Trust has one design that every social product eventually proposes: let people vouch for each other. It is cheap to build, it produces a satisfying number, and it makes a profile feel alive. We rejected it on the record, for a single reason worth stating plainly, because it governs everything else on this page. A count anyone can add to is a count anyone can fake. An open vouch button measures nothing except how many accounts somebody was willing to create. Ten accounts made in an afternoon produce a profile that reads as more trustworthy than a real person with three genuine friends, and the badge has then done worse than nothing — it has laundered a stranger.
Only a party with something to lose may vouch
The replacement follows directly from the diagnosis. If the problem with an open vote is that a voter risks nothing, then the fix is to restrict vouching to a party that does. Only a business can vouch for a person on Korat. A business has a name, a physical address, a public page, a sales history and a body of reviews attached to it — all things that get worse if it hands out endorsements carelessly. It is not that shops are more honest than people; it is that a shop's vouch is attached to something it cannot cheaply abandon, and that attachment is the mechanism.
This is also why the badge label is written the way it is. It reads "vouched for by 3 shops" — a statement of what happened — rather than "trusted" or "verified", which are conclusions the reader is entitled to draw or not draw. The distinction sounds pedantic until you notice that every trust badge scandal has the same shape: a platform stated a conclusion its evidence could not carry, and users reasonably believed it.
The four rows, ordered by what it costs to fake them
A profile can carry four kinds of evidence, and they are displayed in a fixed order: strongest first, where strongest means hardest and most expensive to fabricate.
- Vouched for by N shops. The most expensive to fake, because it requires the cooperation of a business with a reputation attached to its name.
- N real paid visits across N shops. Money actually changed hands, and the platform recorded it. Faking this means spending real money at real businesses, which is a fraud with a genuine cost per unit.
- A device-bound passkey. Proves possession of a specific device with a hardware-held private key. Cheap for a legitimate user, awkward to scale across a farm of fake accounts.
- A verified email. The weakest row, and last for that reason. It proves control of an inbox and nothing more.
Every one of those badges is tappable, and tapping it opens a breakdown showing what the number is made of — which shops, how many visits, when. A badge you cannot inspect asks for faith. A badge that opens into its own evidence asks you to check, and the checking is the point.
What the sheet says out loud
The breakdown sheet states plainly that no ID document has been checked. There is no eKYC on Korat, no passport upload, no government database lookup, and nothing anywhere in the product says "verified identity". Someone with all four badges has shown that shops will vouch for them, that they have spent money in the real world, that they hold a particular device and that they control an inbox. They have not shown their legal name, and we will not imply that they have.
The sheet also says something less obvious and equally important: the absence of a badge is not an accusation. Somebody who joined last week has no paid visits, and somebody who never eats out has none either. If a missing badge reads as a warning, the system has quietly become a score where new and private users start guilty. Saying so on the sheet is cheap; not saying so lets the interface imply what the data does not support.
A claim about another person needs that person's consent
A vouch, a family tag and a partner tag all share an awkward property: they are statements one person makes about another, published where third parties can read them. Left unguarded, that is a mechanism for publishing claims about strangers — and "X is my partner" can do real harm to someone who never agreed to it.
So none of them go live on assertion. A shop vouch, a family tag and a partner tag all sit in a pending state until the subject accepts. While pending, row-level security shows the record only to the two parties involved — nobody else can read it — and only the subject can change its status. The person being described decides whether the description is published. That costs a little friction and removes an entire category of abuse.
The controls that sit underneath the badges
Badges are the visible layer; the enforcement underneath is per-field. Every profile field cycles through public, friends and private, applied when somebody else loads the profile rather than as a display filter on your own screen. Albums, posts and stories carry their own visibility on top of that. Blocking removes a person from your chats and feed and takes you out of their Dating deck. Reporting is not limited to people: posts, comments, stories, messages and business pages can all be reported, choosing from a fixed list of reasons. And you can delete your own account from Settings — a request that can be cancelled, not a button you cannot undo. What is held about you in the first place, and what happens to it afterwards, is in the privacy notice.
Account creation is gated by a PDPA consent screen that must be scrolled to the bottom before it can be accepted, with a real decline path. Android permissions are explained on a pre-screen before the system dialog appears, so the request carries a reason at the moment you decide. Age gates, and what happens to a report involving a minor, are set out separately in the child safety standards.
Nothing on Korat verifies identity, and nothing is end-to-end encrypted. No ID document is checked, there is no eKYC, and there is no phone or SMS verification — that endpoint is not built. Messages, calls and files are protected by row-level security on the server, not by encryption only you can undo.
Uploaded media is publicly readable by URL. There are no signed URLs and no private buckets, so treat a photo you upload as something a person holding the link can open, whatever visibility the surrounding post carries.
Where the engineering account lives
This page is about the trust layer users see. The machinery underneath — how authentication works, how row-level security policies are written, how token-gated actions run through security-definer functions that check the token themselves, and how passkey verification is implemented — is a separate and much longer argument. It has its own page, written to the same standard: mechanisms rather than adjectives, and the unfinished parts labelled as unfinished.
- Evidence rows
- shop vouches · paid visits · device-bound passkey · verified email
- Ordering
- by cost to fake, strongest first
- Who may vouch
- businesses only — never an open user vote
- Consent
- vouches and family/partner tags stay pending until the subject accepts
- Pending visibility
- the two parties only, enforced by row-level security
- ID checked
- none — no eKYC, no document upload, no phone verification
- Missing badge
- explicitly not an accusation