What can an age or identity signal establish, and what remains ungoverned once it has been established?
The questions the programme is built to answer.
This is the evidence layer of the programme. It sets out what the programme studies, whose statement a reader is looking at in each case, and what it deliberately does not claim to have established.
Seven open questions.
Each is a question the architecture is designed around. None is presented as settled, and no finding is claimed for any of them.
How does risk differ between recommendation, continuous media, messaging reach and engagement mechanics, and what follows for governing them separately?
How can protective treatment be applied without accumulating more personal data about young users than the protection itself requires?
Where controls can be worked around, what signals indicate it, and how should a governance layer respond over time rather than once?
What changes when the counterparty in an interaction is an automated system rather than another user?
What makes a record of a platform decision examinable by an authority, and reliable enough to be worth examining?
How does a written obligation become something a system can apply consistently across jurisdictions?
Whose statement is this?
Four kinds of material inform the programme. They are kept distinct so a reader can always tell which one they are reading.
The company’s own architectural and institutional analysis. It is a position, not an independently validated finding, and is not presented as research evidence.
Regulations, guidance and codes issued by named authorities. Each is attributed to its issuing authority with a source date and a last-reviewed date on the regulatory page.
Work published by third parties. Where cited, it is attributed to its authors and never restated as a CIVITERA finding.
Published standards and specifications, which describe target environments rather than conformity held by CIVITERA.
Where external material is used.
Regulatory and policy material is attributed to the authority that issued it, with a source date and a last-reviewed date, and is presented on the regulatory page rather than summarised into a claim here.
CIVITERA’s own published analysis is available through the research page. It is the company’s position, not an independently validated result.
- Public-authority records
- 10, each attributed and dated
- Issuing authorities
- 8
- Findings published
- None
- Independent validation
- Not claimed
What this programme does not publish.
Stated openly rather than merely observed.
- Research findings or prevalence figures the program has not established.
- Any characterisation of a named platform’s features, practices, or compliance position.
- Filing architecture, claim scope, or the relationship between a filing and any platform feature.
- Material provided to counterparties under confidentiality.
This page sets out the questions the program studies and the standard applied to answering them. It does not publish research findings, prevalence figures, or measured outcomes, and CIVITERA does not present its own analysis as independently validated research. Where a factual assertion comes from an external authority, that authority is named and dated. Nothing here is legal advice.
The rest of the programme.
The governance model, the capability layer, and the regulatory context these questions arise from.
Engage on research.
Qualified organisations studying digital safety, platform governance and technical implementation can contact the research division.