will not imply that they have.

The sheet also says something less obvious and equally important: the absence of a badge is not an accusation. Somebody who joined last week has no paid visits, and somebody who never eats out has none either. If a missing badge reads as a warning, the system has quietly become a score where new and private users start guilty. Saying so on the sheet is cheap; not saying so lets the interface imply what the data does not support.

A vouch, a family tag and a partner tag all share an awkward property: they are statements one person makes about another, published where third parties can read them. Left unguarded, that is a mechanism for publishing claims about strangers — and "X is my partner" can do real harm to someone who never agreed to it.

So none of them go live on assertion. A shop vouch, a family tag and a partner tag all sit in a pending state until the subject accepts. While pending, row-level security shows the record only to the two parties involved — nobody else can read it — and only the subject can change its status. The person being described decides whether the description is published. That costs a little friction and removes an entire category of abuse.

The controls that sit underneath the badges

Badges are the visible layer; the enforcement underneath is per-field. Every profile field cycles through public, friends and private, applied when somebody else loads the profile rather than as a display filter on your own screen. Albums, posts and stories carry their own visibility on top of that. Blocking removes a person from your chats and feed and takes you out of their Dating deck. Reporting is not limited to people: posts, comments, stories, messages and business pages can all be reported, choosing from a fixed list of reasons. And you can delete your own account from Settings — a request that can be cancelled, not a button you cannot undo. What is held about you in the first place, and what happens to it afterwards, is in the privacy notice.

Account creation is gated by a PDPA consent screen that must be scrolled to the bottom before it can be accepted, with a real decline path. Android permissions are explained on a pre-screen before the system dialog appears, so the request carries a reason at the moment you decide. Age gates, and what happens to a report involving a minor, are set out separately in the child safety standards.

Nothing on Korat verifies identity, and nothing is end-to-end encrypted. No ID document is checked, there is no eKYC, and there is no phone or SMS verification — that endpoint is not built. Messages, calls and files are protected by row-level security on the server, not by encryption only you can undo.

Uploaded media is publicly readable by URL. There are no signed URLs and no private buckets, so treat a photo you upload as something a person holding the link can open, whatever visibility the surrounding post carries.

Where the engineering account lives

This page is about the trust layer users see. The machinery underneath — how authentication works, how row-level security policies are written, how token-gated actions run through security-definer functions that check the token themselves, and how passkey verification is implemented — is a separate and much longer argument. It has its own page, written to the same standard: mechanisms rather than adjectives, and the unfinished parts labelled as unfinished.

Evidence rows
shop vouches · paid visits · device-bound passkey · verified email
Ordering
by cost to fake, strongest first
Who may vouch
businesses only — never an open user vote
Consent
vouches and family/partner tags stay pending until the subject accepts
Pending visibility
the two parties only, enforced by row-level security
ID checked
none — no eKYC, no document upload, no phone verification
Missing badge
explicitly not an accusation

Frequently asked questions

Why can't my friends vouch for me?

Because an open vouch button measures how many accounts someone was willing to create, not how trustworthy they are. A count anyone can add to is a count anyone can fake.

Only a business can vouch, because a business has a name, an address, a public page and reviews that get worse if it endorses carelessly. The cost of a dishonest vouch is what gives an honest one its meaning.

Does a badge mean Korat has verified who someone is?

No, and the breakdown sheet says so explicitly. No ID document has been checked anywhere on the platform. There is no eKYC.

Each badge states what happened — shops vouched, visits were paid for, a passkey is registered, an email was verified — and leaves the conclusion to you.

Someone I want to deal with has no badges. Should I be worried?

Not on that basis alone. A new account has no paid visits, and so does a long-standing user who rarely eats out. The interface states that a missing badge is not an accusation, because otherwise the system quietly starts new users off as suspects.

Badges are evidence for, not evidence against.

Can someone tag me as their partner without asking?

They can create the tag, but it does not publish. Family and partner tags — and shop vouches — stay pending until you accept, and while pending only the two of you can see the record at all.

Only the subject of the claim can change its status. Someone describing you does not get to decide whether the description goes public.

What if someone is harassing me?

Blocking hides their chats and posts and removes them from your Dating deck entirely, in both directions. Reporting is available from any profile, and from any single piece of content — a post, a comment, a story or a message.

Separately, per-field privacy lets you set each profile field to public, friends or private, and the setting is enforced when someone else loads your profile rather than only hiding things on your own screen.

Read the security page

Badges are the visible layer. The policies, definer functions and passkey verification underneath are written up in full.