How trust works

Handing someone control is a real risk, and most platforms ask you to take it on vibes. This page explains exactly what our reliability score measures, how it is calculated, and where it stops — including the part we have not built yet.

The number

Every profile carries a reliability score from 0 to 100, based on the locks that person has worn: how many they saw through, and how many they walked away from.

The formula is public, because a trust signal you cannot inspect is not a trust signal:

score = (completed + 2.5) / (completed + abandoned + 5) × 100

Everyone starts at 50 — unproven, neither trusted nor suspected. The extra 2.5 and 5 are a deliberate drag: they stop someone with a 1-for-1 record from outranking someone who is 40-for-42. You have to actually accumulate history to move, in either direction.

The tiers

  • Unproven — no finished locks yet
  • Unreliable — below 45
  • Building — 45 to 64
  • Reliable — 65 to 84
  • Trusted — 85 and above

Unproven is not a warning. Everyone starts there, and plenty of excellent partners are new. It means the score has nothing to tell you yet, and you should ask questions instead of reading a badge.

What does not count

You can always end your own lock. That is deliberate and it is not going to change — being unable to get out of a chastity device is a safety problem, not a feature. Releasing yourself early also reveals your combination, which is your way out if a keyholder stops responding.

But an early release does not earn a completion. It records the time you actually served and nothing else: no credit, no movement in your score, no rewards. Otherwise the score would measure how many times you pressed two buttons, and a badge you can farm is worse than no badge at all — it turns an honest signal into a misleading one.

Locks that get abandoned

If a self-lock runs past its unlock time and goes quiet for 7 days, we warn the wearer. If nothing happens for another 7 days, the lock is closed as abandoned and it counts against that person’s score. Any activity during the grace period cancels it.

This is what stops the leaderboard filling up with locks nobody ever finished, and it is why the score means something.

What this score cannot tell you yet

Right now the score measures people as wearers. It reflects whether someone finishes locks they take on. It does not yet measure whether a keyholder shows up for the person whose key they hold.

That is the harder and more useful problem. One piece of it is live: if a keyholder-controlled lock sees no keyholder activity for 14 days, we warn the wearer. The warning does not end the lock and it does not touch anyone’s score.

The rest is still to build: an escalation path when a keyholder goes silent on someone who is locked, and a separate keyholder reliability score. Until that ships, a high score on a keyholder’s profile tells you they are a reliable wearer — not that they are a reliable keyholder. We would rather say that plainly than let you assume otherwise.

Track it on the roadmap.

Your data

Combinations are encrypted at rest and released only to the lock’s owner, and only once the lock is unlocked, completed or abandoned.

Verification photos are seen by the keyholder on that lock or a moderator. If the wearer shares a verification link, the people they send it to can also see the photo once they sign in, and only while the check is open; the wearer can turn the link off. Photos are served through short-lived expiring links rather than permanent URLs, so a copied image link stops working instead of circulating forever. Keyhold is not a content platform and sexually explicit imagery is not permitted — see the terms.

You can export or delete your account and its data at any time.

Keyhold is free to use — three active locks, multiple keyholders per lock, verification and trust scores at no cost.