Remove or observe
Ending a dangerous interaction can protect the child but break the investigative line. Continuing to observe may preserve intelligence but risks leaving the child inside the interaction that is causing the harm.
Platform-integrated child protection
SafeHaven is a platform-controlled protective architecture designed to remove a child from a suspected grooming interaction at the point of risk—without requiring the investigation to end with the child’s withdrawal.
Its Digital Air-Lock separates supported child-facing routes first. The suspect-facing session can then be preserved inside isolated, governed containment for a proposed Live Safeguarded Handover. SafeHaven does not autonomously conduct a sting or investigation: authorised law enforcement determines whether to observe, assume control, use approved evidential capabilities or terminate.
The child is removed from exposure. The child is never made an investigative instrument.
The critical difference
Detection, reporting, moderation and account restriction remain essential. But once a suspected grooming interaction has escalated, conventional processes can face a damaging trade-off: end the contact and lose continuity, or keep watching while the child remains exposed. SafeHaven is designed to separate those two outcomes.
Ending a dangerous interaction can protect the child but break the investigative line. Continuing to observe may preserve intelligence but risks leaving the child inside the interaction that is causing the harm.
The child-facing route is cut first. A separate, isolated synthetic endpoint can then preserve suspect-facing continuity, evidential context and an actionable referral package—without requiring the child to remain present.
Protection-first architecture
SafeHaven is intended to operate within a platform’s own routing, moderation and evidence systems. It does not depend on the child continuing the conversation, collecting evidence or understanding that an investigative process has begun.
Approved platform signals and policy determine when the interaction requires a controlled protective transition. SafeHaven is not positioned as an autonomous oracle that declares criminal guilt.
The platform separates supported child-facing routes and places the child into a neutral safe state before any suspect-facing continuation is permitted.
A separate fictional endpoint can hold the suspect-facing session inside containment without retaining any route back to the child. It does not clone the child’s voice, image or persistent identity. Any authorised post-handover activity is separately recorded and never attributed to the child.
Platform-held context, triggering conduct, identifiers, route-state evidence and any clearly labelled post-handover activity can be sealed into a structured, auditable referral package and disclosed only through authorised, lawful channels.
Remove the child. Seal the route. Preserve the evidence. Continue only inside a synthetic, isolated and lawfully governed environment.
Safety is not traded for evidence. Synthetic continuation is permissible only after the child has been detached from the supported interaction routes.
The law-enforcement value
Online child-abuse investigations can require specialist officers to find a viable subject, develop engagement, assess risk and establish the context needed for an actionable inquiry. When a case arrives only after the interaction has ended, the account has disappeared or the record has fragmented, investigators may also have to reconstruct what happened before meaningful enquiries can begin.
SafeHaven’s broader proposition is not merely to preserve one conversation. At platform scale, each validated Digital Air-Lock event could generate a time-sensitive, structured and auditable referral: a recently active account, the conduct that caused the protective threshold to be met, preserved platform context, a child already removed from exposure and the current state of the contained suspect-facing session.
Fragmented retrospective referral
Actionable referral package
Proposed Live Safeguarded Handover. Where formal integration, legal authority and operational governance exist, an authorised investigator could be permitted to observe the contained session, assume direct control, deploy approved case-bound evidential capabilities—including an in-platform link where lawfully authorised—or terminate the interaction. Law enforcement determines the investigative strategy; SafeHaven supplies the protected technical boundary, evidential continuity and audit trail.
No autonomous sting or investigation. SafeHaven does not independently impersonate the child, investigate the suspect or decide to deploy attribution tools. If no authorised takeover occurs, the child remains protected and the contained session stays in a governed hold state or ends according to approved policy.
An actionable referral is not a finding of guilt or identity. SafeHaven creates no independent law-enforcement access to a platform and cannot guarantee attribution, arrest, prosecution or rescue. Every case package and handover remains governed by platform authority, evidential rules and lawful disclosure.
The potential time saving is an evaluation proposition, not a proven operational outcome. It should be tested with appropriate investigators by measuring referral quality, triage time, time to an actionable next step, the availability of usable identifiers and specialist officer hours saved against current workflows.
Non-negotiable safeguards
SafeHaven is built under Castellen Labs’ behaviour-driven CAST framework. The architecture begins with perpetrator behaviour, but its governing hierarchy remains safety-first.
No investigative benefit justifies leaving the child inside a suspected grooming interaction once the protective transition is made.
Believability comes from controlled context and session continuity—not biometric replication. If voice, video or unverifiable child-specific material is demanded, the decoy follows a governed deferral or termination pathway rather than fabricating it.
Platform control and lawful process define what can be preserved, continued, attributed or disclosed. The protocol cannot claim powers the platform does not hold.
Platform integration
The Digital Air-Lock depends on control of routing, account relationships, moderation state and evidence systems. SafeHaven is therefore designed for integration by gaming and social platforms, with participation from child-safeguarding and authorised law-enforcement partners.
The current development environment uses no real child, suspected offender, guardian or law-enforcement data and is not connected to live platforms. Its purpose is to demonstrate that post-Air-Lock delivery moves to the synthetic endpoint while supported child-accessible routes receive nothing.
Gaming and social platforms, Trust & Safety teams, child-safeguarding specialists, evidence and legal teams, and authorised law-enforcement evaluation.
Confidential evaluation
Castellen Labs welcomes confidential, non-operational evaluation with gaming platforms, specialist child-safeguarding teams, Trust & Safety researchers and appropriate law-enforcement stakeholders.
Phone
Web
Patent status
UK patent pending — GB2620363.8