How platforms handle CSAM.

Independent assessments of how platforms detect, report and act on CSAM.

Recently reviewed

All platforms →

Roblox

roblox.com

D

A platform whose user base is substantially composed of children, carrying an in-product economy and open communication. Detection and moderation investment is significant in absolute terms and insufficient relative to the exposure the product design creates.

Reviewed 2026-04-18

Meta

meta.com

C

Files the overwhelming majority of all CyberTipline reports and operates the most developed detection stack of any assessed operator. The 2023 default rollout of end-to-end encryption on its largest messaging surface removed server-side detection from the place where most of that reporting originated.

Reviewed 2026-04-15

WhatsApp

whatsapp.com

C

Message content is end-to-end encrypted and not scanned. Detection is therefore confined to unencrypted surfaces – profile images, group names and descriptions – plus behavioural signals and user reports, which is what the reporting volume reflects.

Reviewed 2026-04-15

Discord

discord.com

C

Detection on public surfaces is credible and the operator files at volume with NCMEC. The gap is private space: server-scoped and direct messaging carry the bulk of documented harm, and the enforcement record shows removal outpacing any structural change to how adults reach minors.

Reviewed 2026-04-11

Snap

snap.com

C

Detection and reporting are established. The unresolved issue is a product built around ephemerality and stranger discovery, which shapes both the harm pattern and what evidence survives it.

Reviewed 2026-04-09

X

x.com

D

Trust and safety headcount was reduced substantially from 2022. Reporting volumes rose while transparency disclosure narrowed, and independent research has documented known material remaining available after detection was possible.

Reviewed 2026-04-05

How grades are assigned

Each platform is assessed against 21 criteria across four axes. Every criterion is a pass, a fail, or neutral.

A

Comprehensive

Meets the standard across effectively all criteria, with published evidence.

B

Adequate

Meets the standard on the substantive criteria, with identified gaps.

C

Partial

Meets some criteria; material gaps in coverage, disclosure or enforcement.

D

Deficient

Fails the substantive criteria. Measures exist but do not function at scale.

F

Failing

No effective measures, or measures contradicted by the documented record.

Read the methodology

Report CSAM

If you have encountered CSAM, file a report through one of these channels.