The standard
Version 0.1 — draft, 13 August 2026
This standard is not yet in force.
No record is published under it yet. It is published in draft so that it can be read, checked and argued with before it binds anyone.
Recensa is operated by Probioform Norge AS (see the foot of this page). The standard takes effect for a given record on the day that record is published, and binds the operator from that same day under §5.
This document sets out the rules governing every customer record published using Recensa. It binds the brands that publish records, and it binds Recensa.
It is written to be read by anyone: a customer deciding whether to believe a record, a brand deciding whether to publish one, and a regulator deciding whether either of us is being honest.
Every version stays online permanently. Nothing is changed retroactively (§12).
A Recensa record is a public account of what a brand's customers report, published on a domain the brand owns, under rules the brand cannot switch off.
Not independent. The brand owns the domain and pays Recensa. Every record states this above all content, in body text size, on every page.
Not an endorsement. We do not assess whether a product works, whether a company is good, or whether anyone should buy. We issue no scores, grades or ratings of brands.
Not an audit. We check specific things in specific ways, named in §3. We do not inspect premises, verify manufacturing, or investigate companies.
Not a directory. Recensa operates no consumer-facing index across brands, and ranks no brand against another (§5.7).
Record — the pages published at the brand's Recensa-served address. That address is either a domain registered to the brand, or a subdomain of a domain the brand already owns. Recensa never holds the registration in either case, and no particular naming pattern is guaranteed: where the obvious name is unavailable, an agreed alternative is used.
Review — a first-person account from someone who states they used the product.
Order-verified — matched to a completed order in a commerce system the brand connected, by order identifier.
Batch-verified — the reviewer gave a production batch code matching a run the brand recorded, with no order match. The normal case for shop purchases.
Unverified — neither match. Published, and labelled.
Brand statement — text or data the brand supplies about itself.
Connected data — read by Recensa from a connected system, on a schedule.
Calculated — a figure Recensa derives by counting published reviews.
Externally verified — checked against a source outside the brand: a company register, an accredited laboratory, a named publication.
We publish only what we can describe precisely.
Order-verified review — we confirm an order exists in the connected system, that it completed, that it contained the reviewed product, and that the reviewer's contact matches it. We do not confirm identity beyond that.
Batch-verified review — we confirm the code matches a recorded production run. We do not confirm the reviewer bought that unit, or how it was stored after it left the brand.
Company facts — we confirm the registration exists in the named register, and publish the date last checked.
Laboratory results — we confirm a document exists, name the laboratory, and publish the document. We do not verify the testing itself.
Connected data — we publish the source system and the time of the last read.
We never infer, estimate, or fill gaps. Where we cannot verify something, the record says so — including in its own integrity figures (§5.8).
4.1Delete a review for being negative. Removal only on the closed grounds in §6.
4.2Edit the text of anyone's review. Only the author may amend their own, and both versions stay visible with their dates.
4.3Change a review's verification status, or exclude reviews from calculated figures.
4.4Invite only the customers likely to be happy. Invitations go to all buyers of the reviewed product within the defined window. Sentiment is not a field the invitation logic can act on.
4.5Accept a review for payment without labelling it. Any consideration — discount, free product, prize entry — is declared and labelled on that review, and may never be conditional on the review being positive.
4.6Hide the complaint summary or the record integrity figures. Both appear on every record and cannot be disabled, reordered out, or placed behind interaction.
4.7Call the record independent, third-party, or impartial, in the record or in any marketing.
4.8Present a brand statement as verified. The brand's own words and lists are labelled as brand statements (§7), and the brand is responsible for their accuracy.
4.9State or imply that a seller it does not supply is selling counterfeit goods. A brand may publish the channels it supplies and what it can confirm. Resale of genuine goods is lawful, and that accusation is not ours to host.
These matter more than §4. They are why a record means anything.
5.1Sell placement, ranking, badges, favourable labels, or any change to a calculated figure. There is no price at which a figure moves.
5.2Offer a tier in which complaints or integrity figures are hidden. Trust is not a premium feature. Paying less buys less automation, never a less trustworthy record.
5.3Redefine a verification tier retroactively. A review verified under v0.1 stays labelled under v0.1.
5.4Hold a brand's address. The domain is registered to the brand, or is a subdomain of one the brand already owns, and remains its property in either case. Recensa is never the registrant.
5.5Withhold the export. On cancellation the brand receives a complete machine-readable export — reviews, verification states, removal log, history — within 14 days, at no charge.
5.6Sell, license or share review data or reviewer personal data with third parties, or use it to train models.
5.7Run a directory or comparison service across brands. Our customers are brands, and competing with them for their own audience would make every record suspect.
5.8Omit a gap. Where we cannot verify something a record claims, we mark it unverified on the record rather than leaving the section looking complete.
5.9Hide our own numbers. We publish records served, reviews removed with their grounds, brands suspended and brands departed — including when unflattering.
5.10Move an existing customer onto a different plan without their agreement, or apply a new price before telling them. When features not yet built are released, existing customers hear the price before it applies and keep what they are already paying for.
5.11Publish a record without disclosing a conflict. Where Recensa, its operating company, its owners, directors or controlling persons hold a financial interest in the brand whose record is being published, that relationship is disclosed on the record itself, in body text, not in a footnote. The disclosure changes nothing else: verification, removal, calculation and publication rules apply to that record identically.
A conflict that exists today. Recensa is operated by Probioform Norge AS, which holds a financial interest in Probioform. Probioform is used as the first example record for that reason, and every record involving it carries the disclosure required above.
A review may be removed only on these grounds.
Every removal is logged with its ground, its date, and who initiated it. Counts and the breakdown by ground appear on the record. Refused requests are counted too. Removed text is not republished.
Every section carries one label, with a fixed meaning.
| Label | Meaning |
|---|---|
| Verified externally | Checked against a source outside the brand, named in the section. |
| Connected data | Read from a connected system. Source and last-read time shown. |
| Calculated from reviews | Derived by counting published reviews. The brand cannot adjust it. |
| Stated by brand | The brand's own words or list. Not verified by us, and labelled so. |
A brand cannot change which label a section carries.
Three mechanisms, in increasing order of what it would cost us to break them.
8.1 In the software. Sentiment is not a field a brand can filter or act on. No delete-for-negative exists to be requested, escalated to, or granted as a favour.
8.2 In the contract. This standard is incorporated into the agreement. It binds the brand, and §5 binds Recensa — including the parts that cost us revenue.
8.3 In public. Every review is timestamped on arrival, before anyone sees it. Received, published and removed are counted separately, each removal against a ground in §6. The arithmetic is published, so a quiet deletion does not add up:
Received 1,842 Published 1,827 Removed — fraud or duplicate 13 Removed — reviewer's own request 2 Removed for being negative 0 (no mechanism exists)
Everything else is optional.
Recensa does not copy reviews belonging to a marketplace or a review platform. No Amazon, no Reddit, no scraping.
Reviews collected on a brand's behalf by a provider it authorises — Judge.me, Loox, Yotpo, Stamped and similar — are that brand's own first-party reviews. We import them where the brand's rights and the provider's terms allow, through the provider's API, with the brand's authorisation, and with their original dates intact.
Where a third-party platform's rating is shown, it appears as an attributed summary with a link out, never as republished content.
A brand meeting this standard may state:
Customer record published under the Recensa Standard v0.1
A brand may not claim: certified, audited, accredited, approved, endorsed, independently verified, Recensa-rated, unalterable, tamper-proof, or cryptographically verified. We do none of those things. Claiming them is a misrepresentation we act on under §13.
Versions are numbered, dated, and stay published.
Weakening any rule in §4 or §5 requires 90 days' public notice, stating plainly what is being weakened and why.
Records display the version they were published under. Reviews retain the definitions in force when they were verified (§5.3).
If a brand breaches §4:
The brand keeps its domain and its export in every case (§5.4, §5.5).
If Recensa breaches §5, the remedy is that anyone can point at this document, and at the breach log we keep beside it. That is the only enforcement a standard operator can honestly offer without an external body, and it is why §5 is written narrowly enough to be kept.
A customer who believes a record is inaccurate can contact Recensa directly, not only the brand, at hello@recensa.org. We publish how many such contacts we receive and how they resolved.
A reviewer whose review was removed is told which ground under §6 applied.
A brand disputing a calculated figure can require us to show the underlying reviews. We do not adjust the figure.
The first release covers the record itself: importing existing first-party reviews, verified collection, retained negatives, brand replies, complaint themes, provenance labels, the ownership disclosure, the ledger, export, and search measurement.
Batch verification, certificate handling, sales-channel and practitioner lookups, and multi-market records follow once the first records prove useful. Service businesses are not supported in the first release.
Sections of this standard describing features not yet built apply from the moment those features ship, and not before. We do not claim to operate what we have not built.
Named rather than hidden.