How NextAct decides
Every result is produced by rules that can be read, from evidence that is recorded with the time it was observed. Here is the whole method.
1. What the material claims
A message asserts things: who it is from, what is urgent, what will happen if you do nothing. NextAct records each of those as a claim, separately from anything it can check. A claim is never evidence for itself.
Claims are marked as either what the material says or what NextAct established. Nothing read out of the material can become a statement about the world.
2. What the evidence shows
NextAct collects what it can without opening anything: how the address is constructed, what characters it uses, and — when you ask for the additional checks — when the domain was registered, where its name points and what certificate it presents.
Every piece of evidence is recorded with what its kind of source can and cannot establish, and how it bears on a claim:
SupportsContradictsContextOrigin
3. Whether the sources are independent
An email, its attachment and a QR code inside it all come from whoever sent them. They are one source repeating itself, and NextAct counts them once. A certificate proves someone controls a domain; it says nothing about who that someone is.
A claim that nothing independent bears on stays Not established rather than becoming supported by silence.
4. What could not be checked
Unknowns are recorded as first-class findings, with why each matters and how you could resolve it safely. A check that could not run reduces how much NextAct can conclude; it never becomes a finding about the sender.
5. The risk policy
A published, versioned policy turns the findings into a classification. Each rule fires at most once, so repetition cannot escalate a result, and the policy version and fingerprint are stored with every assessment.
Undetermined
NextAct does not have enough verified evidence to classify this reliably. That is not the same as finding nothing wrong.
Low observed risk
No major concern was identified in the checks NextAct was able to perform, and supporting identity evidence was available. This is not a guarantee.
Elevated risk
NextAct found something that does not fit. It is worth checking before you act.
High risk
Several things NextAct checked do not fit together. Do not act on this as it stands.
Critical risk
An identity claim is contradicted by independent evidence and the request could not be undone.
The strongest classification is conjunctive: it needs a contradicted identity and a request that could not be undone and enough evidence to support saying so. A high total on its own is not enough.
6. What to do is separate from how risky it is
A legitimate bank transfer is still irreversible. NextAct therefore tells you what to do before acting separately from what it observed — “risk undetermined, verify before you act” is an honest and common pair.
7. Where AI fits, and where it does not
A language model may read wording and propose findings, and may rewrite an explanation at three levels of detail. Everything it proposes must quote the exact text it relies on, and is checked before anything uses it.
A model can never set the risk level, the protection posture, a claim’s status or what counts as evidence. At most it can make a result more cautious, by a bounded amount. In this build no model is connected at all.
AI is off by default