Risk Rating Methodology

    Every rated vault on pigi carries an overall risk score from 0 to 100 (higher = safer) and a band from A to F. Scores are recomputed and published nightly; the band is what the leaderboards and the vaults table show, and the score drives every risk-adjusted APR on the site. This page describes how those numbers are produced.

    Betabeta

    This rating system is young and actively improving. Coverage is still growing — most tracked vaults are not rated yet, and "not rated" means exactly that, not "safe" and not "risky". New vaults, protocols, and chains are being assessed continuously.

    The methodology itself is under construction too: rubrics get recalibrated, new hard floors are added when real incidents reveal a blind spot, and chain and dependency coverage widens release by release. That means a vault's score or band can move because the methodology improved, not only because the vault changed — every such change ships as a new rulebook version with a changelog, and shows up on the vault's risk chart as a methodology-update marker rather than a silent redraw.

    If a rating looks wrong to you, we want to know — tell us on X. Disagreement with reasons is exactly the input this phase is for.

    The band scale

    A
    score 85–100. Strongest structural safety; deep, market-validated deposits; no unresolved concerns.
    B
    score 70–84. Sound design with limited, identified weaknesses.
    C
    score 55–69. Meaningful structural or operational concerns; suitable only with the risk understood.
    D
    score 40–54. Serious weaknesses or an active red flag; capital at material risk.
    F
    score below 40. Failing: an active exploit, blocked redemptions, or equivalent. Not investable on our scale.

    There is no E band — the scale jumps from D to F, the way academic grading does, so the bottom band unambiguously reads as failing rather than "one notch below D".

    Two layers, blended

    The score blends two layers: a structural rosette at 60% and a quantitative anchor at 40%. The split is deliberate — most catastrophic DeFi losses were structural (admin keys, unbacked assets, blocked exits), not statistical, so the structural judgment carries more weight than the market data.

    The quantitative anchor is computed automatically every day from five observable inputs, each with a fixed weight: deposit scale / TVL (25), yield stability measured as 30-day volatility (25), yield sanity relative to the DeFi base rate (20) — a vault paying far above the market rate must be taking risk somewhere — time in production (15), and the 30-day deposit flow trend (15).

    The structural rosette is an analyst assessment against a versioned, published-in-advance rulebook, across five dimensions: contract & platform security (25%), control & governance (20%), asset & collateral quality (20%), liquidity & exit (20%), and counterparty & operations (15%). Each dimension is a ladder of concrete, checkable lines — audit coverage and recency, signing-authority decentralisation, depositor exit windows, backing visibility, redemption paths, curator track record, disclosure quality — so two analysts scoring the same vault land on the same rung.

    The dependency cap

    A vault is never safer than what it stands on. Every strategy declares its critical dependencies — the protocols it deposits into, the oracles it prices against, the chain it runs on, the curator that manages it — and each dependency is rated on the same 0–100 scale. The vault's overall score is then capped at its weakest rated critical dependency plus 15: a modest premium for insulation is possible, but no amount of good vault design outruns a fragile foundation. Chains are rated from L2Beat's stage framework where it applies, with owner-declared pins for chains outside it.

    Overlays and hard floors

    Overlays are analyst adjustments for information the rulebook cannot see yet — clamped to ±8 points, always with written evidence, and always with an expiry date so they cannot silently become permanent.

    Hard floors exist because weighted averages hide fatal flaws — a vault can score well on twenty lines and still have an admin key that drains it tonight. A floor bypasses the arithmetic entirely and caps the score the same day it fires. Current floors include: an active or unresolved exploit on the strategy or a critical dependency; the deposit asset trading more than 5% off peg for 24 hours; an unaudited, upgradeable contract with no timelock; an anonymous team under six months old paying more than twice the base yield; an undisclosed operator or curator conflict; undisclosed loss seniority for the strategy's own holders; and redemptions empirically blocked for 30 days or more.

    Band stability (why bands don't flap)

    The score moves freely every day, but the published band is deliberately sticky: an upgrade requires the score to hold in the higher band for seven consecutive daily runs, a downgrade for two — and a hard floor moves the band immediately, because an exploit does not wait for confirmation. This is why a vault's score can sit slightly above a threshold while its band still shows the previous letter.

    From score to risk-adjusted APR

    The risk-adjusted APR shown in the tables is the vault's 30-day APR minus a risk penalty derived from its score. The penalty is a continuous, piecewise-linear function — roughly 0.4 percentage points for a vault scoring in the low 90s, about 0.9 around the high 70s, 2.5 in the low 60s, 5 near 47, and 12 or more for failing scores — so two vaults in the same band with different scores get different penalties. A vault whose yield is below its penalty shows 0.00%: on our numbers, the yield does not pay for the risk. Unrated vaults have no risk-adjusted APR at all.

    What is public, what is not

    The band and the overall score are public — on the leaderboards, the vault pages, and the data API, along with each vault's daily score history. The full decomposition behind a score — the per-line rosette justifications, anchor inputs, the dependency graph, and overlay evidence — is internal working material for now. The plan is to open it up: once the scoring has been tested in the field through the beta, the decomposition will be published too, so every rating can be checked line by line.

    The methodology itself is versioned like software: every published score records the exact rulebook version it was computed under, and changes ship as new versions with a changelog — never as silent edits.

    Ratings are pigi's own opinion, produced for comparison between vaults. They are not financial advice, not a guarantee against loss, and not an invitation to deposit.