Technical Architecture · February 2026

REF: The Trust Layer for Online Reviews

A comprehensive guide to how the Review Authentication Framework gives platforms cryptographically verifiable provenance signals for eligible customer-event attestations — explained for technical partners and stakeholders.

Prepared by
REF Protocol
Classification
Public
Version
1.0
Website
refauth.com
01 · The Problem

Fake Reviews Are a $770.7 Billion Crisis

Ratings and reviews are the single most important influence on consumer purchase behavior — 98% of consumers rely on them before buying. Yet roughly 30% of all reviews are fraudulent, and human readers can only detect fakes 54–60% of the time, barely better than a coin flip. Worldwide, fake reviews now cost consumers $0.12 on every dollar spent online.

$770.7B
Annual Global Consumer Harm
Capital One Shopping, Sept. 2025
30%
Of Online Reviews Are Fake
Capital One Shopping, 2025
$53,088
FTC Fine Per Violation
FTC, effective Jan. 17, 2025
1,900%
ROI on Fake Reviews
FTC Enforcement Data

The Federal Trade Commission's October 2024 rule (16 CFR Part 465) criminalized fake reviews, with inflation-adjusted penalties now reaching $53,088 per violation as of January 2025. The scale of harm is staggering and growing: a December 2024 economic analysis of just three US service sectors — Home Services, Legal, and Medical — found $300 billion in annual consumer harm from review fraud in those sectors alone (The Transparency Company / Dr. Roberto Cavazos, UNT). Meanwhile, AI-generated fake reviews have been growing 80% month-over-month since June 2023, making detection-based approaches increasingly futile.

Why Detection Is Failing

Every review platform today — Amazon, Yelp, Google, Trustpilot — relies on the same fundamental approach: collect all reviews, then try to detect and remove the fakes after publication. This is a losing game. Attackers adapt faster than defenders. AI-generated reviews are already indistinguishable from authentic ones. The damage — misdirected purchases, damaged reputations, regulatory exposure — happens before detection ever kicks in.

Property Detection Systems (Status Quo) REF (Authentication)
Approach Find and remove fakes after publication Block fakes before they can exist
Accuracy 54–60% (near coin-flip) Cryptographic certainty
Attacker cost per fake review Near $0 (marginal) Exponentially increasing
AI-resistant No — adversarial ML defeats ML Yes — math, not pattern matching
Scales with attacker budget Defender costs rise linearly Attacker costs rise exponentially
02 · The Core Insight

Solving the "Unpurchased Review Problem"

REF applies the same mathematical breakthrough that Satoshi Nakamoto used to create Bitcoin — but instead of preventing someone from spending a digital coin twice, REF prevents someone from reviewing a product they never bought.

The Satoshi Parallel

Bitcoin's double-spend problem: How do you prevent someone from copying a digital coin and spending it twice? Satoshi's answer: cryptographic proof, distributed consensus, and economic incentives that make cheating irrational.

REF's provenance problem: How do you distinguish a provenance-backed review from unverified feedback? REF combines cryptographic eligibility evidence, distributed validator consensus, and an economic deterrence model while preserving an open path for lawful unverified feedback.

The analogy is architectural, not an equivalence: both systems use cryptographic evidence, distributed agreement, and incentives, while REF retains explicit trust assumptions for attestation sources, key management, and integration policy.

The shift is fundamental. Instead of asking "Is this review probably fake?" after publication, REF asks whether the review carries protocol evidence linked to a configured eligible customer-event attestation. That evidence establishes provenance under stated assumptions; it does not independently prove that the underlying real-world event occurred or that the review content is true. The Three-Lane Architecture preserves an open path for unverified feedback alongside provenance-backed review states.

"REF is the anti-hallucination layer for commerce."
The infrastructure that can anchor AI-generated content to cryptographically verifiable provenance from an eligible customer event — without claiming that the content itself is true.
03 · How REF Works

The Five-Step Token Lifecycle

From a customer's purchase to a published authenticated review, here is every step of the REF verification flow — and what happens behind the scenes at each stage.

🛒
1. Purchase
Customer completes a transaction on a merchant's e-commerce platform.
T = 0
🔐
2. Token
REF generates a unique cryptographic token tied to this specific purchase.
T + ~1 min
⏳
3. Experience
A time-lock period ensures the customer actually uses the product first.
T + 7–30 days
✍️
4. Review
Customer submits their review along with their token to any review platform.
After experience period
✓
5. Verify
Distributed validators confirm the token is valid. Review is published as authenticated.
Real-time (<10ms)

What Happens Behind the Scenes

Step 1 — Purchase & Attestation: The process begins from a configured transaction signal (for example, a payment webhook) rather than a reviewer-authored assertion. The REF integration derives a purchase commitment (att_hash) from transaction data and the merchant's provisioned key signs the resulting attestation. A valid signature authenticates what that configured attestation source asserted under the signing key; it does not independently prove that the underlying real-world transaction occurred. Assurance therefore depends on attestation-source integrity, key custody, and the integration path.

Step 2 — Token Generation & Zero-Knowledge Proof: REF derives a token and nullifier from the attestation commitment and private randomness. A Groth16 proof can show that the private witness satisfies the configured circuit constraints without revealing the private witness values. The proof establishes circuit satisfaction under the stated cryptographic assumptions; it does not independently establish that the underlying real-world purchase occurred.

Step 3 — Experience Period (Eligibility Window): The circuit can enforce a configured eligibility window using its public timestamp inputs. Category-specific waiting periods are integration-policy parameters, not hard-coded circuit semantics. A configured delay can constrain immediate "buy-review-refund" strategies; it does not prove continued ownership or use after eligibility.

Step 4 — Review Submission: When the customer is ready to write a review, they present the REF token through an integration path supported by the review platform or merchant. The token format is designed to be platform-agnostic; this statement does not imply an existing integration or partnership with any particular review platform.

Step 5 — Distributed Verification: The review platform sends the token to REF's validator network. A committee of validators independently verifies the zero-knowledge proof, checks that the token's nullifier (a unique one-time-use identifier) hasn't been spent before, and reaches consensus through a Byzantine Fault Tolerant (BFT) protocol. If the required quorum validates the proof, a quorum certificate can be issued and the platform can apply a provenance-backed review status according to its policy. No production verification-time claim or service level is asserted here.

04 · The Architecture

Four Interlocking Security Layers

REF's architecture is a defense-in-depth design with four distinct layers. If any single layer were somehow compromised, the remaining layers still protect the system. Here is what each does and why it matters.

Layer 1 · Cryptographic

Purchase Attestation

Under the protocol, the merchant signs a purchase attestation with Ed25519. A valid signature authenticates that the attestation was signed by the corresponding merchant key; it does not independently prove that the underlying real-world transaction occurred. A valid merchant attestation is required for token issuance.

What it establishes: Attestation authenticity under the merchant signing key; it does not establish that the underlying real-world transaction occurred.

Layer 2 · Privacy

Zero-Knowledge Proofs

A Groth16 zero-knowledge proof lets the system verify that a witness satisfies the purchase-eligibility circuit without revealing the private witness values encoded by that circuit. Public inputs and surrounding protocol metadata remain visible as defined by the integration. Validators learn whether the proof verifies together with those public values; the proof does not independently establish the truth of the underlying real-world event.

What it protects: The circuit's private witness values from disclosure through the proof; public inputs and surrounding integration metadata remain visible.

Layer 3 · Consensus

Distributed Validation

Consensus requires a validator quorum rather than unilateral approval. Committee rotation is an intended deployment design; EV-008 does not model VRF selection or rotation. Under the model's n ≥ 3f + 1 assumption, safety is evaluated against up to f Byzantine validators within the checked bounded configuration.

What it constrains: Unilateral validator approval within the modeled quorum and fault assumptions; deployment security remains conditional on implementation and operating assumptions.

Layer 4 · Economic

Attack Cost Scaling

REF's economic layer is a mechanism-design model, not a universal real-world guarantee. Under the stated model, modeled capture cost is C(v,N)=C₀·eαv·Nγ and modeled reward is R(v)=k·ln(1+v). For α > 0, the guard α·C₀·Nγ > k is the condition under which modeled marginal capture cost exceeds modeled marginal reward for all v ≥ 0. Any merchant-bond or validator-staking mechanism would require separately specified production parameters and enforcement terms; none are established by this analytic guard.

What it models: Economic deterrence against repeated attacks under explicit assumptions; it does not establish that real-world fraud farms, arbitrage, or sustained campaigns are impossible or unprofitable.

Non-Technical Analogy: The Bank Vault

Think of REF like a modern bank vault. Layer 1 (Cryptographic) is the vault door — you need the right key to enter. Layer 2 (Privacy) is like frosted glass — guards can confirm you belong without seeing what's inside your safety deposit box. Layer 3 (Consensus) is the requirement that multiple guards must independently agree to open the vault — no single guard can act alone. Layer 4 (Economic) is the alarm system and insurance — even if someone breaches the vault, the mechanism layer is designed to raise modeled attack costs under explicit assumptions; it does not establish a universal real-world profitability bound.

05 · Defense in Depth

Protocol Defenses & Integration Posture

REF is pure B2B authentication infrastructure. It does not analyze review content, profile reviewers, or moderate opinions. Its defense layers are structural — rooted in cryptography, economics, and temporal enforcement — not heuristic pattern matching.

Protocol Defense Layers

01 Cryptographic Eligibility Gate Cryptographic ▼
The foundational layer. A provenance-backed review status can be applied when the configured eligibility proof verifies together with the required attestation evidence. The proof establishes circuit satisfaction under the stated assumptions; it does not independently establish the truth of the underlying real-world event.
02 Experience Period Controls Cryptographic ▼
The circuit enforces a configured eligibility window over public timestamps. Example waiting periods are integration-policy choices, not hard-coded category rules. A configured delay can constrain immediate "buy-review-refund" strategies but does not prove continued ownership or use after eligibility.
03 Economic Defense Matrix Economic ▼
The stated model uses R(v)=k·ln(1+v) and C(v,N)=C₀·eαv·Nγ. For α > 0, marginal modeled capture cost exceeds marginal modeled reward for every v ≥ 0 iff α·C₀·Nγ > k. Because modeled capture cost is already positive at v=0, satisfying this guard is a conservative sufficient condition for modeled attack payoff to remain negative over the domain. All 500 archived parameter rows satisfy the guard; the minimum observed ratio is 652.217×. Generator lineage for those archived rows is not established in the current repository.
04 Consensus Verification (PBFT) Cryptographic ▼
Distributed validator network using Byzantine Fault-Tolerant consensus. No single validator can unilaterally approve a proof. The current implementation test network uses four nodes; this implementation topology is distinct from the abstract EV-008 model. The protocol fault model requires n ≥ 3f + 1 and a quorum of 2f + 1. EV-008 records a bounded single-view TLC run (MaxView=0) with 152,658,351 states generated, 17,588,825 distinct states, depth 31, queue exhausted, and no error found for Agreement, LockedValueSafety, UniqueHonestProposalPerRound, and PrepareVotesReferenceProposals. The result is scoped to that bounded safety configuration; it is not an unbounded protocol proof and does not establish liveness.
05 Merchant Bond & Progressive Trust Economic ▼
Performance security deposits are a proposed mechanism-design control, not a current merchant requirement. Illustrative tiers are $10,000 (Tier 1, full platform integration), $25,000 (Tier 2, partial API), and $50,000+ (Tier 3, self-attesting). Under any production agreement, forfeiture conditions would need to be defined contractually and tied to attributable evidence. The 40–60% bond-floor range is an illustrative model parameter intended to support economic deterrence under the stated assumptions; production terms have not been established.
06 Cross-Platform Intelligence Operational ▼
Nullifier-based deduplication across the REF network. When a token is consumed on one platform, its nullifier is recorded by consensus — preventing the same purchase from generating verified reviews on multiple platforms. Attackers cannot simply move from Trustpilot to Google Reviews.
07 Network Effects Amplifier Operational ▼
Security increases superlinearly as the network grows, modeled as Nγ where γ ≈ 2.3. The larger the validator set, the more expensive attacks become and the cheaper legitimate verification gets. REF becomes harder to attack at scale — the opposite of most systems.

The Three-Lane Integration Model

REF operates as a trust layer, not a speech gate. The Three-Lane integration model preserves an open path for unverified feedback while distinguishing provenance-backed reviews. Platform partners remain responsible for their own legal and regulatory compliance.

L1 Lane 1: Verified Purchase Cryptographic ▼
Provenance-backed lane. In the proposed integration model, reviews carrying a zero-knowledge proof bound to configured eligibility evidence derived from a payment-processor transaction signal, subject to attestation-source integrity, can receive the highest provenance weight under platform policy. Example badge: "Provenance-backed — This review carries cryptographic eligibility evidence via REF."
L2 Lane 2: Verified Experience Operational ▼
Non-purchase interactions. Reviews backed by a merchant-attested interaction (customer support ticket, warranty claim, cancelled order). Cryptographically proves an interaction occurred even if money didn't change hands. Badged: "Verified customer experience — Verified interaction with this business."
L3 Lane 3: Unverified Public Feedback Open ▼
Open feedback lane. An open feedback channel for users without cryptographic tokens. REF does not require protocol provenance as a prerequisite for speaking; it distinguishes provenance-backed status from unverified feedback. This design is not a legal safe harbor, and platforms remain responsible for their own policies and compliance.
06 · Attack Economics

Economic Deterrence Under Model Assumptions

REF's economic model evaluates a sufficient dominance condition under explicit assumptions. When the stated condition holds within the modeled parameterization, the modeled honest strategy dominates the analyzed attack payoff.

The Dominance Condition

In the stated mechanism model, attacker reward is represented by R(v)=k·ln(1+v), while modeled capture cost is C(v,N)=C₀·eαv·Nγ. The logarithmic reward and exponential cost shapes are model definitions used for this analysis, not empirically established laws of real-world fraud economics.

Under the model, when the stated cost condition dominates the modeled reward function across the relevant parameter domain, the analyzed attack strategy is economically dominated over that domain. This is the dominance condition:

α · C₀ · Nγ > k
If this inequality holds, honest behavior dominates fraud at every scale

In plain English: if the cost-scaling rate (α) times the base attack cost (C₀) times the modeled network factor (N raised to the power γ) exceeds the maximum reward curvature (k), the model predicts that the analyzed attack payoff is dominated by the honest strategy under those assumptions. The conclusion is conditional on the model, parameterization, and attack scope.

Why Does This Work?

Four modeled properties contribute to this economic deterrence result:

Exponential cost scaling (α): In the stated mechanism model, C(v,N)=C₀·eαv·Nγ, so modeled capture cost grows exponentially in v when α > 0. This is a model structure, not evidence that every real-world fraudulent review requires a real purchase or that deployment costs follow the function exactly.

Modeled network factor (Nγ): In the stated mechanism model, Nγ scales modeled capture cost. This parameterized term does not establish that adding validators, merchants, or transactions necessarily increases real-world security or attack cost.

Diminishing attacker returns (k): The hundredth fake 5-star review doesn't help a merchant nearly as much as the first one. Logarithmic rewards mean attackers hit a ceiling of benefit quickly while costs keep rising.

Mandatory real-money commitment: Unlike detection-based systems where you can generate unlimited fake content at near-zero cost, REF requires actual purchases (real money) as the prerequisite for every single review token.

Archived Dataset Evaluation

The analytic mechanism guard is evaluated against the locked MC-500 dataset. All 500 archived parameter rows satisfy α·C₀·Nγ > k; the minimum observed ratio α·C₀·Nγ/k is 652.217×. This is a result about the archived parameter rows, not a claim that strategic behavior was simulated or that a random-sampling process has been provenance-closed. Generator lineage for the archived rows is not established in the current repository.

The reported statistics are recomputable from the locked CSV. The provenance of the process that generated those 500 parameter rows is not established in the current repository, so no claim about the sampling process is made here.

07 · Business Model

"Stripe for Review Authentication"

REF is pure B2B infrastructure. We don't host reviews, compete with platforms, or require consumer accounts. We provide the authentication layer that makes the entire review ecosystem trustworthy — the same way Stripe provides the payment layer that makes e-commerce work.

How REF Earns Revenue

REF generates revenue through three complementary streams: SaaS subscription fees from merchants, merchant performance security deposits that create economic alignment, and platform licensing agreements.

Starter
$299/mo
Up to 10,000 verifications
  • Core Verification API
  • Standard nullifier checks
  • Email support
  • 99.5% uptime SLA
Scale
$2,999/mo
Up to 1,000,000 verifications
  • Dedicated infrastructure
  • Custom experience time-locks
  • Validator network dashboard
  • Illustrative production target: 99.99% uptime SLA
Enterprise
Custom
Unlimited verifications
  • On-premise deployment option
  • Custom consensus configuration
  • Dedicated integration team
  • 24/7 priority support

Merchant Performance Deposits

A performance security deposit is a proposed mechanism-design option, not a current merchant requirement. Illustrative tier values are $10,000 (Tier 1, full platform API integration), $25,000 (Tier 2, partial API), and $50,000+ (Tier 3, self-attesting merchants without platform cross-validation). Under a production agreement, any forfeiture conditions would need to be defined contractually and tied to attributable evidence. The 40–60% bond-floor range is an illustrative model parameter intended to preserve economic deterrence under the stated assumptions; production terms have not been established.

Unit Economics

99.5%
Gross Margin at Scale
$0.0001
Cost Per Verification
25.8×
Illustrative LTV/CAC Ratio
<30 days
Illustrative Payback Period

The cost structure is fundamentally software-like: cryptographic operations cost $0.00008, validator consensus costs $0.00003, and total marginal cost per verification is approximately $0.000123. This creates extraordinary gross margins that improve with scale.

08 · Competitive Moat

Structural Barriers to Incumbent Replication

Big Tech possesses the engineering talent to build cryptographic systems, but is blocked by a fundamental incentive misalignment. REF's defensibility is rooted in structural asymmetry: an independent protocol can enforce strict authentication, whereas an incumbent platform cannot do so without cannibalizing its own engagement metrics.

Big Tech Cannot Be the Neutral Referee

Google, Amazon, and other platforms that host reviews have an inherent conflict of interest: they profit from review volume (advertising, engagement, transactions), not review quality. Building review authentication would mean reducing their own review volume, scrutinizing their own merchants, and creating an adversarial relationship with their revenue base. Just as Stripe succeeded because it wasn't owned by any bank, REF succeeds because it isn't owned by any platform.

This is not just a strategic disadvantage for Big Tech — it's a cognitive barrier. Consumers intuitively distrust authentication from the same company that profits from the content being authenticated. Independent certification authorities (like VeriSign for SSL, Moody's for credit) are trusted precisely because they have no stake in the outcomes they certify.

Five Compounding Moats

Moat Type Description Strength Over Time
Cryptographic Depth Zero-knowledge proofs, BFT consensus, formal verification — years of specialized engineering that cannot be replicated quickly Increases (more verified properties)
Network Effects Design objective: a larger, diverse validator set can reduce concentration risk when the protocol's fault-model assumptions continue to hold; production network scale has not yet been established Increases (Nγ scaling)
Switching Costs Merchant bonds, API integration, validator relationships, compliance frameworks — deeply embedded in operations Increases (deeper integration)
Regulatory Alignment Positioned as the compliance infrastructure for FTC Rule 465 — setting the standard that the market converges on Increases (regulatory evolution)
Neutral Positioning As an independent infrastructure provider, REF can serve all platforms equally — something no platform owner can credibly offer Permanent structural advantage
09 · Verification Evidence

Rigorous Digital Engineering

REF applies a Rigorous Digital Engineering (RDE) approach to its verification program. The current evidence bundle covers specific properties, models, artifacts, assumptions, and bounded analyses; results should be read within those stated scopes. Here is the current evidence.

Security Properties and Verification Status

Property What It Establishes Evidence / Method
Authenticity Every review is bound to a real purchase Ed25519 signature verification + ZK proof binding
Uniqueness One purchase = one review (no duplication) TLA+ model checked (269 states, 0 violations)
Integrity Finalized reviews cannot be altered TLA+ model checked (152 million states, 0 violations)
Privacy The proof hides the circuit's private witness values; public inputs and surrounding protocol metadata remain visible Groth16 zero-knowledge assumptions + documented circuit public/private signal boundary (EV-011)
Incentive Compatibility Under the stated model, the marginal capture-cost guard can be established analytically; universal strategy dominance for all actors is not established Analytic mechanism guard + locked 500-row parameter dataset (500/500 archived rows satisfy guard)
Individual Rationality Participating in REF is better than the status quo FTC penalty avoidance ($53,088/violation) + trust uplift

Phase 1 Evidence Register

REF's Phase 1 evidence register comprises five hash-locked evidence bundles stored in the version-controlled repository; assurance scope differs by artifact:

Consensus specification (TLA+ v1.9): formally models the consensus protocol with Propose→Prepare phase separation, Byzantine fault actions, and quorum math. EV-008 provides bounded single-view model-checking evidence for four safety invariants; the recorded run found no error. It does not establish unbounded safety or liveness.

Token lifecycle model: bounded TLA+ model checking evaluated seven invariants with zero violations in the recorded run, including one-purchase-one-review and at-most-one-token-per-purchase properties.

Mechanism design analysis: under the stated model and α > 0, marginal modeled capture cost exceeds marginal modeled reward for all v ≥ 0 iff α·C₀·Nγ > k. All 500 archived parameter rows satisfy that guard; the minimum observed ratio is 652.217×. This public claim concerns the locked dataset, not an asserted random-sampling process.

Internal ZK circuit constraint audit (EV-011 v2.1): 1,155 constraints; eight findings documented. The v1.1 record shows code changes for F-001, F-002, F-004, F-005, and F-007; F-003 is documented for a v2 fix, F-006 as a v1 design boundary, and F-008 is monitored. All 8/8 recorded negative vectors were rejected.

Threat model (v1.0.1): structured enumeration of the current in-scope adversary model, attack scenarios, documented defects, and mitigations, with property/evidence mappings where recorded.

External Validation Roadmap

REF has done the verification work that typically only happens post-Series A, as a pre-fundraising investment in credibility. This is the level of rigor expected of cryptographic infrastructure — and REF has it before going to market. A scoped external attestation engagement (Trail of Bits or Veridise, $100–175K) is budgeted as a Series A use of funds to provide third-party validation.

10 · Who Uses REF

Three Customer Types, One Infrastructure

REF serves a two-sided market of merchants and review platforms, with consumers benefiting transparently. Here is how each stakeholder interacts with the system.

For Merchants (E-commerce Businesses)

The integration model supports merchant connection through an API or SDK. Under the planned production workflow, an eligible customer event can trigger issuance of protocol evidence for later review authentication. Business outcomes, regulatory effects, conversion lift, and implementation timelines are not established production results and should be evaluated through pilots and partner-specific review.

For Review Platforms (Trustpilot, Google, Yelp, etc.)

Review platforms can integrate REF's verification API so that protocol evidence accompanying a review can be submitted for validation. No production verification-time claim or SLA is asserted here. The resulting signal establishes protocol provenance under the configured rules. Operational and economic benefits remain to be validated in production pilots.

For Consumers

Consumers don't need to do anything differently. After purchasing, they receive a review link (via email or in-app) that contains their embedded token. When they click through and write a review, the token is automatically presented to the platform. The experience is seamless — and the "Verified Purchase" badge gives them confidence that every other review they read on the platform is equally authentic.

Target Market

REF targets mid-market businesses ($10M–$500M revenue) facing FTC compliance challenges, with expansion into enterprise accounts. The total addressable market spans $4.8 trillion in global e-commerce, with $770.7 billion in annual consumer harm from fake reviews. REF's initial beachhead is Shopify Plus merchants (25,000 potential accounts) and Trustpilot enterprise clients (8,500 potential accounts).

$4.8T
Global E-commerce TAM
98%
Consumers Rely on Reviews
0%
Of Transactions Currently Authenticated
$25M
Series A Target