UK patent pending — Application GB2620363.8

Platform-integrated child protection

Remove the child.
Preserve the line of inquiry.

SafeHaven is a platform-controlled protective architecture designed to remove a child from a suspected grooming interaction at the point of risk—without requiring the investigation to end with the child’s withdrawal.

Its Digital Air-Lock separates supported child-facing routes first. The suspect-facing session can then be preserved inside isolated, governed containment for a proposed Live Safeguarded Handover. SafeHaven does not autonomously conduct a sting or investigation: authorised law enforcement determines whether to observe, assume control, use approved evidential capabilities or terminate.

The child is removed from exposure. The child is never made an investigative instrument.

The critical difference

Protection and investigation no longer have to compete

Detection, reporting, moderation and account restriction remain essential. But once a suspected grooming interaction has escalated, conventional processes can face a damaging trade-off: end the contact and lose continuity, or keep watching while the child remains exposed. SafeHaven is designed to separate those two outcomes.

THE CONVENTIONAL TENSION

Remove or observe

Ending a dangerous interaction can protect the child but break the investigative line. Continuing to observe may preserve intelligence but risks leaving the child inside the interaction that is causing the harm.

THE SAFEHAVEN SEPARATION

Remove and preserve

The child-facing route is cut first. A separate, isolated synthetic endpoint can then preserve suspect-facing continuity, evidential context and an actionable referral package—without requiring the child to remain present.

Protection-first architecture

A controlled transition, not another moderation alert

SafeHaven is intended to operate within a platform’s own routing, moderation and evidence systems. It does not depend on the child continuing the conversation, collecting evidence or understanding that an investigative process has begun.

Protective transition

Approved platform signals and policy determine when the interaction requires a controlled protective transition. SafeHaven is not positioned as an autonomous oracle that declares criminal guilt.

Child removed first

The platform separates supported child-facing routes and places the child into a neutral safe state before any suspect-facing continuation is permitted.

Suspect-facing session preserved

A separate fictional endpoint can hold the suspect-facing session inside containment without retaining any route back to the child. It does not clone the child’s voice, image or persistent identity. Any authorised post-handover activity is separately recorded and never attributed to the child.

Actionable referral prepared

Platform-held context, triggering conduct, identifiers, route-state evidence and any clearly labelled post-handover activity can be sealed into a structured, auditable referral package and disclosed only through authorised, lawful channels.

Remove the child. Seal the route. Preserve the evidence. Continue only inside a synthetic, isolated and lawfully governed environment.

Safety is not traded for evidence. Synthetic continuation is permissible only after the child has been detached from the supported interaction routes.

The law-enforcement value

An actionable referral package with a live safeguarded handover pathway

Online child-abuse investigations can require specialist officers to find a viable subject, develop engagement, assess risk and establish the context needed for an actionable inquiry. When a case arrives only after the interaction has ended, the account has disappeared or the record has fragmented, investigators may also have to reconstruct what happened before meaningful enquiries can begin.

SafeHaven’s broader proposition is not merely to preserve one conversation. At platform scale, each validated Digital Air-Lock event could generate a time-sensitive, structured and auditable referral: a recently active account, the conduct that caused the protective threshold to be met, preserved platform context, a child already removed from exposure and the current state of the contained suspect-facing session.

Fragmented retrospective referral

  • A potential subject must first be found or referred
  • Engagement and context may need to be developed from zero
  • The original interaction may already have ended
  • Records may be incomplete and account identifiers stale
  • Officer time begins with discovery, triage and reconstruction

Actionable referral package

  • Generated by a validated post-platform-threshold event
  • A recently active account and triggering conduct preserved
  • Time-ordered context and identifiers retained by the platform
  • The child removed before investigative handoff
  • The contained session state available for an authorised decision
  • A structured, higher-integrity starting point for lawful triage

Proposed Live Safeguarded Handover. Where formal integration, legal authority and operational governance exist, an authorised investigator could be permitted to observe the contained session, assume direct control, deploy approved case-bound evidential capabilities—including an in-platform link where lawfully authorised—or terminate the interaction. Law enforcement determines the investigative strategy; SafeHaven supplies the protected technical boundary, evidential continuity and audit trail.

No autonomous sting or investigation. SafeHaven does not independently impersonate the child, investigate the suspect or decide to deploy attribution tools. If no authorised takeover occurs, the child remains protected and the contained session stays in a governed hold state or ends according to approved policy.

An actionable referral is not a finding of guilt or identity. SafeHaven creates no independent law-enforcement access to a platform and cannot guarantee attribution, arrest, prosecution or rescue. Every case package and handover remains governed by platform authority, evidential rules and lawful disclosure.

The potential time saving is an evaluation proposition, not a proven operational outcome. It should be tested with appropriate investigators by measuring referral quality, triage time, time to an actionable next step, the availability of usable identifiers and specialist officer hours saved against current workflows.

Non-negotiable safeguards

The child cannot become part of the investigative mechanism

SafeHaven is built under Castellen Labs’ behaviour-driven CAST framework. The architecture begins with perpetrator behaviour, but its governing hierarchy remains safety-first.

01

Remove exposure first

No investigative benefit justifies leaving the child inside a suspected grooming interaction once the protective transition is made.

02

Preserve without cloning

Believability comes from controlled context and session continuity—not biometric replication. If voice, video or unverifiable child-specific material is demanded, the decoy follows a governed deferral or termination pathway rather than fabricating it.

03

Operate within authority

Platform control and lawful process define what can be preserved, continued, attributed or disclosed. The protocol cannot claim powers the platform does not hold.

Platform integration

Protective infrastructure—not a standalone child app

The Digital Air-Lock depends on control of routing, account relationships, moderation state and evidence systems. SafeHaven is therefore designed for integration by gaming and social platforms, with participation from child-safeguarding and authorised law-enforcement partners.

Synthetic-only demonstrator

The current development environment uses no real child, suspected offender, guardian or law-enforcement data and is not connected to live platforms. Its purpose is to demonstrate that post-Air-Lock delivery moves to the synthetic endpoint while supported child-accessible routes receive nothing.

Designed for

Gaming and social platforms, Trust & Safety teams, child-safeguarding specialists, evidence and legal teams, and authorised law-enforcement evaluation.

Not represented as

  • An autonomous sting, criminal-detection or investigative service
  • A covert hacking or surveillance tool
  • A consumer-installed child-safety application
  • A replacement for safeguarding professionals or authorities
  • A guarantee of identification, intervention, arrest or prosecution

Confidential evaluation

A new architecture for ending exposure without ending the inquiry

Castellen Labs welcomes confidential, non-operational evaluation with gaming platforms, specialist child-safeguarding teams, Trust & Safety researchers and appropriate law-enforcement stakeholders.

Email

jerome@castellenlabs.co.uk

Phone

0345 257 5020

Web

castellenlabs.co.uk

Patent status

UK patent pending — GB2620363.8