Confianza y seguridad

Cómo funciona la moderación, qué permitimos y qué no, y cómo tratamos los abusos.

Esta página aún no está traducida. A continuación se muestra la versión en inglés. Si quieres ayudar a traducirla, escribe a [email protected].

Last updated 12 Sep 2026

Nothing goes live unchecked

A rating on wowpilot is screened before anyone else can see it, never only after a complaint. The first pass is automatic — length, links, shouting, personal information, how many ratings this account and this network have sent today, how old the account is. Anything that trips a check waits for a moderator. Everything else publishes, usually within a business day.

How fakes get caught

  • Limits. One rating per person per business, and only a handful per account per day.
  • Hashed addresses. We store a one-way hash of the sending IP, never the address itself — enough to notice ten "different" customers posting the same paragraph from one connection.
  • Account weight. A rating from a brand-new account with no history counts for less in a score than one from someone with a track record, and repeatedly-flagged accounts lose weight further.
  • Burst detection. A quiet business that suddenly collects a run of five-star ratings has the newest ones held until a person has looked.
  • Bot check. Sign-up, ratings from unverified accounts and anonymous reports all pass through Cloudflare Turnstile.

Criticism isn't for sale

There is no way for a business to pay for the removal of a genuine negative rating — not a plan, not a partner programme, not a phone call. What a business can do is reply, in public, right under the rating. A rating only comes down if it breaks the rating rules, and that decision is made by a moderator who doesn't know whether the business pays us anything.

Both sides on the record

Once a page is claimed (how that's verified), the owner and their team can reply to any rating, and the customer can reply back. Replies are public and labelled, so a reader always sees who said what. We think a good reply to a bad rating is the most persuasive thing on the page — and we'd rather businesses argue their case than bury it.

Reports from the community

Any member can report a rating as spam, fake, abusive, off-topic, containing personal details, or "something else". Three unresolved reports hide a rating automatically until a moderator looks again. Reports are read by a person; using them as a weapon gets the reporting account restricted.

Every decision is logged

Publish, hold, hide, remove, restore — each moderator action is recorded with who did it and why. Removed ratings are excluded from scores and search but kept, so an appeal can reverse a mistake and a pattern of abuse stays investigable.

Who gets to speak for a business

A page is only "claimed" once the owner proves control of the business's domain: a role-address email, a DNS TXT or CNAME record, an HTML file, or a meta tag — all checked by our servers. Tokens expire after 7 days. A claim built on a misrepresentation is revoked when found.

What we can't promise

No filter catches everything. A patient attacker with real accounts and real domains can still get a few fakes through. Our answer is to make that expensive, keep the audit trail complete, and act fast when someone shows us a problem — not to pretend the problem doesn't exist.

Tell us

A rating that shouldn't be up: use Report this rating on the page. A whole account, a campaign, a security hole: write to us and a person will pick it up.