Transparent by design

The methodology

Every signal, score, and review on Arodus follows rules we publish openly. Risk and reviews are one system here, each built to make the other earlier. This page documents exactly how the system works and will grow as new modules launch.

Peer intelligence

Inside verified reviews

How Vendor Ratings

Are Calculated

The ratings on Arodus come from buyers with verifiable invoice history. ERP-verified spend is a more reliable signal than public reviews or self-reported surveys, and here is exactly how a vendor's rating is composed.

How the Arodus Score is built

One score from 0 to 100, showing where a vendor stands today. It combines three verified inputs, none of them self-reported.

Arodus Score = Risk + Verified Reviews + Spend Trajectory

01

Risk Sets the Score

Every vendor starts at 100 and loses points only when a verified event lands, each one linked to its source. The score leans on the worst dimension, so one serious problem is never averaged away by clean ones.

02

Verified Buyers Adjust It

The spend-weighted rating from buyers who actually pay the vendor moves the score, within published limits. Poor reviews carry more weight than glowing ones, since unhappy paying customers are the more reliable warning.

03

Spending Trajectory Confirms It

When buyers across the network quietly cut spend on a vendor, it often shows up before any news does. A sustained decline pulls the score down. Steady growth lifts it slightly.

Risk signals outweigh opinion. A vendor already in the Severe or Critical range cannot be lifted by good reviews or rising spend. Reviews count for more where more verified buyers stand behind them, sized to the company's scale; a thin panel moves a score only slightly. Deductions fade with time, and fade faster when the vendor's own paying customers keep paying and report no impact.

01

Only paying buyers count

Every rating traces to a buyer who actually paid that vendor. Receipts are the price of entry, which keeps out competitors, planted reviews, and anyone who never worked with them.

02

Ratings follow the money

A review's weight is the verified money currently behind it. When a buyer stops paying a vendor, their reviews keep counting for twelve months at the weight of the relationship they ended, praise and criticism alike, then retire. Recent, funded relationships shape today's rating most.

03

You know who's talking

Ratings are anonymous, but every contribution still shows the reviewer's organizational role and their verified annual spend tier, so you can judge whether the experience is relevant to your own relationship with that vendor.

04

Weighted by spend

The final vendor rating is not a simple average. Each review is multiplied by the reviewer's verified 12-month spend with that vendor, then divided by total active spend across all reviewers. Newer reviews count more than stale ones, and reviews from a relationship's first months carry partial weight. A $600k/year relationship shapes the score more than a $6k pilot, because proportional dependency is the real measure of trust.

Aggregate Rating = total of (each score × that buyer's verified spend) ÷ total verified spend

Calculated across all active, ERP-verified reviewers.

The third input: spend trajectory

Reviews are what verified buyers say. Spend trajectory is what they do with their money, read from the same verified ledgers.

01

What buyers do, not just what they say

Spend trajectory reads the payment behavior of a vendor's verified buyers across the network: growing, steady, shrinking, or leaving. It comes straight from ERP-verified bills and payments, so it is ledger fact, and it weighs more than any written opinion. A cluster of buyers cutting spend is the earliest warning most vendors ever show.

02

Drag is generous, lift is small

Falling spend and buyer departures pull a score down hard. Rising spend lifts it only a little, because growth mostly proves invoices were already committed, and praise is the easy direction to game. When ratings and payment behavior disagree, payment behavior wins.

03

Visible once the network can see

Spend signals appear only once enough verified buyers cover a vendor, and they strengthen as coverage grows. A thinly covered vendor's score rests on the public record alone; the network takes over vendor by vendor as buyers join.

The six risk dimensions

Every vendor is scored across six dimensions using verified evidence: official records, first-party statements, and network signals. Each dimension has defined event types and defined data sources. Record-based evidence and network signals (outages, reviews, and spend movement) are picked up on the same daily cycle, and the score updates once a day, on every plan.

01

Operational risk

Service outages, downtime, and degradation events, surfaced from vendor status pages and first-party disclosures, often before your team notices the impact downstream.

02

Cybersecurity risk

Data breaches, ransomware events, and critical CVE exploits, tracked across government alerts, breach filings, and official disclosures, often before they reach the press cycle.

03

Financial risk

Bankruptcy filings, liens and judgments, distress notices, and sustained market pricing below sector for public companies, surfaced from official records and market data.

04

Compliance and regulatory risk

OFAC sanctions, significant GDPR fines, active litigation, and government-mandated bans, monitored across official registries, court records, and watchlists.

05

Reputational risk

Executive misconduct, fraud claims, and public-trust events, scored only when an official record or first-party statement confirms them. Press coverage appears in your feed, labeled, and never moves a score.

06

Strategic risk

Major M&A activity, geopolitical exposure, and key executive departures, scored from official filings and first-party announcements.

Signal Integrity

How we verify every signal

Every signal is graded by how solid the evidence behind it is. Reported events reach your feed the day they break, so you hear about them early. Scores only move once there's a verifiable record.

01Moves scores

Official record

Court dockets, breach filings with a state attorney general, WARN layoff notices, SEC filings, and government sanctions or exclusion lists.

02Moves scores

First-party statement

A vendor's own status page, press release, or regulatory disclosure. A company admitting its own incident is evidence, not a rumor.

03Display only

Reported

Press coverage, crowd-sourced trackers, and unverified claims. These show up in your feed the day they break, labeled unverified, and never move a score.

Every scored event links back to its primary source, the docket, the filing, the disclosure, with the article that reported it credited underneath. The full score breakdown is visible in the product beneath every score, so you can always see which events produced the number.

Data transparency

What we read from your ERP

What We Read

From Your ERP

Arodus connects via OAuth and requests read-only permissions. Arodus reads at the bill level: your vendor records and the bills and payments behind them. You can revoke access at any time from within your ERP.

01

Vendor data

Vendor records

Vendor legal name, category, email domain, and account number. Contact names and addresses are read for matching and not retained. The domain deduplicates ERP entries, so AWS East and Amazon Web Services resolve to one vendor profile with a unified risk score.

Used for

Vendor identity, canonical mapping, deduplication, risk profile creation

02

Payment data

Bill and payment records

Vendor, invoice date, payment date, and payment amount in the bill's currency. We ingest at the bill level only and do not read line-item or SKU detail today. Used to verify active vendor relationships, calculate rolling 12-month spend per vendor, and determine peer review eligibility.

Used for

Spend verification, review eligibility, 12-month rolling spend, spend-weighted review aggregation

Read-only, scoped to your vendors. The field-by-field detail lives on the Trust page and on the OAuth screen before you connect.

Vendor health status taxonomy

Every vendor on Arodus carries a current health status, updated automatically as verified signals arrive. Status levels define both the severity of risk and the operational response required.

Healthy100–90
Operational TriggerRoutine monitoring. No action required.
Risk TriggersNo active verified signals across Operational, Cybersecurity, Financial, Compliance, Reputational, or Strategic dimensions. No financial-distress filings, clean compliance record, no pending litigation.
Warning89–75
Operational TriggerIncrease monitoring frequency, flag for quarterly review.
Risk TriggersEarly verified signals: minor compliance inquiry opened on the record (unfined); vendor-disclosed service degradation; executive departure confirmed by the company; market pricing slipping below sector for a sustained stretch (public vendors).
Degraded74–50
Operational TriggerNotify procurement team. Begin contingency planning.
Risk TriggersConfirmed moderate event: minor regulatory fine sized to the vendor's scale; regional data incident disclosed but contained; minor lawsuit filed; a sustained market-pricing decline against sector; verified buyer spend falling across the network.
Severe49–25
Operational TriggerEscalate to CPO/CFO. Initiate vendor replacement search.
Risk TriggersHigh-impact confirmed event: ransomware attack confirmed by the vendor or a regulator; major lawsuit with an adjudicated or settled amount that is material at the vendor's scale; WARN-scale layoffs; a deep, sustained market-pricing decline; OFAC preliminary inquiry opened; confirmed executive misconduct; large regulatory fine.
Critical24–0
Operational TriggerImmediate executive escalation: freeze new spend, activate continuity plan.
Risk TriggersExistential event: bankruptcy filing; OFAC sanctions imposed; confirmed mass data breach with PII exposure; criminal charges against executives; government-mandated ban; hostile acquisition by sanctioned entity.
InactiveN/A
Operational TriggerContract terminated or offboarded; archived, not scored.
Risk TriggersContract terminated, offboarded, or no spend in the last 12 months. Removed from active scoring. Historical data retained for audit purposes.

How scores recover

An event lands at full deduction the day it is verified, no exceptions. What happens next follows published rules: deductions fade with time, fade faster when the right evidence proves no harm, and never quietly disappear.

01

Deductions fade on published clocks

One-time events fade over months, on clocks that vary by type: operational incidents fade fastest, financial distress signals take longest. Ongoing conditions, like an active sanctions listing or open litigation, hold their full deduction until the condition verifiably ends, then clear. Official resolutions speed the fading: a dismissed case, a closed inquiry, a confirmed fix.

02

One judge per event type

Each event type has exactly one judge that can speed its fading, and only with evidence. For events whose real question is whether customers felt it, layoffs, executive departures, outage aftermath, the judge is the vendor's own paying customers: if verified buyers keep paying at steady levels over the following months, the deduction is fully faded within six months. For financial and legal-liability events at public companies, the judge is the market: no abnormal move against sector over the following weeks, fully faded within two months. Payment behavior outweighs ratings when the two disagree.

03

Some deductions never soften

Sanctions, insolvency, and fraud findings hold regardless of customer sentiment or market reaction, and cap the score outright while active. Data-breach deductions fade only through confirmed remediation and time, because the harm from stolen data arrives later, whatever anyone's stock or satisfaction says. And no amount of good evidence lifts a score above where it stood before the event.

04

Sized to the company, never estimated

Severity is always relative to the vendor's scale. Public companies are scaled by reported revenue from their filings; private companies by observed headcount. We never estimate a private company's revenue. A lawsuit's demand is an allegation, not a fact: litigation scores by its stage in court, and dollar amounts enter the math only when a judgment or settlement makes them real. Events too small to matter at a vendor's scale are recorded on the profile and score zero.

05

Faster fading is never erasure

The event stays on the profile and in the score history permanently; only its arithmetic fades. Anyone reading the profile still sees what happened, when, and why its weight changed.

06

Corrections

A vendor can dispute any listed fact. If the underlying fact is wrong, most commonly an event attached to the wrong company, the fact is retracted, the score recomputes the same day, and the retraction is logged. Disputes are resolved by review of the record; filing one changes nothing by itself.

See your vendors scored this way

We're onboarding our first companies by hand right now. Take the tour, leave your work email, and we'll get you connected.