Terms, defined.
Plain-language explanations of the structural concepts behind Vouch.
Index
k-anonymity
A privacy guarantee that hides individual records by ensuring each one is indistinguishable from at least k-1 others.
Two-way review
A review system where both parties to a transaction can rate each other, structured so neither side can retaliate against the other.
k=3 threshold
The minimum number of reviews required before any aggregate score appears on a Vouch profile.
Lock window
The seven-day interval during which submitted reviews stay sealed before publishing, neither party can read the other's review until the window closes.
Aggregate score
The averaged rating that appears on a Vouch profile once it crosses k = 3.
Category breakdown
Five rating dimensions per direction (brands rate creators on Communication, Brief Accuracy, Content Quality, Audience Fit, Professionalism; creators rate brands on the symmetric set).
Verified profile
A Vouch profile with confirmed identity, email verification on signup, plus platform-handle verification linking the profile to its public creator accounts.
k-anonymity
A privacy guarantee that hides individual records by ensuring each one is indistinguishable from at least k-1 others.
K-anonymity is a privacy concept introduced in academic research on data anonymization in the late 1990s. It addressed a specific problem: even when researchers stripped names from healthcare records, the remaining attributes, birthdate, ZIP code, sex, often combined uniquely enough to re-identify individual patients. The fix was to require each released record to be indistinguishable from at least k-1 others on those identifying attributes. Below the threshold, the data wasn't released at all.
The same idea generalizes beyond health data. Census bureaus use it to publish statistical releases without exposing individual respondents. Mobility datasets use it to share aggregate movement patterns without giving up individual paths. Anywhere a small dataset risks identifying a single contributor by accident, k-anonymity is one of the foundational defenses.
Vouch applies the concept to reviews. The dataset is the set of reviews on a single profile; the question is whether reading the aggregate score and category breakdown could let someone reverse out which reviewer left which rating. The answer depends on how many reviewers there are. With one review, the aggregate IS the review, total leakage. With two, you can infer either of the two reviewers' ratings if you know the other's. With three or more, individual ratings dissolve into the average.
The protection is mathematical, not promissory. We don't publish the aggregate and trust ourselves not to leak the individual ratings, we don't publish the aggregate at all until the math says it's safe. Reviewers can't be exposed by a future change in policy because the policy isn't doing the work. Three reviewers are doing it.
K-anonymity is an old idea. What's new at Vouch is applying it to a marketplace where the parties have to find each other and trust each other's reviews. Most prior deployments protect data subjects from researchers; Vouch protects reviewers from reviewees. The math is the same. The users are different.
Related: k=3 threshold · Two-way review
Two-way review
A review system where both parties to a transaction can rate each other, structured so neither side can retaliate against the other.
Two-way review is a marketplace pattern where both parties to a transaction rate each other after the fact. Uber drivers rate riders; Uber riders rate drivers. Airbnb hosts rate guests; Airbnb guests rate hosts. eBay buyers rate sellers and the reverse. The pattern emerged because one-way review systems consistently produce misleading signal in two-sided markets.
One-way systems fail in three predictable ways. The first is selection bias: only the most enthusiastic and the most aggrieved users leave reviews, so the median experience never gets recorded. The second is retaliation: when reviews are attributable, the reviewed party can punish the reviewer in future interactions, which trains everyone to either not review or to review only positively. The third is sycophancy: positive reviews are easier to write, easier to publish, and carry less social cost, so the population skews flattering even when the underlying experience was mixed.
Two-way systems address some of these structurally. When both sides rate, both sides have skin in the game; mutual stakes replace one-sided social pressure. They don't fix retaliation on their own, though. If a creator can read a brand's review before submitting their own, a low rating from the brand triggers a retaliatory low rating from the creator, and the system collapses into vendetta theater.
The structural fix is the lock window. Both reviews are submitted independently. Both stay locked until a fixed time elapses. Vouch uses seven days. After the lock, both publish at once. Neither side can react to the other. Neither side knows what the other wrote when they were writing their own. Reciprocity is preserved; reaction is removed.
On Vouch, two-way review applies to brands and creators on every campaign. Brands rate creators on five categories; creators rate brands on five categories; both sides' scores aggregate independently. The asymmetry that's endemic to influencer marketing, brands choose, creators are chosen, gets corrected at the data level. A brand that consistently scores low on payment timeliness carries that signal alongside everything else.
Related: k-anonymity · k=3 threshold
k=3 threshold
The minimum number of reviews required before any aggregate score appears on a Vouch profile.
The k=3 threshold is the operational expression of k-anonymity on Vouch. Until a profile has at least three published reviews, no aggregate score appears anywhere on the platform. Not on the public profile, not in search results, not on Discover, not even on the reviewee's own dashboard. The profile exists, the reviews exist, but the aggregate doesn't render.
Three is the smallest k that prevents single-source attribution while still allowing reasonable signal to surface once it's reached. With k=2, two reviewers can each identify the other's ratings if they know their own. K=4 would be more conservative on privacy and less responsive on signal, most profiles would languish below the threshold for longer than they need to. K=3 is the smallest number that breaks the inference cleanly. The privacy literature calls this kind of choice a privacy-utility tradeoff. The choice here is deliberately on the conservative-for-utility, sufficient-for-privacy edge.
Below the threshold, the protection is total. Even the reviewee can't see scores on their own profile. This rules out a class of attacks where someone identifies the only creator they've worked with this quarter and reads the resulting review. There's nothing to read. The review exists in the database, locked behind RLS policies the application code can't bypass, and surfaces only when the math allows.
Above the threshold, what's revealed is the aggregate, average score, category breakdown, count of reviews. What stays hidden is everything granular: which reviewer wrote which rating, which category each individual reviewer emphasized, what the distribution of pre-threshold scores looked like. The aggregate is the signal; the individual review is the protected data.
The threshold protects the first reviewer most directly. They never face the awkward situation of being the only voice in the room, by the time anything is visible, two more reviewers have joined. It also protects the early reviewee: their first impression on the platform isn't a single rating that hardens into reputation, but a deferred view that only appears once it represents a meaningful sample.
Related: k-anonymity · Two-way review
Lock window
The seven-day interval during which submitted reviews stay sealed before publishing, neither party can read the other's review until the window closes.
After both parties submit their reviews on a Vouch campaign, the reviews enter a sealed seven-day window. Neither side reads the other's review during that period. Submission timestamps aren't exposed either, so timing alone can't hint at who reviewed first. When the window closes, both reviews publish simultaneously and anonymously.
The mechanic exists to prevent reactive grading, the version of two-way review where a creator sees a brand's 3-star rating and revises their own 5-star down to 2 in retaliation, or vice versa. Once the lock closes, reviews are immutable. The seven-day length is long enough to neutralize the urge to respond in kind, short enough that the resulting reputation signal moves at the speed of the work, not at the speed of committee.
Related: Two-way review · Aggregate score
Aggregate score
The averaged rating that appears on a Vouch profile once it crosses k = 3. Individual ratings dissolve into the average; the average is the only signal published.
Above the k = 3 threshold, what Vouch publishes is the aggregate, the averaged rating across all reviews on a profile, broken out by category. The individual ratings are not exposed. No reviewer's 3 or 5 can be pulled out of the average; the dataset only renders in its summarized form. This is the operational meaning of anonymity at the data layer.
The aggregate carries more signal than any single review does. One 4-star rating is a single data point; an aggregate of 4.6 across twenty-seven reviews is a population. The choice to publish only the population, not the points composing it, is what lets the reviewer write honestly. They contribute to the average; they don't become the rating.
Related: k-anonymity · Category breakdown
Category breakdown
Five rating dimensions per direction (brands rate creators on Communication, Brief Accuracy, Content Quality, Audience Fit, Professionalism; creators rate brands on the symmetric set).
Every Vouch review scores the counterparty on five named dimensions, not one overall stars-out-of-five. Brands rate creators on Communication, Brief Accuracy, Content Quality, Audience Fit, and Professionalism. Creators rate brands on Communication, Brief Clarity, Payment Timeliness, Creative Respect, and Professionalism. Each dimension carries its own 1–5 score; the aggregate score is the average across all five.
The five-category structure forces specificity. "Was a nightmare to work with" gets translated into honest ratings on Communication and Brief Accuracy. "Loved them" gets translated into something that actually differentiates "they were pleasant" from "they delivered." Aggregate scores hide individual ratings; category breakdowns reveal which dimensions are doing the work behind the average.
Related: Aggregate score · Two-way review
Verified profile
A Vouch profile with confirmed identity, email verification on signup, plus platform-handle verification linking the profile to its public creator accounts.
A verified Vouch profile has cleared two checks. The first is email, every account confirms via emailed link before any review activity. The second is platform-handle verification: creators link their Vouch profile to one or more public social accounts (Instagram, TikTok, YouTube) so reviewers can be sure they're reviewing the right person. Brands are verified via corporate-domain email at signup.
Verification doesn't imply endorsement. It says the person behind the handle is who they say they are, and that the campaigns associated with their profile actually involved them. It's the floor, anonymity sits on top of it. You can't have meaningful anonymous reviews of a faked identity, so identity gets verified first and pseudonymized immediately after.
Related: Two-way review