← Back to app

Technical Specification

Last updated: August 2026  ·  Version 1.2.0  ·  ChildSafe AI by Privacomply Ltd

1. Platform Overview

FieldDetail
Versionv1.2.0 — ChildSafe AI
Release DateAugust 2026
DeveloperPrivacomply Ltd
DPO / ArchitectKevin Morrison, IAPP CIPP/E, CIPM
Websitechildsafe-ai.privacomply.co.uk

2. Technology Stack

ComponentTechnologyNotes
AI EngineGoogle Gemini gemini-3.6-flashDirect API mode (120s timeout); 5-attempt exponential backoff on 429/503/504
BackendNetlify Serverless Functions (Node.js ESM)Functions: gemini.mjs, proxy-download.mjs, scrape-website.mjs, get-regulatory-updates.mjs
DatabaseGoogle Cloud Firestore — europe-west2, London UKUser reports, audit history, My Library documents. UK data sovereignty enforced at infrastructure level.
AuthenticationFirebase Authentication (Google Sign-In)europe-west2, London UK
Hosting / CDNNetlifyGlobal CDN with UK/EU edge nodes; serverless function execution in UK region
FrontendVanilla JavaScript (ES2022)Single-page app; no framework dependencies
IntegritySHA-256 (Web Crypto API)HITL certificate hash: SHA-256(reportId|reviewerId|reviewDecision|reviewTimestamp)

3. Compliance Frameworks

FrameworkAuthorityJurisdictionStandards
UK GDPRICOUnited Kingdom14 articles assessed (Arts. 5–35)
ICO Children’s CodeICOUnited KingdomAll 15 Age Appropriate Design Code standards
DUAA 2025UK ParliamentUnited KingdomDigital Use and Access Act 2025
Online Safety Act 2023OfcomUnited KingdomChild safety provisions
EU AI ActEuropean CommissionEU/EEAHigh-risk AI provisions
KCSIE 2024DfEUnited KingdomKeeping Children Safe in Education
Digital Services ActEuropean CommissionEU/EEAPlatform obligations
UNCRC DigitalUN / 5RightsInternationalGeneral Comment 25 — children’s digital rights
SEND FrameworkDfE / NHSEUnited KingdomSpecial Educational Needs and Disabilities

4. Scoring Methodology

Compliance scores are computed automatically from the findings returned by the AI analysis pipeline. Each RED finding deducts 10 points from the base score of 100; each AMBER finding deducts 5 points. The minimum achievable score is 0.

Score = max(0, 100 − (red × 10) − (amber × 5))

RAG classification thresholds:

Score RangeRAG StatusMeaning
80–100● GREENCompliant
50–79● AMBERRequires Attention
0–49● REDCritical Risk

5. AI Processing Configuration

TaskParametersRetry Strategy
Main Analysistemperature: 0, maxOutputTokens: 5,000–20,000 (5,000 base + 4,000 per framework, capped at 20,000)5-attempt retry: 0s / 8s / 16s / 25s / 35s backoff
CC Standards + UK GDPR Articles Breakdowntemperature: 0, maxOutputTokens: 10,0005-attempt retry with 5s initial delay after main analysis
DPIA Generationtemperature: 0, maxOutputTokens: 8,0005-attempt retry: 0s / 8s / 16s / 25s / 35s backoff
90-Day Roadmaptemperature: 0, maxOutputTokens: 8,0005-attempt retry: 0s / 8s / 16s / 25s / 35s backoff

6. Human-in-the-Loop (HITL) Verification

HITL certification is required before compliance certificates are issued, in accordance with the ICO AI Governance Framework 2024 and Article 22 UK GDPR. The reviewer selects one of four Review Decisions, authenticates with a professional PIN (SHA-256 hashed, stored in browser localStorage only), and their name, qualifications, and timestamp are recorded. A SHA-256 integrity hash of the review record is computed and stored alongside the certificate.

Review Decisions:

7. Data Architecture

Data TypeStorage LocationNotes
Document content submitted for analysisBrowser memory only (JS state object)Never persisted to disk, localStorage or database. Discarded after analysis.
Documents saved to My Library🇬🇧 Firestore, europe-west2, London UKStored per authenticated user UID. Deleted on user request.
Compliance reports (scores, findings, breakdowns)🇬🇧 Firestore, europe-west2, London UKStored per authenticated user UID.
Audit history🇬🇧 Firestore, europe-west2, London UKTimestamped HITL-certified review records.
Reviewer registryBrowser localStorage onlyReviewer name, qualifications, SHA-256 hashed PIN. Never transmitted to server.
Browser historyBrowser localStorage onlyUp to 25 analysis summaries — no document content.

8. Website Scanner

The website scanner feature (marked WORLD FIRST) automatically extracts publicly accessible privacy policies, cookie banners, and consent mechanisms from a target URL using the scrape-website.mjs serverless function. Deterministic signal detection checks for cookie consent banners, age gate mechanisms, data collection indicators, and tracking scripts. Results are then analysed against all selected compliance frameworks using the same AI pipeline as document analysis.

9. Copyright and Licensing

© 2026 Privacomply Ltd. All rights reserved. ChildSafe AI is a proprietary product of Privacomply Ltd. Designed and developed by Kevin Morrison IAPP CIPP/E, CIPM.

ChildSafe AI Technical Specification v1.2.0 · August 2026 · Privacomply Ltd · Designed by Kevin Morrison CIPP/E CIPM