Reputation Tower

How It Works

International methodologies. For each case.

Reputation Tower has been doing this work for years, on a case-by-case basis, before any of it became a system. What's below is that experience, turned into a method — and checked against the same standards intelligence analysts, fact-checkers, and auditors use for exactly this kind of work.

Detect — collecting information the way it’s actually done in OSINT work

Search engines are one source among many, not the whole picture. We pull from public registries, media archives, court filings, social platforms, image search, autosuggest, and closed channels — the private groups and forums where a coordinated attack usually gets organized before it’s ever public. The way we collect and log this follows the same principles set out in the Berkeley Protocol on Digital Open Source Investigations — the UN Human Rights Office’s own standard for gathering and preserving open-source information so it can actually be relied on later, not just skimmed once.

Adjudicate — the part almost nobody else actually does

A typical audit finds every negative mention, gives it a red flag, and hands you a long list. It treats a real regulatory investigation exactly the same as a fabricated smear site, and exactly the same as some unrelated stranger who happens to share your name. That’s not analysis. That’s just counting.

We ran our engine against a real client file recently — 428 sources, all flagged as “risk” by a standard audit. Once we checked who each source actually was and how credible it actually was, three quarters of that “risk” turned out to be noise: other people with the same name, and a compromat network recycling one fabricated story across dozens of domains. What was left — the real, confirmed regulatory action — we kept exactly as it was. We don’t erase real problems. We just stop pretending fake ones are real.

Why “everywhere” and “true” are two different questions

A fabricated story can rank #1 for fifteen different searches. A real problem can sit quietly on page three. Visibility and truth are not the same measurement — and here’s how the two combine in practice:

Highly visible + credible
A real, serious situation. This needs a response strategy, not a takedown request.
Highly visible + not credible
A coordinated smear. This needs delisting and a legal track if it's organized.
Barely visible + credible
Worth watching. Not urgent, but real.
Barely visible + not credible
Background noise. Not worth your time or ours.

We score these separately, on purpose, and never let one substitute for the other.

Remediate — turning the verdict into a plan

This is where years of our experience can be used. Every case is different — a coordinated attack needs a completely different plan from one outdated article from three years ago, or a digital profile that needs to be built from nothing. We lay out what needs correcting, what’s outdated, what’s fabricated and needs to go, and what the finished, accurate profile should look like. We build a strategy with a plan and checklist.

Standards & Methodology

We rely on the international and trustworthy standards and frameworks.

Source credibility
NewsGuard, the Journalism Trust Initiative (the EU's own reference standard for this), the Global Disinformation Index, and the International Fact-Checking Network — the same frameworks fact-checkers use to tell real journalism from disinformation. We run every source in your file through them, not just the ones that already look suspicious.
Source vs. claim, scored independently
The Admiralty Code — the NATO system for grading intelligence, in use since the 1940s and still standard today. Reliability of the source, credibility of the claim: two separate scales, never blended into one number that hides which part is actually shaky.
Evidence that holds up outside our own report
A screenshot proves nothing on its own — anyone can fake one. Ours are timestamped using RFC-3161, an independent trusted-timestamp standard, not your computer's clock. Geo-tagged, hashed, and recorded in an unbroken chain of custody, following the same collection principles set out in the UN's Berkeley Protocol on Digital Open Source Investigations. That's the bar used in actual investigations, not the bar most reputation reports bother clearing.
Checked, not just claimed
Two of our reviewers can look at the same case independently and land on the same conclusion — that's measured (Cohen's kappa = 0.617, “substantial agreement” on the standard scale), not something we're asking you to take on faith. The methodology itself is assessed under ISAE 3000, the international standard for independent assurance, and built to hold up under GDPR and the EU's Digital Services Act.

See what this looks like on an actual case.

Bring us a name, a company, or a portfolio. We'll run the method end to end and show you the result.

Ask our expert

Confidential. No obligation.