Source reliability, credibility, and confidence.
Liberty91 makes three separate trust judgements, and they answer three different questions. Reliability asks who said it. Credibility asks how well-supported the claim is. Confidence asks how sure we are about a specific indicator. They are computed differently, they move for different reasons, and reading one as a proxy for another is the usual source of confusion. This page is the canonical definition of all three.
| Judgement | Attached to | Scale | Moves when |
|---|---|---|---|
| Source reliability | The source | A to F | The source is corroborated or discredited over time |
| Credibility | The Threat Event | 1 to 6 | New reporting corroborates or disputes the occurrence |
| Confidence | The indicator | 0 to 100 | An enrichment vendor returns a verdict |
What is the Admiralty scale?
Reliability and credibility both come from the Admiralty scale (also called the Admiralty code), a long-standing intelligence convention that rates two things independently:
| Source reliability | Information credibility | ||
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Cannot be judged |
A rating is written as a letter and a number. For example, B2 means a usually reliable source reporting information assessed as probably true.
Reliability belongs to the source
Reliability (A to F) is a property of the source, not of any one story it runs. A government CERT and an anonymous forum post do not carry the same weight, and that judgement applies across everything they publish rather than being re-argued story by story. It sits on the source itself, whether that is a Module feed or an individual RSS source.
Where a grade starts
Every source begins at a grade appropriate to its class:
| Source class | Starting grade | Meaning |
|---|---|---|
| Government | A | Completely reliable |
| Vendor | B | Usually reliable |
| News | C | Fairly reliable |
| Anything else | C | Fairly reliable |
These are starting positions rather than fixed verdicts. A grade is a running assessment, and the platform moves it as the source earns or loses standing.
How a grade moves
A source is promoted on evidence. Each time it is independently corroborated on a Threat Event, meaning other sources reported the same occurrence and the account stood up, it earns a validation credit. After five consecutive credits its grade improves by one band, and the credit count starts again. Promotion stops at A: nothing rises above completely reliable.
A source can also be discredited by an analyst. That is a deliberate call, and it is treated as one. Discrediting drops the grade one band immediately, and it permanently caps that source at B thereafter, so a source you have caught out can recover to usually reliable but never to completely reliable again.
Grade changes are not cosmetic. Because credibility is computed from the reliability of the contributing sources, a change to a grade ripples back through the credibility of every Threat Event that source has contributed to.
A worked example. A regional news outlet enters the platform at C, fairly reliable. Over the following months it is independently corroborated on five separate Threat Events in a row, so it is promoted to B. It then runs a breach story that an analyst establishes did not happen and discredits it. The grade falls back to C, and its ceiling is now fixed at B: five more clean corroborations will take it back to B, and no further.
A reliable source can carry an unverified claim
The clearest illustration the platform has is the Ransomware.live module, which collects the victim claims ransomware groups publish on their own leak sites. Liberty91 grades ransomware.live at B, usually reliable, because it reports faithfully what the leak site said. What it reports is an attacker's assertion: the group may be exaggerating, recycling an old breach, or naming the wrong company entirely.
Both readings are correct at once, and they belong on different axes. Reliability B describes the aggregator. Credibility describes how well-supported the claim about that victim is, and on a claim nobody else has reported it stays low until other reporting corroborates it. This is why alerts generated from these claims spell out that they are unverified leak-site claims: a reliable pipe carrying an unproven message is exactly the case the two-axis scale exists to express.
Where you see it
Reliability shows on every report attached to a Threat Event, as the grade letter with its meaning spelled out on hover, so a source graded B reads as usually reliable without you needing to remember the scale. Each report also carries its source's own icon, which makes a leak-site post recognisable in the list at a glance.
Credibility belongs to the occurrence
Credibility (1 to 6) is a property of the Threat Event, the real-world occurrence itself, and it is computed across every report attached to it. The platform shows the band together with its meaning, so a Threat Event rated 2 reads as probably true.
| Rating | Label |
|---|---|
| 1 | Confirmed |
| 2 | Probably True |
| 3 | Possibly True |
| 4 | Doubtful |
| 5 | Improbable |
| 6 | Cannot be judged |
A Threat Event with nothing to judge yet shows a dash rather than a rating.
How it is computed
Only public, attributable reporting counts towards credibility. Reports that turn out to be the same story re-published are collapsed to a single source, so circular reporting cannot manufacture confidence that is not there.
Each remaining source then contributes weight along two dimensions. Its reliability sets the base weight, running from a full share for an A-rated source down to a token share for an F-rated one. Its stance scales that weight by what the report is actually doing: a report that claims or corroborates the occurrence counts in full, one that merely updates a known occurrence counts for rather less, and one that mentions it in passing counts for least of all.
The weights are summed and banded. In practice that means:
- One moderately reliable source on its own tops out at 3, Possibly True. A single account, however well written, is a single account.
- Two independent fairly reliable sources reach 2, Probably True.
- 1, Confirmed requires several reliable, genuinely independent sources.
- An attributable dispute from a credible source knocks the rating down a band.
What to do with it
Treat 1 and 2 as actionable, 3 as something to watch and corroborate before you act on it, and 4 to 6 as low-trust. Always read the credibility alongside the reliability of the sources underneath it: a 3 carried by an A-rated government source is a different proposition from a 3 carried by three D-rated aggregators, even though the band is the same.
Credibility moves as reporting develops, which is what you want from an assessment of something still unfolding.
Confidence belongs to the indicator
Confidence (0 to 100) is a property of an individual indicator, and it answers whether that indicator is genuinely malicious. Unlike the two ratings above it has nothing to do with the Admiralty scale: it starts from how clearly the indicator was stated in the source report and rises as independent enrichment vendors confirm it, with a hard cap applied if any vendor reports it as benign. It is also distinct from the indicator's decaying score, which measures freshness rather than certainty.
The full calculation is on IOC enrichment and decay scoring.
How Liberty91 uses these ratings
When an event is deemed relevant to an Intelligence Requirement, a threat entity, asset, or supplier, the platform assesses the source and the data and assigns an Admiralty rating. That rating becomes a weight in the knowledge base, so well-sourced information shapes the analysis more than weak or unconfirmed reporting. This is one of the ways the platform keeps its knowledge grounded and reduces hallucination in the products it generates.
You can read more about the original decay and weighting research on the CIRCL Decaying Indicators of Compromise work that informs Liberty91's IOC scoring.
Frequently asked questions
What scoring system does Liberty91 use to rate sources?
Liberty91 uses the NATO Admiralty scale, which rates source reliability from A to F and information credibility from 1 to 6. A rating like B2 means a usually reliable source reporting information assessed as probably true.
What grade does a new source start at?
It depends on the class of source. Government sources start at A, vendor sources at B, and news sources at C. C is also the fallback for anything else.
How does a source improve its reliability grade?
By being independently corroborated. Each time a source is corroborated on a Threat Event it earns a validation credit, and after five consecutive credits its grade improves by one band, up to a ceiling of A.
What happens when I discredit a source?
Its grade drops by one band immediately, and its ceiling is permanently capped at B, so it can never be promoted back to A. The change ripples through the credibility of every Threat Event that source contributed to.