{"version":4,"rules":"0.1.1","status":"in_force","published_at":"2026-09-23T12:33:53Z","effective_at":"2026-09-23T12:33:53Z","summary":"Businesses that are answering come first, then those that are not. Within each, those whose record reaches 0.40 are ordered by it, and everyone else, newcomers included, follows in a shuffle that changes once a day and that anyone can reproduce. Near a place, the same order holds among the businesses within the radius. A record is the share of promises kept, estimated cautiously (the less evidence, the more cautious): a promise counts when it closes, recent evidence counts more than old, a customer who returns counts a little more but never much more, and what a verified customer's agent signed counts more than the business's own word. Nothing about the order can be bought, and nobody is ever removed from the directory.","order":{"listed":"status in (verified, unreachable) and verified_at is set","answering":"a ping within answering_hours and no failed manifest sweep since; once a business has sent a signed ping, only its signed pings count (unsigned ones are still answered 204 and kept as telemetry); a business that has never signed is answering by any ping","answering_hours":24,"not_answering_since":"the later of the last ping that counts and the last good manifest fetch","snapshot":"frozen every hour at :00 UTC; a business verified after :00 appears at the next snapshot","rank_score_int":"floor(score × 10^4 + 0.5)","ranked_from":0.4,"ranked_from_int":4000,"rank_shuffle":"the first 16 hex digits of SHA-256(\"\u003cYYYY-MM-DD\u003e:\u003cbusiness uuid, lowercase\u003e\") for the snapshot's UTC date, a string","rank_pos":"ROW_NUMBER() OVER (ORDER BY rank_answering DESC, rank_ranked DESC, CASE WHEN rank_ranked THEN rank_score_int ELSE 0 END DESC, rank_shuffle ASC, id ASC)","near":{"parameter":"near=lat,lng","radius_km":10,"radius_km_max":1000,"order":"rank_pos among the businesses within radius_km","distance":"distance_km, great-circle, on each listing"},"cursor":"base64url JSON {m, p}: the mode (rank or near) and the last rank_pos, continued in the current snapshot, so across :00 an entry may repeat or be skipped; any other cursor, including earlier formats, is 410 cursor_expired"},"score":{"method":"the Wilson score interval's lower bound","formula":"score = 0 if n = 0, else (p + z²/(2n) − z·√(p(1−p)/n + z²/(4n²))) / (1 + z²/n)","z":1.2816,"z2":1.64249856,"share":"p = K / (K + B), K and B the sums of x over kept and broken evidence","confidence_business":"n = f × Σx(word) + Σx(verified), f = min(1, word_cap_units / Σ(x/t)(word)); while releasing (R31), n ≤ release_units_per_month × full months since verification","confidence_person":"n = K + B","word_cap_units":50,"stored_decimals":6,"compared_as":"floor(score × 10^4 + 0.5)","computed":"nightly at 00:00 UTC from all evidence at that scoring_time; listings, presentations and signed pings read that snapshot","perfect_record":"n / (n + z²): 0.40 needs 1.10 units, 0.75 needs 4.93","counterparty_snapshot":"s is the counterparty's score in the previous night's snapshot, 0 on the first night and without record or identity"},"weights":{"piece":"x = o × t × q × r × d","outcomes":[{"code":"booking.completed","business":"kept","customer":"kept","o":1,"by":"the inbox"},{"code":"order.fulfilled","business":"kept","customer":"kept, when paid or free","o":1,"by":"the inbox"},{"code":"booking.cancelled_by_business","business":"broken","o":1,"o_with_notice":0.5,"by":"the inbox"},{"code":"order.not_fulfilled","business":"broken","o":1,"by":"the inbox"},{"code":"booking.no_show_business","business":"broken","o":1,"by":"a verified report that stands (§3.4)"},{"code":"order.not_received","business":"broken","o":1,"by":"a verified report that stands (§3.4)"},{"code":"promise.unclosed","business":"broken","o":1,"by":"the network, 9 days after the promise was due without an outcome (R30)"},{"code":"booking.no_show_customer","customer":"broken","o":1,"by":"the inbox"},{"code":"booking.cancelled_late_by_customer","customer":"broken","o":0.5,"by":"the inbox"},{"code":"order.payment_failed","customer":"broken","o":0.5,"by":"the inbox"},{"code":"order.charged_back","customer":"broken","o":1,"by":"the inbox"},{"code":"booking.cancelled_by_customer","o":null,"by":"the inbox"},{"code":"order.cancelled_by_customer","o":null,"by":"the inbox"},{"code":"order.lapsed","o":null,"by":"the inbox"}],"presumed":0.5,"presumed_when":"a kept outcome the system auto-completed (aut 1), or whose promise arrived over 24 h after its iat or after it was due; lifted when a verified acknowledgement token backs the outcome","time":[{"up_to_days":30,"t":1},{"up_to_days":182,"t":0.75},{"up_to_days":365,"t":0.5},{"up_to_days":null,"t":0.25}],"time_from":"age at scoring time from the evidence date: iat; a business's broken outcome max(iat, arrival − 24 h); promise.unclosed when recorded; a report its kept row's date","source":{"verified":2.5,"counterparty":"c = 1 + s × min(1, U / 5)","counterparty_full_at":5,"u":"for evidence about a business: its person's unrelated businesses (components with kept outcomes) outside this business's component; about a person: the business's other distinct customers, by customer key"},"repeat":{"formula":"min(cap, 1 + step·(m − 1)) / m","cap":3,"step":0.25,"customer_broken_cap":1,"pair":"per business–customer pair, side and ledger (kept apart from broken); the customer is the person's customer key, else the receipt sub"},"dispute":0.5,"never_counts":["cancelling in time","declines, expiries, quotes, messages, refunds, sandbox items","promise receipts and v1 receipts (stored, never scored)","amounts","the business's own items or email domain"],"which_outcome_stands":"per item and side, the greatest iat, then nonce, never arrival order; a business's broken outcome is final (a later kept one is a conflict); only a report that stands turns kept into broken","report_weighs":"a report that stands replaces the business's kept row at that row's weight, as verified evidence; disputed, it and the kept row each count d","contest_weighs":"a contested outcome counts d until the business withdraws it","customer_broken":"a customer's broken outcome (booking.no_show_customer, booking.cancelled_late_by_customer, order.payment_failed, order.charged_back) counts against them only when their email was proven by the outcome's date: by a code this network emailed (sign-in or recovery), for every business; or at the business that recorded it, for its own outcomes: its inbox, issuing or linking them with that address, said how it proved it (email_proof otp: a code it emailed there; dkim: DKIM-authenticated mail from it), or they presented there the key issued for the address, which rides on the first email to them. Otherwise it is stored and never scored, even once the email is proven later. Kept outcomes always count; evidence about a business is unchanged"},"timing":{"hold_days":30,"release_units_per_month":30,"release_month_days":30,"release_until_day":90,"unclosed_after_days":9,"business_notice_hours":24,"late_customer_cancel_hours":48,"late_promise_hours":24,"broken_dated_arrival_hours":24,"auto_complete_hours":48,"order_lapse_days":14,"order_due_days":30,"report_opens_hours":1,"report_window_days":90,"dispute_days":14,"future_iat_seconds":300,"rules_notice_days":15,"nightly":"00:00 UTC","rank_snapshot":"hourly at :00 UTC","shuffle":"daily, by the snapshot's UTC date"},"verified":{"routes":["vouched: the key is in the Web Bot Auth directory of a platform on recognised_platforms and made the item's own presentation","delegated: the key is delegated through the person's session to a pass of the item's person, who is established"],"recognised_platforms":[],"established":{"tier":"trusted","unrelated_businesses":3,"each_trusted_when_issued":true,"span_days":60,"email":"network-proven"},"related":["a registrable domain (the embedded public-suffix list, private suffixes included)","a receipt key, when each proved it holds it: a receipt or a signed request verified under it","an address in one IPv4 /24 or IPv6 /48 within 30 days, from pings signed by each, ignoring egress_ignored","at least half of the smaller one's customers, each counted by customer key or company domain only when this network proved their email with a code it sent, else as their own person","an operator record with a reason"],"mutually_unrelated":"in different connected components of the relation","psl_snapshot":"2026-09-23","private_suffixes":["surfingdog.ai","workers.dev","pages.dev","netlify.app","vercel.app","github.io","gitlab.io","herokuapp.com","fly.dev","onrender.com","web.app","firebaseapp.com","azurewebsites.net","azurestaticapps.net","appspot.com","cloudfunctions.net","run.app","deno.dev","up.railway.app","glitch.me","repl.co","ngrok.app","ngrok-free.app","trycloudflare.com","blogspot.com","myshopify.com","wixsite.com","square.site","carrd.co","framer.app"],"egress_ignored":["10.0.0.0/8","172.16.0.0/12","192.168.0.0/16","100.64.0.0/10","127.0.0.0/8","169.254.0.0/16","0.0.0.0/8","::1/128","fc00::/7","fe80::/10","173.245.48.0/20","103.21.244.0/22","103.22.200.0/22","103.31.4.0/22","141.101.64.0/18","108.162.192.0/18","190.93.240.0/20","188.114.96.0/20","197.234.240.0/22","198.41.128.0/17","162.158.0.0/15","104.16.0.0/13","104.24.0.0/14","172.64.0.0/13","131.0.72.0/22","2400:cb00::/32","2606:4700::/32","2803:f800::/32","2405:b500::/32","2405:8100::/32","2a06:98c0::/29","2c0f:f248::/32"],"customers_one_domain":"customers whose email shares a registrable domain that is not free mail count as one; evidence between a business and a customer of its own domain (its registrable domain or its contact_email's) never counts","not_observed":["hosted owner accounts: this network holds none, so tenants under a private suffix compare by registrable domain"],"acknowledgement":"only an acknowledgement token verifies: the ADR-016 counter-signature JWS over the receipt's sha, signed by a key that passes a route (for an SDK agent, the key it delegated); a forwarded acknowledge_receipt signature (agent_key, purpose ack) is stored and verifies nothing, and only the token stops a report (409 you_acknowledged_it)","customer_key":"customers are counted by customer key: the address with everything from the first + to the @ dropped, and at gmail.com and googlemail.com the dots too, as gmail.com; used for distinct customers, U for evidence about a person, r's pair for evidence about a business, and the overlap relation for customers whose email this network proved; identity (issuance, recovery, codes) keeps the exact address"},"tiers":{"business":{"trusted":{"min_score":0.75,"distinct_customers":10},"building":{"min_score":0.4},"new":"everything else, including no record"},"person":{"trusted":{"min_score":0.75,"unrelated_businesses":3},"building":{"min_score":0.4},"new":"everything else, including no record"},"distinct_customer":"a customer key (one mailbox) with a network-proven email, or presented at another, unrelated business","ranked":"a business is ranked, sorting before the shuffle, from building (R32)"},"limits":{"issuance_per_business_per_day":50,"passes_per_key_per_day":10,"instance_calls_per_minute":600,"presentations_per_person_per_business_per_day":20,"pass_strings":8,"pass_string_chars":200,"per_entries":8,"promises_per_business_per_day":10000,"unusual_use_businesses_per_24h":10,"signature_seconds":300,"signature_skew_seconds":60,"code_digits":6,"code_minutes":10,"code_tries":5,"codes_per_hour_per_address":3,"session_hours":24,"issuance_replay_days":7,"networks_per_inbox":8,"listing_limit_max":100,"unusual_use_signing_keys":2},"never_used":["advertising","payment, sponsorship or any other money","the amounts on receipts","anything a business's profile says about it, apart from the location a near search measures from","who is searching: every caller gets the same order for the same search"],"changelog":[{"version":2,"published_at":"2026-09-22T00:00:00Z","effective_at":"2026-09-22T00:00:00Z","summary":"The neutral order during the redesign: verified businesses newest first, near a place nearest first.","url":"https://network.surfingdog.ai/v1/ranking?version=2"},{"version":3,"rules":"0.1","published_at":"2026-09-23T08:43:18Z","effective_at":"2026-09-23T11:16:18Z","summary":"Network rules 0.1 (ADR-017): kept promises scored with confidence, answering businesses first, ranked from 0.40, everyone else in a daily shuffle.","url":"https://network.surfingdog.ai/v1/ranking?version=3"},{"version":4,"rules":"0.1.1","published_at":"2026-09-23T12:33:53Z","effective_at":"2026-09-23T12:33:53Z","summary":"Only a real counter-signature verifies a promise. Once an inbox signs its pings, only signed pings count. Stop linking businesses by contact email. One mailbox is one customer (ana+1@gmail.com counts as ana@gmail.com); shared customers link businesses by mailbox only once this network proved the address. A broken promise counts against a customer only once their email is proven: \"Someone using your email can't hurt you.\" In force the day it was published: ours was the only listed business.","url":"https://network.surfingdog.ai/v1/ranking?version=4"}],"next":null}