Credora
Credora, operating as Credora by RedStone since its September 2025 acquisition by the oracle network RedStone, produces credit risk ratings for on chain lending markets on a single A plus to D scale covering tokens, lending pairs and vaults. Its methodology maps to the probability of default curves used in traditional structured credit analysis, runs one hundred thousand Monte Carlo simulations per market, and is stated as calibrated on more than thirty years of credit data. The firm publishes each rating framework openly while stating plainly that the underlying algorithm remains proprietary.
Ratings are distributed through RedStone's oracle infrastructure alongside price feeds, so a protocol can query price and risk in a single call, with named integrations at the lending markets Morpho and SparkLend and public application programming interface endpoints. Its privacy preserving architecture, documented publicly, runs the real time data unit and key management inside Intel Software Guard Extensions enclaves using the open source Gramine runtime, chosen so that its security can be independently verified, alongside zero knowledge proofs in the credit scoring pipeline.
Founded in 2019 as X-Margin by Darshan Vaidya and Matt Ficke, it raised 14 million dollars from backers including Coinbase Ventures, S&P Global and HashKey before the acquisition, and relaunched public ratings in November 2025.
Capability Axes
Capability grades
15 of 15 axes rated · 5 graded A or B
The removal test leaves nothing at all. There is no product underneath the rating: the entire output is computed, with one hundred thousand Monte Carlo simulations run per market and scores updating continuously as collateral mixes and liquidity conditions shift. No analyst writes a report here and there is no prior non modelled business, unlike the ratings houses this firm is measured against. Strip the quantitative layer and what remains is an empty distribution rail. The consensus ratings protocol and the probability of default engine are the company.
This is the most fully automated decision chain encountered in this pocket and no control anywhere in it is described. A rating is computed without human involvement, delivered through an oracle without human involvement, and consumed by lending markets that use it to inform credit decisions and automated controls and to adjust parameters dynamically rather than on static assumptions. Every stated benefit of the design depends on taking people out of the loop.
Nothing describes a materiality threshold before a score change propagates, a delay or confirmation step, a circuit breaker if inputs behave anomalously, an override route for a consuming protocol, or any review of a rating before it moves capital. A published methodology explains how a score is reached; it is not a control over what the score then does.
The boundary of disclosure is drawn explicitly and in the vendor's own words, which is rarer in this index than disclosure itself: every rating framework is publicly documented covering what is measured, why, and what the output means, while the underlying algorithm is stated to remain proprietary. Naming precisely where transparency stops is a more honest posture than the vague assurances that are the norm on this axis.
The methodological anchoring is described rather than gestured at, mapping to the probability of default curves used in traditional structured credit analysis with a stated calibration on more than thirty years of credit data. Held off the top grade because that calibration is asserted and never evidenced: no back test, no realised default comparison, no accuracy figure and no artificial intelligence management system certification, and no validation pack is offered to an institution that would have to defend the rating internally.
Named counterparties with real capital behind them, and no named customer with a measured result. The integrations at Morpho and SparkLend are substantial lending markets and are corroborated by independent trade press rather than only by the vendor.
Named executives are quoted on the record, including RedStone's co-founder and Credora's own co-founder, and the investor base carries weight of its own, with Coinbase Ventures, HashKey and S&P Global having taken positions before the acquisition and RedStone having done acquisition diligence with money at stake.
The outcome claim that rated vaults on Morpho grow faster and retain capital better than unrated peers points the right way and arrives without a single figure attached, and no default study, calibration result or back test has been published against a methodology that asserts thirty years of credit data behind it.
The dual position shape appears here in its sharpest form yet in this index, and unusually the commercial motive is stated by the owner in writing rather than inferred. The rater is owned by the oracle network that distributes the ratings and sells price feeds to the same protocols being rated, and the acquisition rationale published by that owner describes price, ratings and collateral intelligence as together forming a strong competitive moat that makes it the most differentiated oracle in the market.
A protocol's rating and its choice of data infrastructure therefore sit inside one commercial relationship. Nothing describes what separation exists between the rating judgement and the infrastructure sales interest, whether a protocol's oracle spend is visible to the rating process, or whether a market can be rated at all without consuming the owner's feeds.
The privacy engineering is real and its relevance to the current product is unestablished, which is why it is not credited here. The original design used zero knowledge proofs alongside enclave computation so that a borrower's positions could be scored without being revealed to the scorer, which is privacy by construction of a kind this index rarely sees.
That architecture was built for an institutional credit scoring business that the acquisition substantially reshaped, and today's published product rates vaults, pools and tokens largely from public chain data, where the privacy question barely arises. No privacy policy, data processing agreement, subprocessor list or retention schedule was located, and nothing states what confidential counterparty data, if any, the platform still ingests.
No certification or attestation was located, and what stands in its place is more technically checkable than most certified vendors provide. The privacy preserving architecture is documented publicly at component level: the real time data unit and the key management system run inside Intel Software Guard Extensions enclaves under the Gramine runtime, with the published reasoning stating that Gramine was selected partly because it is open source and its security can therefore be neutrally verified rather than taken on trust.
That is a disclosure act rather than a badge, and a buyer can inspect the claim independently. Held at this grade rather than higher because no audited attestation exists, and because the architecture documentation predates the September 2025 acquisition and the subsequent product relaunch, so whether it describes the current rating platform is not established anywhere. Worth confirming on a later pass.
The firm publishes letter grade ratings on an A plus to D scale and holds no credit rating agency registration. Independent research covering this category records the established agencies alongside it as registered under the United States nationally recognised statistical rating organisation regime and on the European securities regulator's register, and records no equivalent standing here.
One structural detail is worth stating plainly rather than drawing a conclusion from: S&P Global, itself a registered rating agency, took an investment position in this unregistered one. No sandbox participation, supervised test or regulator programme admission was located.
No fairness testing, differential outcome analysis or coverage bias assessment is published, and the vendor's own evidence establishes why it would matter. The claim advanced for the product is that rated vaults grow faster and retain capital better than unrated ones, which is an assertion that a rating causes allocation rather than merely describing risk.
On that account, which market gets rated first, which is left uncovered, and how the rated universe is selected are decisions that move capital, and none of them is described. The consensus ratings protocol is named repeatedly without stating whose views form the consensus, how they are weighted, or what happens when they diverge.
No liability position, error rate, correction path or appeal route is published, against a consequence chain that is automated end to end. A computed score propagates through an oracle into a lending market that adjusts parameters on it, so a wrong rating reaches capital without passing any person, and the party who bears the loss is a lender in a vault who has no relationship with the rater and may not know a rating was involved.
Oracle delivered data driving automatic financial action is a well documented failure surface in this market, and the ratings were themselves relaunched in the weeks after a liquidation event of roughly twenty billion dollars. Nothing states where responsibility sits between the rater, the oracle network that distributes the score, the protocol that acts on it and the allocator who relied on it.
The disclosure here runs the opposite way to the index norm and still lands in the same place. Most vendors describe their models in some form and say nothing about the infrastructure beneath them. This one names its silicon and its runtime precisely, down to Intel Software Guard Extensions enclaves and the open source Gramine runtime with its manifest based configuration, and names nothing about the models themselves: no provider, no family, no version, no statement of whether any component is licensed from a third party or built in house. The execution layer is unusually well disclosed and the modelled layer is not disclosed at all.
The distribution architecture is the strongest thing about this vendor and it is specific, named and live. Ratings travel through RedStone's oracle infrastructure alongside price feeds, so a consuming protocol queries price and risk in a single call rather than reconciling two sources, and the stated design intent is that risk data becomes a default property of the data layer rather than a separate lookup.
Named integrations at Morpho and SparkLend are live, public application programming interface endpoints are available to partners, and Spark surfaces both real time ratings and risk profiles inside its own front end. Reaching dozens of protocols through infrastructure that is already installed is a materially deeper integration position than a data feed a buyer must wire up.
No hosting regions, residency commitments or tenancy model are published. Delivery is through a public application programming interface and through oracle feeds that publish scores on chain, which is a stated and deliberate design rather than an omission, and it is the only part of the deployment picture described anywhere.
The enclave based architecture implies specific hardware requirements and therefore constrains where computation can run, and no statement connects that to any jurisdiction. The question is sharpened by an unresolved corporate one: the operating entity's location after the acquisition is not stated in any material reviewed.
No pricing, tier structure or billing basis is published, which is the index norm, and the more consequential omission is who pays for a rating. Whether a protocol or vault curator commissions and funds the assessment of its own market, or an allocator subscribes to independent coverage, determines where the conflict sits in any ratings business, and nothing states which model applies.
The published material describes ratings as freely propagating to protocols through infrastructure those protocols already pay for, which suggests a third arrangement again and describes none of them.
The stated buyer set is broad and the evidenced one is not. Published positioning addresses institutional allocators directly, and independent coverage adds custodians, insurers and institutional desks mapping scores to capital and margin frameworks, but no institution of any type is named as a customer. What is evidenced is a single segment: on chain lending markets, with Morpho and SparkLend as the named integrations and distribution to protocols already consuming RedStone oracle feeds. That is genuine reach inside one narrow slice of one asset class rather than coverage across institution types, and the grade reflects the evidence rather than the ambition.
Alternatives to Credora
The closest documented capability profiles to Credora in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Institution and Segment Coverage and Autonomy and Oversight Model where Credora does not
Documents Institution and Segment Coverage and Autonomy and Oversight Model where Credora does not
Documents Institution and Segment Coverage and Autonomy and Oversight Model where Credora does not
Documents Institution and Segment Coverage and Autonomy and Oversight Model where Credora does not
Documents Institution and Segment Coverage and Autonomy and Oversight Model, among others where Credora does not
Documents Institution and Segment Coverage and GLBA and Data Privacy Posture, among others where Credora does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.