Principles
The limits are the product
An evidence system that cannot say what it refuses to do is a surveillance system with better manners. These are the commitments, stated so that breaking one would be provable.
Commitments
What we do
- Public sources only.
- Material published in order to be found. If reaching it requires being let in, we are not there.
- Human review before every escalation.
- Nothing leaves the organisation on a model’s judgement alone. A named person decides, and the decision is logged.
- Protect legitimate criticism explicitly.
- Criticism of a government, state, army, policy, party or leader — including Israel’s — is a defined, reviewed classification outcome, not an afterthought.
- Separate severity from confidence.
- Two scores, never merged, with the model’s confidence recorded apart from the reviewer’s.
- Data protection by design.
- Minimisation, retention limits, role-based access, audit logging, and a data protection impact assessment before any operational deployment in the EU. All planned; none yet in place [3].
- Publish aggregate statistics openly.
- Counts, trends, categories, languages and platforms, published as open aggregates that anyone may use. Anonymised only: no post content, no usernames, no personal data of any kind. This is a commitment to statistics, not the promise of an open content database. The schema, the suppression threshold and the limits are set out on accountability.
- Publish our error rates.
- Including the unflattering ones. A monitoring organisation that only reports its successes is reporting nothing.
- Measure the platforms, not only the content.
- Response times, action rates, appeal outcomes and re-uploads, published as dated editions with the method released ahead of the results. This is a commitment and nothing has been measured yet — see the Platform Accountability Index.
- Date and version what we publish.
- Every substantive page carries a version and a date, and changes are recorded rather than quietly applied.
- State what we have not done.
- No entity, no pilot, no partners, no case files. Said first, not discovered later.
What we never do
- We do not name people.
- Our output describes content, addresses and dates. It does not label individuals, publicly or privately.
- We do not read private messages or enter closed spaces.
- Public sources only. No credentials, no membership, no infiltration.
- We do not run reporting swarms.
- Volume is not a tactic. A well-built single notice is.
- We do not file anything a person has not approved.
- No automatic notices, no automatic complaints, no automatic legal action.
- We do not publish blacklists.
- No public register of names, no shaming index, no scoreboard.
- We do not treat criticism of a government as antisemitism.
- Including criticism of Israel’s. The reference definition is non-legally binding and is applied with that protection stated [4].
- We do not profile individuals.
- Our research is about content, networks and institutions. Never about predicting what a person will do.
- We do not reproduce the content.
- No antisemitic text, image, symbol or paraphrase appears on this site. Reprinting is distribution, not documentation.
- We do not publish synthetic imagery.
- No AI-generated images anywhere on this site, and no photograph of any person who is not a named, consenting member of the organisation.
- Our research collection only reads.
- Where collection is automated, it reads public material and does nothing else: it never posts, never replies, never engages, never brigades, never mass-reports, and never enters private spaces or closed groups.
If we ever break one of these, it should be possible to prove it. That is what the record is for.
Legal basis
The framework we operate under
Most organisations in this field do not publish the legal theory behind their collection. Civic Shield does, including the parts of it that are unsettled and the status it has not earned.
What Article 3 provides
Article 3 of the EU copyright directive for the Digital Single Market creates an exception allowing reproductions and extractions of works to which there is lawful access, for the purpose of text and data mining carried out for scientific research [1]. Article 7(1) of the same directive provides that contractual terms purporting to override that exception are unenforceable — which is why a website’s terms of use are not, on their own, the end of the question [1].
In September 2024 the Regional Court of Hamburg applied the German implementation of that exception in Kneschke v. LAION, the first substantive national decision to test it [2]. It is a first-instance judgment of one national court. It is a meaningful signal, not settled European case law, and this page should not be read as saying otherwise.
What Article 3 does not do
- It covers copyright and related rights only. It resolves one question, not the legality of an operation.
- Data protection applies independently. Holding public material that includes personal data still requires a lawful basis under Article 6, a condition under Article 9 where special-category data is involved, data minimisation, retention limits, and in all likelihood an impact assessment under Article 35 [3]. Text and data mining status does not touch any of that.
- Lawful access is still required. Publicly visible material qualifies. Login-gated, paywalled or private content does not.
- Technical blocking remains lawful. A service is entitled to rate-limit or block automated reading, and the exception does not create a right of access to anyone’s systems.
Governance — planned, and described as planned
None of the following exists yet. Each is a commitment made in the due-diligence package, and each will be reported against once there is an organisation capable of holding it.
- An independent board or supervisory committee with legal, technical, civil-society and governance expertise.
- An ethics and privacy advisory group covering free expression, privacy, human rights and trust-and-safety practice.
- A conflict-of-interest policy that includes donor influence, and quarterly reporting to funders.
- Full audit logging of every view, edit and export of a case record, with documented review decisions.
- Encryption in transit and at rest, role-based access control, and vendor review with data processing agreements.
References
Sources
- Directive (EU) 2019/790 on copyright and related rights in the Digital Single Market. Article 2(1) (definition of "research organisation"), Article 3 (text and data mining for scientific research), Article 7(1) (contractual provisions contrary to Article 3 are unenforceable).
- Landgericht Hamburg, judgment of 27 September 2024, case 310 O 227/23 (Kneschke v. LAION) — the first substantive national decision applying the scientific-research text-and-data-mining exception. A first-instance decision of one national court. It is persuasive, not settled EU-wide case law.
- Regulation (EU) 2016/679 — General Data Protection Regulation. Article 6, Article 9, Article 35.
- International Holocaust Remembrance Alliance, Working Definition of Antisemitism (adopted 26 May 2016; non-legally binding).
- Regulation (EU) 2022/2065 — Digital Services Act. Article 22 (trusted flaggers), cited here only to state that Civic Shield does not hold that status.
Next step
These commitments are meant to be checked, not believed.
The due-diligence pack contains the governance model, the safeguards, and the list of questions that are still open — including the ones on this page.