Castellen Labs — Confidential Evaluation
Invisible Guardian is a server-authoritative, coercion-resistant safety protocol designed specifically for high-lethality domestic-abuse, stalking and abduction scenarios — when a perpetrator may be watching, demanding visible compliance or taking control of the handset.
It protects the safety commitment beyond the victim's control of the device and makes apparent compliance compatible with concealed escalation.
Request a confidential briefingThe Problem
Most personal-safety applications are built around a user who can still reach, operate and trust their phone. In a high-lethality coercion or abduction scenario, that assumption can collapse at the precise moment protection is needed most.
A perpetrator may watch the screen, inspect each action, demand that monitoring is cancelled, seize or destroy the phone, restrict connectivity or react to the smallest indication that help has been requested. A vibration, notification, callback, unusual delay or recognisable emergency sequence may expose resistance and escalate danger.
In that environment, asking the victim to keep the phone in hand, complete a conspicuous alarm flow, monitor the screen or actively gather evidence can create additional risk.
Invisible Guardian was created for this exact point: when observable help-seeking may itself be dangerous and the handset can no longer be treated as a trusted source of truth.
Scope
Invisible Guardian is not a general domestic-abuse app, an incident diary, a wellbeing tool, a journey companion or a consumer location tracker. It is not a replacement for emergency services, specialist safeguarding, professional risk assessment or an individual safety plan.
It is an additional protective layer for high-lethality circumstances including escalating coercive control, post-separation stalking, threatened or actual abduction, forced transport, confinement, demanded handset inspection or surrender, and forced cancellation of protection.
Guardian does not contain different user-selectable risk modes. The high-lethality threat model governs the entire architecture from the moment a protection commitment is accepted.
Conventional safety and evidence tools remain important before and after an incident. Invisible Guardian addresses a different problem: preserving protection when the victim may be unable to raise a visible alarm safely.
Architecture
The organising principle of Invisible Guardian is simple: once protection has been durably accepted, the server — not the phone — holds the authoritative safety state.
The victim establishes a time-bound protection commitment while they still control the device. Once the server accepts it, the deadline, response policy and event chronology remain outside the handset's control. Closing the application, logging out, losing connectivity, powering off the phone or destroying its local data cannot silently satisfy or cancel that accepted commitment.
From that point forward, the handset is treated as potentially watched, controlled, seized, disconnected or destroyed.
Some safety systems may place an individual timer or counter on a server. Invisible Guardian is built around a broader principle: the server-held safety commitment and the assumption of hostile observation govern every state transition, visible response, cancellation attempt and escalation pathway.
An accepted deadline remains server-held after device seizure, disconnection or destruction. If safe completion is not authoritatively validated before that deadline, the configured response can begin without any further action from the handset.
Coercion Resistance
Invisible Guardian recognises that a perpetrator exercising coercive control may not be satisfied because an application simply closes. They may demand proof that monitoring has stopped, reopen the application, inspect its history or force the victim to repeat the cancellation process.
Guardian therefore treats credible visible disarmament as an end-to-end safety property — not as a single confirmation screen.
The genuine safety credential and universal duress credential are designed to produce the same ordinary-looking confirmation, timing, navigation, feedback and continuing interface reality. To the observer, protection appears to have been successfully disarmed in either case. The server alone retains the protected truth.
When safety has genuinely been established, the server validates the authorised safe completion and closes or resets the commitment according to policy.
When the protected credential is submitted under coercion, the device presents the same credible disarmament outcome while the server records the protected event and initiates the configured escalation pathway.
Protocol 03
If a perpetrator discovers the system or directly asks whether protection exists, concealment may no longer be credible. Transparent Compliance allows the victim to truthfully acknowledge the protection and visibly demonstrate apparent disarmament through the ordinary interface.
The perpetrator sees the demand being obeyed. The protected submission initiates concealed server action.
This removes the need for the victim to sustain a lie after discovery and turns apparent compliance into a possible path to protection rather than treating discovery as automatic system failure.
Protocol 04
In some high-lethality circumstances, waiting for a routine deadline — or waiting for the perpetrator to discover the system — may itself be dangerous.
Proactive Disclosure allows the victim, where they judge it safer, to reveal the protection or offer to demonstrate disarmament before the perpetrator demands it. A protected submission can then advance the configured response without weakening or delaying the already accepted deadline.
This is an optional survival pathway, not an instruction to disclose and never a promise that disclosure will calm or de-escalate a perpetrator. The decision remains with the victim.
Transparent Compliance and Proactive Disclosure provide potential lifelines in circumstances where secrecy has already failed — or where waiting for it to fail may create even greater danger.
Safety Hierarchy
Evidence is essential to building prosecutable cases. But at the point of threatened abduction, forced confinement or escalating violence, asking the victim to gather more evidence can become dangerous.
Invisible Guardian follows a strict safety hierarchy:
Design Rationale
A repeated emergency sequence such as 9999 may appear easy to remember, but under hostile observation the risk begins before the final digit is entered. Repetition becomes increasingly recognisable as the sequence develops, and a controlling observer does not have to wait for the final digit before reacting.
Invisible Guardian deliberately uses a universal duress PIN designed to be simple and easily remembered under extreme stress. It avoids conspicuous repeated emergency patterns that may become recognisable as they are entered. The genuine-safety and duress journeys are designed to remain visually and behaviourally equivalent throughout the interaction.
The duress credential is only one part of the system. Server authority, silence, observational equivalence, credible continuing disarmament, Transparent Compliance, Proactive Disclosure and protected expiry operate together as one architecture.
Device Independence
Once a commitment has been accepted, the following remain held by the server if the handset is seized, disconnected, powered off or destroyed:
Guardian does not pretend that device loss has no consequences. A disconnected or destroyed phone cannot provide new location, audio, video or other telemetry. A protected submission cannot create immediate server action if it cannot reach the server. In that situation, the previously accepted server deadline remains the independent fallback.
Integration
Invisible Guardian is designed as an additional protocol layer for established personal-safety platforms, monitoring providers, specialist safeguarding organisations and authorised response pathways.
It is not intended to replace existing monitoring centres, emergency services or operational response teams. Its role is to extend protection into threat conditions that conventional device-led interactions do not fully address: hostile observation, forced cancellation, loss of handset control and the inability to raise a visible alarm.
Its architecture, source materials and operating demonstration are available to qualified institutional, safeguarding, security and research partners through controlled confidential evaluation.
Engagement
Invisible Guardian is designed for the point at which the victim may be unable to raise an alarm, the phone may be controlled by the perpetrator, any visible cue may escalate violence, and convincing proof of compliance may be demanded.
The server retains the safety commitment. The handset presents the reality most likely to preserve the victim's immediate safety.
Castellen Labs welcomes confidential engagement from monitored-safety providers, domestic-abuse and safeguarding organisations, independent security specialists, survivor-led researchers and academic assurance partners.
If someone is in immediate danger in the UK, call 999 when safe to do so.
Invisible Guardian is an additional protection architecture under development. It does not replace emergency services, police response, specialist domestic-abuse support, professional safeguarding or an individual safety plan. It cannot guarantee connectivity, location continuity, intervention, rescue, de-escalation or survival.