Methodology

Coordination Integrity Scores

Commons computes five coordination readings from campaign data for the organization running the campaign. These diagnostics measure whether participation is organic, diverse, and sustained — or manufactured, concentrated, and bursty. They are not included in the message a recipient receives, and no reading is self-reported.

These readings can invert: a machine-distributed campaign can score higher than an organic one. They are diagnostics for the organization running the campaign, not a measure of legitimacy. No action available. Both directions of this reading are ambiguous.

Geographic Diversity Score

GDS

Measures how spread out participants are across legislative districts. Computed as 1 − HHI, where HHI is the Herfindahl–Hirschman Index — the sum of each district's share squared.

ScoreInterpretation
0.90+Actions span many districts evenly
0.50–0.89Actions span several districts, with some district clustering
< 0.50Concentrated in few districts

Privacy: Computed from one-way district hashes, never addresses. No minimum-count floor is applied to districts, so a district with one action can appear. Neighborhood-level (H3 cell) counts are withheld below 5 actions.

Message Authenticity

ALD

Measures how many message hashes are distinct. Computed as the ratio of unique message hashes to total message hashes; repeated hashes lower the ratio.

ScoreInterpretation
0.90+At least 90% as many distinct message hashes as messages
0.50–0.89Between 50% and 89% as many distinct message hashes as messages
< 0.50Fewer than 50% as many distinct message hashes as messages

Privacy: Only message hashes are compared, never content.

Timing Pattern

H(t)

Measures how participation is distributed over time using Shannon entropy over hourly buckets.

NormalizedInterpretation
0.65+Actions are distributed across multiple hourly buckets
0.33–0.64Actions have some temporal spread and some clustering
< 0.33Nearly all actions in a narrow time window

Action Rate

BV

The ratio of the peak hourly action count to the average count across hourly buckets that contain actions.

ScoreInterpretation
1.0–2.0The peak hourly count is up to twice the active-hour average
2.0–5.0The peak hourly count is between two and five times the active-hour average
5.0+The peak hourly count is at least five times the active-hour average

Engagement Depth

CAI

The ratio of actions from participants in the Veteran and Pillar tiers to actions from participants in the Active tier. It describes the participation-history mix recorded by Commons.

ScoreInterpretation
0.50+Veteran- and Pillar-tier actions amount to at least half the Active-tier action count
0.10–0.49Veteran- and Pillar-tier actions amount to between one tenth and just under half the Active-tier action count
< 0.10Veteran- and Pillar-tier actions amount to less than one tenth of the Active-tier action count

Engagement tiers (0–4) measure platform participation history, not identity verification level.

What These Scores Never Reveal

  • No individual addresses. Geographic diversity is computed from hashed district identifiers. The hash cannot be reversed to an address.
  • No message content. Message authenticity compares SHA-256 hashes. No text is stored or compared.
  • No individual attribution. Scores are aggregates. There is no way to trace a score back to a specific person.
  • Privacy floors are specific. Neighborhood-level (H3 cell) counts and engagement-tier counts are withheld below 5 entries; district-level counts have no minimum-count floor.

What Commons Does With Your Data

Plain-language summary of how we collect, use, and retain personal data. Full Terms of Service and Privacy Policy documents are forthcoming; until they ship, this section is the canonical disclosure on the Commons domain. Companion technical detail lives in our security limitations doc.

  • Legal basis (GDPR Art. 6(1)): we process address fields under our legitimate interest in district verification (Art. 6(1)(f)) and your account email under contract performance for authentication (Art. 6(1)(b)). For users in the EU/UK we honor the standard GDPR rights (access, rectification, erasure, portability, objection); contact information is on the homepage.
  • Address fields — mDL path: when you verify with a state-issued mobile driver's license, your wallet shares postal code, city, and state with our servers. Those fields are used to derive your congressional district and may be represented afterward as encrypted ground-vault material and disclosed district/cell metadata. We do not store identity documents or keep plaintext address fields at rest.
  • Address fields — Shadow Atlas path: your browser computes a cryptographic commitment to your district. Approximate coordinates may transit our servers briefly so we can confirm the district mapping is authentic. After successful attestation, the address can be saved as encrypted ground-vault material for future delivery.
  • What we persist: a one-way district hash, disclosed district/cell metadata, encrypted ground-vault material, your account email (for sign-in and anti-sybil), engagement-tier counters, the actions you take through the platform, and operational logs stripped of plaintext address fields.
  • Hardware-isolated processing (TEE / enclave) is on the roadmap; today the address-resolution and proof-witness paths run in our standard server runtime. Our retention commitment for raw address fields (seconds, not minutes) holds in both architectures.
  • We do not currently sell your data, and we have no plans to. If our practices change in any way that would constitute a "sale" or "share for cross-context behavioral advertising" under CCPA, we will provide at least 30 days' notice via in-product banner and email before the change takes effect. We do not use third-party advertising trackers. We use minimal first-party analytics and operational telemetry.
  • mDL verification is currently feature-flagged off; the surface is not reachable in production. When it goes live, replay and relay limits are documented in our KNOWN-LIMITATIONS file (F-1.3). Full DeviceAuth verification (T3) is a launch checkpoint.

commons.email — verification-backed civic coordination