Methodology
Every platform is assessed against the same 21 criteria, grouped into four axes. Criteria are fixed in advance of assessment and their identifiers are stable across revisions, so that a platform's record can be compared against itself over time.
Verdicts
The operator's practice satisfies the stated standard, evidenced by published documentation or independent reporting.
The standard is not satisfied, or the operator's stated practice is contradicted by the documented record.
Partly satisfied, unstated in scope, or without sufficient public evidence either way. Never resolved by inference in the operator's favour or against it.
Grades
Axis grades are assigned on the balance of verdicts within that axis, weighted so that failures on criteria governing private surfaces count more heavily than failures on public ones. The overall grade is a weighted composite of the four axes, not an average.
Comprehensive
Meets the standard across effectively all criteria, with published evidence.
Adequate
Meets the standard on the substantive criteria, with identified gaps.
Partial
Meets some criteria; material gaps in coverage, disclosure or enforcement.
Deficient
Fails the substantive criteria. Measures exist but do not function at scale.
Failing
No effective measures, or measures contradicted by the documented record.
Criteria
Detection & scanning
Whether known and novel abuse material is found at all, and across which surfaces of the product.
Hash matching on publicly posted media
All images and video posted to public surfaces are matched against known-CSAM hash sets before or immediately after publication.
Hash matching on private messages and attachments
Media sent in one-to-one and group messaging is matched against known-CSAM hash sets, not only when a user reports it.
Classifier detection of previously unseen material
A trained classifier flags material that has no existing hash, with human review before enforcement.
Detection applied to live and streamed video
Live broadcast surfaces are sampled and assessed while the stream is running, not only after archival.
Detection of grooming and solicitation in text
Conversational patterns indicating adult solicitation of minors are detected and escalated.
Participation in industry hash-sharing programmes
The operator both consumes and contributes to shared hash sets such as those run by NCMEC, IWF and Tech Coalition.
Reporting & transparency
What the operator tells NCMEC, law enforcement and the public, and whether those disclosures can be checked.
Files CyberTipline reports to NCMEC
Confirmed apparent CSAM is reported to NCMEC as required, rather than only removed.
Publishes child-safety enforcement figures
A recurring transparency report gives removal volumes, account actions and report counts specific to child sexual exploitation.
Report quality sufficient for investigation
Reports carry the metadata law enforcement needs to act – originating account, timestamps, IP where lawful, and the file itself.
Reporting cadence and timeliness
Reports are filed on discovery rather than batched into periodic submissions that delay investigation.
Response & enforcement
What happens after material is found: how fast it comes down, what happens to the account, and whether the decision can be contested.
Time to removal of confirmed material
Confirmed material is removed within hours of detection, with the interval published.
Account termination on confirmed violation
Accounts that distribute confirmed CSAM are terminated, not warned or rate-limited.
Prevention of re-registration
Terminated accounts are prevented from returning through device, payment or identity signals.
Preservation of evidence
Account data and content are preserved for the statutory period so that investigations are not foreclosed by deletion.
Escalation of imminent-harm cases
Cases indicating an ongoing threat to a child are routed to law enforcement immediately, outside the normal queue.
Product & policy posture
The design decisions that determine how much abuse is possible in the first place, before any detection is applied.
Protective defaults for minor accounts
Accounts registered to minors default to private, with discovery and messaging restricted without opt-in.
Restrictions on adult-initiated contact with minors
Adults cannot initiate contact with accounts known to belong to minors absent an existing connection.
Age assurance at registration
Age is established by something more than an unverified self-declared date of birth.
Recommendation systems assessed for minor-safety harm
Ranking and recommendation systems are tested for whether they connect adults with minors or surface exploitative material, with results disclosed.
Encryption posture and stated mitigations
Where end-to-end encryption is deployed, the operator publishes what compensating detection it applies at the endpoint or through metadata and reporting.
Published child-safety policy with defined enforcement
A public policy states what is prohibited and what the consequence is, in terms specific enough to be held to.