Research

Catch the danger. Protect the child.

A small family of focused models, each doing one safety job well. Most already run in our alpha. The rest are still in the lab. They run on the device itself, and none of them keep raw content.

01

Grooming-pattern recognition

A small language model that learns the shape of predatory talk. Secrecy pressure, pushing a child to move to another app, gifts, fishing for their age or address. It raises a flag a parent can act on, with no message contents attached, and it is tuned so that secrecy and isolation count for more than a simple age question.

In alpha
02

On-device content filtering

It checks images and text as a page loads and blocks the unsafe ones in place. Only the harmful part is removed, so the rest of an ordinary page keeps working and there are no blunt whole-site bans. Illegal child-abuse material is blocked on sight and reported as the law requires. It is never stored, shown, or generated.

In alpha
03

Reading the screen in encrypted apps

Plain OCR, running on the device, reads the text already drawn on screen. That lets it catch grooming even inside end-to-end-encrypted chats. It never logs keystrokes or passwords, and the text never leaves the device.

In alpha
04

Video detection and in-place rewriting

Our flagship alpha. It spots unsafe video as it plays and rewrites it on the fly, blurring or muting only the moments that are a problem and re-packaging the same stream so the rest plays without a break. It runs on the device and keeps no raw content.

In alpha
05

Offender-record matching

Early research into linking convictions that are already on the public court record, to support our journalism and help protect communities. A person reviews every match, it happens only after a case has been to court, and it is built around data-protection law. Never before a charge, never an automated accusation.

Research
06

Edge distillation

The work underneath all of it. We shrink every model so it runs offline on everyday hardware, from a mid-range phone to an ageing laptop, because protection that needs the cloud is protection an adult can switch off.

Research
White paper · How we train

We train for the harm we cannot miss.

The patterns the engine looks for did not come from guesswork. They came from grooming we have watched unfold first-hand, across years of frontline decoy operations, then tested and written down. That is the difference between a model trained on theory and one trained on how this actually happens.

We do not scrape children's data. The models learn from lawful public datasets, from examples of grooming that safeguarding practitioners label with us, from synthetic conversations, and from plenty of ordinary chat so the model does not cry wolf at every clumsy message.

Rules come first and the model comes second. A plain set of rules handles the obvious cases. The model is the thin layer on top for the rest. No large language model sits in the live path, which keeps the work fast, cheap to run, and easy to check.

We tune for recall on real danger rather than for a leaderboard, and we test against the way predators actually behave: keeping secrets, moving a child to another app, cutting them off from the people around them. Then we distill everything down small enough to run offline on everyday hardware, phones and laptops alike.

Nothing a child sends is ever used to train, and no raw content is kept. That is a hard rule, not a setting.

White paper · What we're aiming for

Where this is going.

A device a parent can trust
Something a parent can hand a child, or set up on the family computer, knowing the worst is caught, without anyone watching over the child's shoulder.
Cover every device, every platform
Text, images, video and audio, across apps and the web, judged on the device itself, built to run on Windows, Mac, Android, iOS, iPad and tablets, not just the phone.
Small enough for any device
Models light and fast enough to run on a cheap phone or an ageing laptop, and given away where giving them away protects more children.
A standard others can use
We publish how the work is done and open the tooling, so good protection does not stay locked inside one company.
Benchmark

We measured the frontier. Most of it looked away.

We built a benchmark of 36 real child-safety tasks across five areas, then ran six frontier models through it. Only xAI's Grok took the work on. That gap is a big part of why we build our own.

Grok-4.1 · xAI
79.9% average. 100% on real grooming cases, 95.2% on stranger-meeting scenarios.
Grok-3 · xAI
59.5% average.
Claude-Opus-4.6 · Anthropic
42.2% average. Declined the real-grooming and health-risk tasks.
Gemini-3-Pro / 2.5-Pro · Google
Declined most tasks. 0.0%.
GPT-5 · OpenAI
Declined all five categories. 0.0%.

Scores are from our own benchmark, run in June 2026 against the model versions named above. Each provider's safety filters may behave differently over time. The method, prompts and per-task results are linked above so anyone can check the work.

Disclosure

What we publish, and what we never will.

We publish
How the models work, how we test them, what we find, and the open-source tooling around them.
We never publish
A child's data, a raw grooming dataset, or live model weights, and nothing that would help an adult get around the protection. That stays closed for good.

Backers · partners · researchers

Help us build the AI that keeps children safer.

We are a small, self-funded team, four years into this. If you fund safety research, want to build with us, or want to put these models to work protecting children, get in touch.