What we examine
- Account security: authentication, account recovery, and detection of compromised or impersonated accounts
- Privacy and visibility defaults, and how they differ for younger users
- Age assurance: self-declared birthdates, age estimation, and account-linkage signals
- Parental and supervision tools, and messaging or contact restrictions between adults and minors
- Reporting, blocking and content-moderation workflows, and the records they generate
- Logs, retention and data available to reconstruct what a user saw and did
Questions we help answer
- Which controls were available at the relevant time, and how were they configured by default?
- Did they work as described, and could a user or offender get around them?
- How do they compare with the technical safeguards available and in use at the time?
- What do the account and platform records show about the controls actually in effect?
- What additional records should be requested in discovery to answer these questions?
How it fits your case
We review platform documentation, account records, and technical productions in discovery, test features where possible, and explain in plain terms how the controls worked, what they could and could not prevent, and the limits of what the evidence shows.