For governments & public bodies

Protect a population. Without building a database of it.

Population-scale child protection usually requires a national store of children’s communications. RoseShield runs detection on the citizen’s own handset, so that store is never assembled.

RoseShield detects risk. Your jurisdiction defines the response.

RoseShield never determines what constitutes an offense, never decides who is notified, and never reports to anyone.

What the engine does

Detects harm on the device, scores it, and acts on the thresholds your policy sets.

What stays sovereign

Definitions, escalation routes, retention, reporting obligations, and every decision that carries legal weight.

What centralization costs

Once children’s content is held centrally, these problems follow regardless of intent.

It can be breached

A store of children’s intimate communications is among the most valuable targets that could exist.

It can be repurposed

Built for child protection, available for everything else. Every future administration inherits it.

It can be compelled

What exists can be ordered produced. Architecture is a more durable protection than policy.

It must be defended in public

Central scanning of citizens’ messages has proved politically costly wherever it has been attempted.

It costs at scale

Central inference on national message volume is a permanent and growing compute bill.

It outlives its authors

A database built with good intentions is inherited by whoever governs next.

What RoseShield provides

A detection layer. The authority keeps control of policy, escalation and reporting.

Nothing to breach

There is no repository of children’s communications, because one is never assembled. A store that does not exist cannot be leaked, subpoenaed by a future government, or quietly repurposed.

The law stays yours

What counts as grooming, exploitation or a reportable event is a matter for your jurisdiction. The engine scores; your authority decides. That allocation is written into the architecture, not only the contract.

Defensible in public

On-device detection avoids the political exposure that central scanning has carried wherever it has been attempted.

Non-removable detection on citizens’ devices is a serious deployment decision, and we expect to be asked about it in those terms.

How a program runs

Technical validation, then a bounded pilot, then expansion against thresholds agreed in advance.

Technical validationNo citizens involved
Your engineers verify the architecture on your own hardware. Network traffic analysis, model footprint, battery and latency measured under your conditions.
Bounded pilotA defined cohort
An opt-in group at a size your regulator and your legal team are comfortable with. Success criteria and stop conditions written down before it starts.
EvaluationPublished, not asserted
Detection performance by harm category, false-positive rate by intervention tier, and what the pilot failed to catch.
ScaleOnly on gates met
Expansion against thresholds agreed in advance. If the evidence does not support the next stage, the next stage does not happen.

This sequence produces the evidence a parliamentary question, a court or a journalist will ask for, before it is asked for.

Arrange a briefing

Architecture, data flows, the sovereignty position and the program sequence. Bring your technical and legal teams.

Arrange a briefing