Vendor Verification Guide

Check Reviews

Feedback history tells you more sorted by most recent than by overall score, since a vendor's current performance is what you're actually about to experience — an aggregate score built up over a year can mask a rough last month. Prioritize reviews that describe something specific: actual product quality, real shipping time, how the vendor communicated when something needed clarifying. A vendor with hundreds of reviews that are all vague one-liners ("great!", "fast!") is a pattern worth treating with suspicion rather than reassurance — that's often what review manipulation looks like at scale, not what organic feedback looks like. Check whether reviewer accounts have activity beyond the single review in question; an account that exists only to leave one glowing review for one vendor is a weak signal on its own, but several of them clustered on the same vendor is a stronger one.

💡 Tip: Hundreds of reviews that are all vague one-liners is a pattern worth suspicion, not reassurance — that's often what manipulated feedback looks like at scale.

🔐 PGP Verification

A vendor's PGP key fingerprint is a more reliable identity anchor than their username, since usernames can be squatted or impersonated but a private key can't be forged — check it against records on other markets and forums where the same vendor claims to be active. A vendor operating legitimately across platforms signs with the same key everywhere; a fingerprint that doesn't match between two places they claim to be the same person is worth treating as a real discrepancy, not a technicality. If anything feels off, request a freshly signed message rather than accepting an old one as proof — a signature proves the key holder signed that specific message, not that they're trustworthy in general, so use it to confirm identity, not character. A vendor's key that changes without a signed transition announcement from the old key is the single clearest signal something is wrong: a legitimate rotation always signs the announcement with the outgoing key first.

💡 Tip: A legitimate PGP key rotation is always announced and signed by the outgoing key first — an unexplained key change with no signed transition is the clearest compromise signal there is.

📊 Statistics

No single number tells the whole story, so weigh vendor metrics together: account age (3-6 months as a rough floor for "established"), total completed orders (50+ as a reasonable reliability bar), how often the vendor loses disputes rather than just how many they've had, average response time (under 24 hours is a healthy baseline), and the share of orders marked shipped on schedule. Compare all of it against other vendors in the same category rather than against an absolute standard, since normal response times and shipping windows vary meaningfully between product types. Resist the instinct to treat a brand-new vendor with zero disputes as automatically safer than an established one with a few — a spotless record on a handful of transactions isn't evidence of anything yet, it's just a small sample size.

💡 Tip: A new vendor with zero disputes isn't safer than an established one with a few — it's just a smaller sample size that hasn't been tested yet.

⚠️ Important Warnings

  • 🔑 An unexplained PGP key change with no signed transition from the old key is the clearest compromise signal there is
  • 🗣️ A cluster of vague, near-identical reviews is a manipulation pattern, not reassurance
  • 📊 Weigh vendor metrics together, compared against the same category — not against one absolute standard
  • 🆕 A spotless record on very few transactions is an untested sample, not proof of trustworthiness