Questions
Reasonable objections.
Scepticism about a verification tool is the correct posture.
How do I know your report is not simply made up?
You do not, and you should not have to. The verifier re-runs every recorded call from your browser against a node you choose. A fabricated answer shows up as a row that differs.
Why is there no overall safety score?
Because an unfalsifiable summary judgement is the problem. A score is derived by a method you cannot inspect from data you cannot see; if it is wrong you have no way to find out. Shipping one would make us the thing we are replacing.
Does a proxy finding mean a project is a scam?
No, and no report says anything of the kind. Upgradeability is a normal operational choice. It means reading the code tells you what the contract does today, not what it will do. Prill never uses the words scam, rug or honeypot as labels.
What happens if one of your checks is wrong about a real project?
It is the worst thing this product can do. So findings are observations with their evidence attached rather than verdicts, they carry a certainty grade, and anyone can re-derive them. A dispute is settled against the chain, not against us.
Why do I need to connect a wallet?
You do not, and you never will. Everything here is a read. Connecting a wallet to a tool that only reads is a habit worth breaking, not one to reinforce.
Why only one chain?
Because one chain that works beats four that half-work. The engine is chain-agnostic and adding one is adding a row to a table; the reason it is a short list is that each needs an endpoint we have actually measured.
A report I ran yesterday will not verify. Is something wrong?
Almost certainly not. This chain produces a block every tenth of a second and public endpoints retain about ten thousand of them — roughly seventeen minutes. Older state is gone, and the verifier says “partly checked” rather than pretending. An archive node answers.
Is this a security audit?
No. It reads state and bytecode; it does not read source or reason about logic, and it cannot see a backdoor in a path that does not execute. The full list of what it cannot see is its own page.
Can I use this from my own code?
Yes. GET /api/read/4663/<address> returns the same report the page renders, evidence included. No key, no account, no rate-limit tier.
Who is behind this and what is the business model?
There is no company, no funding and no revenue. Reports are free and always will be; the bonded-claim contract is written and not deployed. Anything else would be a claim we cannot back, on a site about not making those.