> ## Documentation Index
> Fetch the complete documentation index at: https://docs.webacy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Risk Factors

> Reference for the hundreds of independent risk factors Webacy combines into every score, spanning security, financial, operational, and compliance signals.

A **risk factor** is an individual characteristic, behavior, or observation that contributes to Webacy's overall assessment of an entity. Rather than relying on a single indicator, Webacy evaluates hundreds of proprietary risk factors spanning security, financial integrity, operational resilience, governance, compliance, and behavioral analysis.

Some risk factors are simple binary observations, while others are the result of complex analytics performed across blockchain history, market data, and relationships between entities. Together, these factors provide the foundation for every risk score, rating, alert, and policy decision generated by the platform.

The exact weighting, implementation, and methodologies behind many of these risk factors are proprietary and continuously refined as new threats and asset classes emerge.

## Risk Factor Categories

Webacy's risk factors can be organized into several broad categories.

<Tabs>
  <Tab title="Security Risk">
    Security risk factors identify vulnerabilities, malicious behavior, exploit patterns, and characteristics that could place users or assets at risk.

    Examples include:

    * Malicious contract functionality
    * Freezeability
    * Blacklisting capabilities
    * Unlimited mint permissions
    * Proxy upgradeability
    * Address poisoning exposure
    * Exploit associations
    * Transaction simulation results
  </Tab>

  <Tab title="Financial Risk">
    Financial risk factors evaluate the health, sustainability, and economic characteristics of digital assets and protocols.

    Examples include:

    * Holder concentration
    * Liquidity concentration
    * Redemption constraints
    * Reserve composition
    * Collateral quality
    * Asset backing
    * Yield sustainability
    * Market dependency
  </Tab>

  <Tab title="Governance Risk">
    Governance risk measures the level of control, centralization, and operational authority exercised over an asset or protocol.

    Examples include:

    * Admin privileges
    * Upgrade authority
    * Emergency pause controls
    * Governance participation
    * Voting concentration
    * Multisig structure
    * Key person dependencies
  </Tab>

  <Tab title="Operational Risk">
    Operational risk factors assess how resilient an asset or protocol is during normal operation and periods of stress.

    Examples include:

    * Oracle dependencies
    * Infrastructure concentration
    * Protocol integrations
    * Treasury management
    * Smart contract dependencies
    * Historical operational incidents
  </Tab>

  <Tab title="Compliance Risk">
    Compliance-related factors identify exposure to sanctioned entities, illicit activity, regulatory concerns, and known high-risk actors.

    Examples include:

    * OFAC sanctions exposure
    * DPRK associations
    * Money laundering indicators
    * High-risk counterparties
    * Mixer interactions
    * Jurisdictional considerations
  </Tab>

  <Tab title="Behavioral & Network Risk">
    Many risks cannot be identified by looking at an entity in isolation.

    Webacy analyzes historical behavior and relationships across the blockchain to identify patterns that emerge over time.

    Examples include:

    * Issuer reputation
    * Counterparty risk
    * Wallet clustering
    * Historical transaction behavior
    * Connected entity analysis
    * Fund flow relationships
    * Known ecosystem associations
  </Tab>
</Tabs>

## Beyond Individual Risk Factors

Many risk factors are not inherently "good" or "bad." Instead, they provide additional context that helps explain an entity's overall risk profile.

For example, a vault may receive financial risk signals related to redemption mechanics, governance signals related to administrative controls, and operational signals related to underlying protocol dependencies. Together, these independent observations create a more complete picture than any single factor could provide on its own.

## Beyond Risk Categories

The categories presented are intended to help explain the Webacy Risk Framework, not to define rigid boundaries. Many risk factors naturally span multiple dimensions of risk. For example, a governance issue may also introduce operational risk, while an issuer's reputation may influence both financial and compliance assessments. As the blockchain ecosystem evolves, new products, use cases, and regulatory requirements will continue to shape how these signals are interpreted. The strength of the Webacy Risk Framework lies not in assigning every factor to a single category, but in combining signals from across the ecosystem to provide a more complete and contextual view of risk.

## A Continuously Evolving Framework

Webacy currently evaluates **400+ proprietary risk factors**, with new signals regularly added as the blockchain ecosystem evolves. Emerging asset classes, protocol designs, attack vectors, and regulatory requirements continually introduce new considerations, and our framework evolves alongside them.

Risk factors are the building blocks of the Webacy Risk Framework, enabling explainable, transparent, and adaptable risk intelligence across every supported blockchain entity.

## What's Next

<Card title="Risk Scores and Ratings" icon="sort-numeric-up" horizontal href="/risk-scores-and-ratings">
  Webacy provides both numerical risk scores for automation and letter-grade ratings for quick interpretation.
</Card>
