TrustR
TrustR is our flagship recommendation and discovery provider for non-custodial social apps. Under the hood, ranking algorithms are highly configurable and portable across providers. On the surface, platforms don’t need to manage feed algorithms, they become a shared commodity that anyone can generate or consume.
Nostr has a problem ...
How does one discover trustworthy content and users on a “trustless” network that nobody owns? The classic “Web of Trust” answer is to calculate trust scores relative to each observer (client user), for every pubkey (network user) interacting with and around that observer.
The double whammy for Nostr is that these calculations are pretty heavy to run locally on a mobile app for every client user, and that client apps have little choice but to do so. Nostr lacks a standard for requesting such custom calculations as each client user might need for a given search or desired user experience.
Any social app (even a Nostr client) that holds custody over recommendation or discovery algorithms, is still on the hook for moderating and controlling user content.
... without a standard for trust.
Vendor Lock In
Users are limited to whichever algorithm their current app chose to build. A configuration cannot be carried to another app, a result cannot be inspected, and two providers cannot be compared.
More Cost Burden
Apps that hold custody over recommendation and discovery carry the full cost of computing them and the full liability for moderating what they surface. Neither cost is shared with the network.
No Layering of Results
Every service computes every request from scratch. Using another provider's results requires a separate integration with each one, so no provider's work builds on another's.
More Centralized
Recommendation and discovery fall to the few providers that can afford the compute. The network's curation centralizes around them.
TrustR has a solution ...
TrustR calculates Web of Trust in the cloud, freeing apps to simply publish requests and retrieve results. Using the TSM standard, apps can publish their own requests from any user point of view, or retrieve results from their user’s already published request.
TSM (Trust Service Machines) is an open source Nostr standard for trust services. Any app can send the same request to any provider, and one provider’s output can be sent to another as input. TSM compatibility allows apps and providers to become non-custodial processors recommendation and discovery, rather than controllers.
Social apps on Nostr can offload the burden of content moderation, simply by allowing users to choose their own algorithms for recommendation and discovery.
... with interoperability.
Algorithmic Sovereignty
A user's configuration is a signed Nostr event. It can be sent to any TSM compatible provider without modification, and it can be forked, shared, or combined with others.
Open Marketplace
Providers compete on quality, freshness, privacy, and price. An app chooses a provider, or lets the user choose, instead of building and maintaining one.
Distributed Compute
Results are addressable Nostr events, so one provider's output can be another provider's input. The cost of answering the same question is paid once and shared.
Decentralized Curation
Many algorithms run on the network, each computed from a user's own point of view. The capture of any one provider changes nothing for the others.
MVP Demo
Our TrustR demo shows off three separate TSM services. It uses the results from one as the input for the next. Each one accepts standard TSM requests and publishes standard results as signed Nostr events. This MVP models how independent providers can interoperate on the network, preserving non-custody for apps and services.
Baseline Web of Trust
Your personal spam filter based on follows, mutes, and reports across the network ranked from your point of view.
Topical Search
Retrieve notes or articles that have been published within your baseline web of trust, and ranked on semantic relevance to a search topic.
Topical Influence
Rerank authors from the topical search based on semantic relevance and by engagement on the ranked posts.
Open Standards and Open Source
Interoperability preserves non-custody for apps and services by allowing the user to choose. Below are the open source standards and libraries that we have developed and maintain alongside TrustR.
GrapeRank TSM
Nostr's first (and only) Web-of-Trust library for non-custodial apps and services. It allows anyone to run a GrapeRank service, ingesting event interactions from across the network to generate highly configurable user rankings from any point of view.
GrapeRank on GitHubTSM
Trust Service Machines (TSM) is a Nostr standard for trust service providers to announce the services that they offer, for users to publish requests (privately or publicly), and for results to be published in a discoverable manner that apps may consume.
Read the TSM specNAS
Nostr Archive Standards (NAS) is a Nostr standard for the production and discovery of event archives. Nostr relays are a poor mechanism for reliable delivery of bulk or older events. NAS provides a standard format upon which network aggregation and analytics can operate while preserving user-custody of published events.
Read the NAS specAudience
Client apps
Social apps that need a feed for users who have no Web of Trust of their own yet, or a custom ranking for a particular view. TrustR computes it from a standard request, and the app never holds the algorithm.
Relay services
Personal and paid relays that filter by trust instead of by keyword. TSM processing can be resold, white labeled, as a value add for relay customers.
Curators
Users and organizations that publish rankings as a service. A curator’s TSM request is a signed event, so any app or user can subscribe to its results.
Power users
Users who already curate and want their rankings to follow them between apps. Any TSM compatible app can consume the results of a request published from the user’s own point of view.
Architecture
TrustR is built on six instances across three interfaces. The Public Interface is standard Nostr: a dashboard where users configure and publish TSM requests, and a relay that carries those requests, the feedback, and the results as signed Nostr events. The Listener Interface is a single Service Orchestrator, the only instance that reads the public relay and calls the Compute Interface behind it. That gated compute (GrapeRank, NDE, and the Archive Relay) is private to TrustR and reachable only through the orchestrator.
Apps and users depend only on the Public Interface, which is defined by the TSM standard and not by TrustR. Any TSM compatible provider can replace everything behind it (Listener and Compute interfaces) without a change to any app, and requests and results remain signed events on public relays that any app may consume.
Example Request Flow
One GrapeRank ranking, start to finish. The same shape holds for any TSM service.
Before anything — the Service Orchestrator has published its service announcements. The Archive Relay is already scanning public relays for notes, articles, profiles, follow lists, mutes, reports and zaps. Both run continuously.
The reader configures — in the TrustR Dashboard. Which service, whose point of view, and which interactions to interpret.
The request is published — as a signed event to the TrustR Relay. From here it is public Nostr data, not an API call.
The Orchestrator picks it up — on its announced relays. It checks the subscription, then calls the service over a private interface and holds the connection open.
The point of view resolves — as GrapeRank fetches the events that define whose perspective this is.
The interactions ingest — from the Archive Relay, not from the public network. This is the step that would be unaffordable per request without a local archive.
Interpretation — turns every interaction into a rating between zero and one.
Calculation — runs a weighted average iteratively until it converges. Four parameters shape it, and the requester sets all four.
Unsigned output returns — to the Orchestrator. The service hands back output events without signing them, because it holds no key.
The Orchestrator signs and publishes — to the TrustR Relay, and to any relays the request named. Feedback events go out along the way, so the reader sees progress rather than a spinner.
The Dashboard redraws — as events land. Outputs are addressable, so a later recalculation replaces the same coordinates rather than arriving as a second answer.
That signed output is now an addressable event on a public relay. NDE can take it as its own point of view, and it never has to integrate with TrustR to do so.
We are Nostr Integration Experts.
We offer concierge services for companies at any stage, from sizing up the protocol to building and shipping on it.
Consultation
We advise on Nostr integration for existing products.
Research
We offer free research groups for existing Nostr apps and services, supporting them to be even more non-custodial.
Development
We offer hands on help integrating Nostr with existing products.