How it works and user guide

See how a review moves from public evidence to a human decision.

Learn how Survivor Tech Review gathers information, distinguishes source types, drafts findings, handles uncertainty, supports reviewer decisions, and turns the finished assessment into next steps and reports.

  • See where every piece of supporting information came from.
  • Understand what each finding does and does not establish.
  • Know what still requires a company answer, a spare-device test, or human judgment.
Start a review

01

The review model

The framework organizes its questions around three habits: question the claim, follow the data, and notice what is missing.

Three questions behind every review

Three questions behind every reviewThree overlapping circles labeled Question the claim, Follow the data, and Notice what's missing. The review sits where all three overlap.Questionthe claimFollowthe dataNotice what'smissingReview

Question the claim

  • What the product promises
  • What happens when it fails
  • How the AI invites disclosure

Follow the data

  • What information it collects or creates
  • Where the information goes
  • Who can see it
  • How long it stays, and what Delete really deletes
  • What traces of use remain

Notice what's missing

  • What is missing
  • Public signals of security engineering

02

What it is, and what it isn't

It is It is not
A structured review of public evidence and unanswered questionsA security test or an audit
A draft for a person to review, finding by findingAn automatic verdict, score, or rating
Clear about what it could not findA certification that anything is safe
Built on published survivor-safety guidanceLegal advice
Private: nothing is stored on the serverA place to enter survivor information

03

How a review runs

How a review progresses from a web address to a verified report: four automated analysis stages, a human decision gate, and report generation.

1. Read

  • The homepage, privacy policy, terms, security, FAQ, about, and data-rights pages, found through links and the sitemap.
  • App Store and Google Play listings, including the developer-reported privacy labels.
  • What the website sends a first-time visitor: security headers, cookies (and whether they carry standard protections), and the outside companies loaded on every page read. When enabled, optionally inspects publicly served client scripts for exposed private credentials, direct-to-cloud AI connections, and unencrypted local storage, and reads the visible settings of embedded chat tools.
  • Public records: whether the email domain publishes spoofing protection (SPF and DMARC), when the domain was registered, and, if the site states a nonprofit EIN, IRS Form 990 data from ProPublica. Linked PDF documents on the same site are read too.
  • Internet Archive history, to see when the privacy policy changed.
  • Long pages are read in parts, never silently cut. Text aimed at AI reviewers is withheld and shown to you.

04

How the research digs

The tool has to show how hard it looked. A question that comes back thin is searched again with broader queries before “nothing found” is accepted.

How each research question is searchedStart with suggested searches, read the results, then check: were there enough searches and at least one citable source? If not, run broader searches once and read again. If so, keep only pages that mention the product, and log every search.SuggestedsearchesRead results,open pagesEnoughto report?yesKeep pagesabout itLog everysearchnoBroader searches(once)
  1. Who is behind itIdentify the organization or person that makes and runs this product, and how accountable they are.
    "Example Chat"Standard and Extended
  2. Incidents, lawsuits, and regulatorsFind reported security incidents, data exposures, lawsuits, complaints, and regulatory actions involving this product or the company that makes it.
    "Example Chat" breach OR leak OR exposedStandard and Extended
  3. Independent reviews and pressFind reviews, testing, or reporting about this product by anyone other than its maker, especially domestic violence and privacy organizations.
    "Example Chat" reviewStandard and Extended
  4. What users reportFind reports from users about failures that matter for safety: features that did not work, the app being discovered, data lost or exposed, or support that did not respond.
    "Example Chat" redditStandard and Extended
  5. Outside companies and AI providersFor each outside company or service this product uses, find that organization's own documentation on data retention, who at the customer can see user data, and whether user data trains models. For AI products, find which AI model or provider is used.
    ChatDesk data retentionStandard and Extended
  6. Checking the product's security claimsLook for anything that verifies or contradicts the product's security and privacy claims: audits, certifications, security pages, disclosed encryption design, bug bounties.
    "Example Chat" security audit OR "penetration test"Extended only

Standard: about 6 searches and 2 full pages per question. Fewer than 4 searches, or nothing citable, triggers one broader round before “nothing found” is accepted. Extended: about 8 searches and 3 pages, with a broader round below 5.

Live example The research log for Example Chat. Open a question to see every search it ran.

Web research

Standard depth · 2 questions · 9 searches · 1 page read in full

Recorded from the searches themselves. Where a question came back thin, the tool sent it back once with broader searches before accepting “nothing found.” Nothing found is a statement about the search, not about the product.

  • Incidents, lawsuits, and regulatorsNo usable source found · 5 searchesDug deeper

    Searches run

    1. "Example Chat" breach OR leak OR exposed 4 results
    2. "Example Chat Inc." lawsuit OR settlement OR complaint 0 results
    3. "Example Chat Inc." FTC OR "attorney general" 1 results
    4. Example Chat data breach 3 results
    5. site:ftc.gov Example Chat Inc. 0 results

    Pages opened

    Seen but not used

    Results the search returned that were not cited. Worth a look if a finding seems thin.

    The AI's summary of this search

    A lead, not evidence. Only the sources above can be cited.

    Searched, nothing relevant: breaches, lawsuits, regulators (queries listed).

  • Outside companies and AI providersFound sources · 1 source · 4 searches

    Sources kept

    • E4 · ChatDesk: conversation history

    Searches run

    1. ChatDesk data retention 6 results
    2. ChatDesk view export conversations OR sessions 5 results
    3. Hotjar data retention 7 results
    4. Hotjar view export conversations OR sessions 4 results

    Pages opened

    The AI's summary of this search

    A lead, not evidence. Only the sources above can be cited.

    Found: ChatDesk keeps conversations until the owner deletes them, and owners can export them (E4).

05

Where the supporting information came from

Every quote carries a label showing who produced or observed it. Different source types can support different kinds of conclusions.

Direct observations & independent outside sources

  1. Observed on the public websiteObserved on the public website

    What the website actually sent to a visitor: scripts, headers, trackers, and cookies.

  2. Government, regulator, or court recordIndependent outside source

    An official public record independent of the product maker, though still dated.

  3. News, watchdogs, DV organizations, researchIndependent outside source

    Independent of the maker. Check the publication date and whether it addresses this exact product.

  4. Documentation from services the product usesDocumentation from services the product uses

    What an underlying service (e.g. AWS or Twilio) can do by default, not how this product configured it.

  5. Internet Archive recordHistorical copy of a product/company page

    Historical copy of a page over time. Shows what the company previously stated, not outside confirmation.

  6. Reported by the app publisherReported by the app publisher

    App store privacy declaration filled in by the publisher. The app store does not verify it.

  7. Forum post or user reviewIndependent outside source

    One person's subjective report. A lead worth checking, not an established fact.

  8. The product's own websiteProduct/company statement

    A statement from the product or company. The review's job is to check it, not repeat it.

Product/company statements & claims to check

06

Anatomy of a finding

A real finding card, with each part explained. Point at a number to highlight that part.

  1. What the reviewed information shows

    Seven statuses across four groups: Public answer, company information only, not answered (ask company, device test needed, or not established), and sources disagree (conflicting sources or one source raises a conflicting concern), always as an icon and words, never color alone.

  2. Potential impact for survivor safety

    Filled pips show potential impact if accurate: high, medium, lower, or context only. It does not measure likelihood or certainty.

  3. The review question

    The exact question from the survivor-safety review criteria this finding answers.

  4. The plain-language finding

    A short summary drafted by the AI. You check it against the quotes below.

  5. How well supported this finding is

    How many quotes and sources, and whether any are independent of the product's maker.

  6. The quote and who said it

    Checked word for word by code. The badge says who wrote it; select it to launch the Evidence Drawer with passage highlighting, SHA-256 fingerprint verification, and cross-references.

  7. What to do next

    A question for the company or product team and a hands-on test on a spare device, ready for your next-steps list.

  8. Checks applied by the review

    What the review changed and why, for example capping a status the evidence could not support.

  9. Your decision

    Include (Y) or Exclude (N or X), or set aside for another review (F, note required). Notes or flags do not count as a final decision.

07

Reading the results

The overview comes first: how many findings are decided, what matters most, what the reviewed information establishes, and where the gaps are.

Live example The overview for Example Chat.

What the reviewed information establishes

Public information answers this
The public information reviewed gives an answer to this question. The answer may describe a safeguard, a problem, or a serious concern. This label does not mean the product passed or is safe.
Company-provided information only
The answer comes only from a company describing its own product or service. The review did not find independent information or a direct observation confirming how the reviewed product behaves.
Not answered by the sources reviewed
The public information reviewed did not answer this question. This does not mean the practice or safeguard does not exist.
Needs an answer from the company
Public information is not enough to answer this question. The company or product team would need to explain how this works.
Needs a safe test on a spare device
Public information cannot answer this question. It needs to be checked on a spare device using made-up information, never real survivor information.
Sources disagree
Two or more reviewed sources give conflicting information about this question. Check the underlying sources before relying on either answer.
One source raises a conflicting concern
One reviewed source challenges the apparent answer or raises information that does not fit with it. Review that source before relying on the finding.

Potential impact for survivor safety

High potential impact
If this finding is accurate, it could materially affect a survivor’s safety, privacy, ability to remain undiscovered, access to help, records, evidence, or ability to make an informed choice.
Medium potential impact
If this finding is accurate, it could meaningfully affect how an advocate or survivor decides whether, when, or how to use the product, but the likely consequences are less severe or more limited than a high-impact finding.
Lower potential impact
This issue may still matter, but its likely consequences are more limited, easier to explain, or less directly connected to immediate survivor safety than higher-impact findings.
Context only
Useful context for understanding the product, but this finding does not identify a specific survivor-safety concern on its own.

Three separate dimensions every finding communicates

To understand review results clearly, keep these three distinct dimensions separate:

  • Finding status: What the reviewed public information was able to establish across the review questions (for example, whether public information answers the question, relies only on company-provided information, or is not answered by reviewed sources). A public answer can still describe a serious safety concern.
  • Potential impact: How much the issue could matter for survivor safety if the finding is accurate (high, medium, lower, or context only). It does not measure likelihood or certainty.
  • Verification strength: How independently the supporting information can be checked (from independent observations and public records to company statements).

Three examples showing why these dimensions are independent

1. High potential impact, but not yet answered

Question: How long does the service retain exact location history before permanent deletion?

Finding status: Needs an answer from the company (The reviewed public privacy policy does not state a retention period; the product team needs to clarify).

Potential impact: High potential impact (If accurate or unaddressed, stored location history could put a survivor at immediate risk of discovery).

Takeaway: Lack of public answers does not make an issue low-impact.

2. Answered by public information, but high potential impact

Question: Can company staff read users' private messages?

Finding status: Public information answers this (The privacy policy clearly discloses that authorized support staff can view stored chat transcripts).

Potential impact: High potential impact (Staff access to sensitive disclosures could matter greatly for a survivor's privacy and physical safety).

Takeaway: “Public information answers this” means the question is answered, not that the answer is safe or favorable.

3. Independently verified, but lower potential impact

Question: Does the homepage load third-party analytics scripts?

Finding status: Public information answers this (Observed directly via passive website observation).

Potential impact: Lower potential impact (An analytics script collects standard browser screen dimensions; meaningful for general web tracking, but lower direct impact for immediate survivor safety).

Takeaway: High verification strength does not make an issue high-impact.

Understanding verification and evidence clarity

Public Verification Strength

How strongly the review's findings can be checked against independent, observed, or otherwise public evidence. It does not measure whether the product is safe.

  • Strong: High percentage of findings supported by independent watchdogs, regulators, academic studies, or direct website observations.
  • Mixed: Balanced mixture of independent evidence, service provider documentation, and company statements.
  • Limited: Relies almost entirely on the company's own assertions with few or no independent checks.

Evidence clarity by safety topic

Shows how clearly the reviewed public evidence answers questions across five critical safety domains:

  • Data deletion: Whether data can truly be deleted from servers, backups, and downstream vendors.
  • Anonymity and traces: Protection against device indicators, recent app lists, account sync, and download history.
  • Location tracking: Discretion in requesting continuous GPS, fine location, or device sensor access.
  • Incident response: Documented vulnerability disclosure (security.txt) and user breach notification plans.
  • Vendor transparency: Disclosure of third-party analytics, hosting, SDKs, and subprocessors.

Unevaluated topics are shown as “Not evaluated” rather than an artificial average score.

Deciding each finding and tracking review progress

Every finding in the review requires a clear decision before the review can be finalized. The interface tracks progress by counting only final decisions:

Include

You decide the finding belongs in the final review. Counts toward decided progress.

Exclude

You decide the finding should be left out of the final review. Counts toward decided progress.

Needs another review

The finding is set aside for another colleague, supervisor, or specialist (note required). Does not count as a final decision and still blocks report finalization.

Example: Reading review progress

If a review has 34 total findings, with 22 included, 6 excluded, 2 flagged for another review, and 4 not yet decided:

  • The progress meter shows 28 of 34 decided (82%) because only Include and Exclude are final decisions (22 + 6 = 28).
  • 6 decisions remain (2 flagged + 4 undecided = 6).
  • The report checklist remains incomplete until all 6 remaining findings are given final Include or Exclude decisions.
  • A note or flag does not count as a final decision.

Review layouts: Split view and List view

The review screen provides two viewing modes depending on your workflow:

Split view (Default for rapid triage)

Presents an index of all findings on the left and full finding details with quotes on the right. Ideal for rapid keyboard triage: use J and K to move through findings, Y to include, N to exclude, and U to jump directly to the next item needing a decision.

List view (Linear document flow)

Displays findings as a continuous vertical document grouped by framework parts. Completed decisions can be collapsed with the “Collapse decided” toggle to focus only on remaining open questions.

Navigating review sections: The Left Side Rail

A persistent navigation rail on the left side of the results workspace keeps your position clear and gives one-click access (or keyboard shortcut) to all eight review sections:

1. Overview (Alt+1)

Review status pulse, high-concern summary, and verification strength index.

2. Findings (Alt+2)

Live badge tracks decided progress (e.g. 28/34, turns green when all are decided).

3. Summary (Alt+3)

AI synthesis based solely on included findings. Shows Draft until reviewed and accepted.

4. Next steps (Alt+4)

Questions ready to email the product team and safe device tests, prioritized by severity.

5. Product (Alt+5)

Direct quotes of every promise the product makes regarding privacy, anonymity, and security.

6. Sources (Alt+6)

All stored pages, search logs, limits, passive scan observations, and source-wide text search.

7. Export (Alt+7)

Readiness checklist, audience format toggle, and download actions. Shows Ready when satisfied.

8. Ask review (Alt+8)

Interactive AI assistant grounded strictly in collected evidence, findings, and safe testing steps.

Tip: Use the collapse button (« / ») at the top of the rail to tuck it away when you want maximum horizontal space for split-view triage.

08

Step by step

A full review, from entering an address to sharing the report.

  1. Start

    Enter the product's website. You can type just example-chat.org. Choose what kind of product it is and how deep web research should go. App store links are optional; the tool finds them if the site links to them.

    Tip: if you paste an App Store link into the website field, it is moved to its own field for you.

  2. Watch it work

    Each stage shows its progress and elapsed time. You can stop at any point; whatever finished is kept. If a stage has a problem, a panel explains it and offers the next step.

  3. Decide each finding

    Read the finding and its quotes, then choose Include or Exclude. If you need a colleague or supervisor to look at it first, choose Needs another review (which requires a short note explaining what to check). A note or flag alone does not count as a final decision. The review defaults to Split view for rapid triage using keyboard shortcuts (J/K to move, Y/N to decide, U for next undecided).

  4. Check the supporting information

    Open any quote to see the exact page the tool stored, with the passage highlighted, who wrote it, when it was read, and every finding that cites it. Or search the text of every source at once.

  5. Write and review the summary

    Once every finding is decided, write the summary. It uses only the findings you included, and every sentence names what it rests on. Accept it and choose your final recommendation: Not ready to recommend (point to survivor-safety resources such as NNEDV Safety Net), Reconsider after company answers and testing on a spare device, or Could be discussed with cautions.

  6. Send the questions

    Next steps gathers every question for the company or product team and every hands-on test on a spare device, most serious first, ready to copy into an email or a test log.

  7. Save and export

    Save the review file (.json) to keep your complete working state; it is your only copy. Choose your export format: the Full review report (technical details, guidance mapping, and evidence citations) or the Survivor-facing summary (plain language without technical jargon for safety planning). Download in Markdown or print to PDF. The report stays marked DRAFT until all findings are decided and the summary is accepted. If findings are modified after the summary is generated, an alert will prompt you to rewrite the summary before final export. Adding a reviewer name is optional and does not block finalization.

  8. Ask the review assistant

    Use the Review Assistant (Alt+8) to interrogate findings, compare company promises against verified evidence, explore device traces, or generate targeted questions for leadership and developers. Every response is strictly grounded in the review's stored sources with direct citation links.

    Privacy reminder: the assistant operates exclusively in local browser memory. Never enter survivor names, stories, or identifying information.

09

Keyboard shortcuts

Triage findings quickly with single keystrokes, and jump across results sections with Alt+1..8. Shortcuts do nothing while you are typing in a note or input.

Finding triage (when a card has focus)

Y
Include in Report (keep finding), then advance to next decision needed
N / X
Exclude Finding (reject, then choose a reason)
F
Needs another review (flag to set aside for a colleague or supervisor)
J / K
Next / previous finding
U
Next decision needed (jump to next undecided or flagged finding)
Enter
Show details of a collapsed finding
?
Show or hide the shortcut list

Section navigation (anywhere in review)

Alt + 1
Jump to Overview section
Alt + 2
Jump to Findings triage section
Alt + 3
Jump to Summary and recommendation section
Alt + 4
Jump to Next Steps (questions and device tests)
Alt + 5
Jump to Product statements and claims
Alt + 6
Jump to Sources, search, and limits
Alt + 7
Jump to Export and download readiness
Alt + 8
Jump to Ask this review assistant

10

What “Not answered by reviewed sources” means

Before you rely on one

  1. Search the sources for the words you would expect to see, like retention or delete.
  2. Check the limits: was the page read to the end? Did it need JavaScript?
  3. Open the research log to see what was searched.
  4. If it still matters, send the company the question. It is already written.

Limits appear with every review

  • 1 page was too long to read to the end Anything the review says is missing may be in the unread part.
  • Nothing citable was found for: independent reviews and press After 9 searches, including broader ones where the first results were thin. That describes the search, not the product.

11

When something goes wrong

Every problem comes with a plain explanation and a next step. Progress that finished is always kept.

Usually a typo, a missing "www.", or a site that has closed. The panel offers to edit the address or look for old copies in the Internet Archive.

12

Staying safe as a reviewer

Do

  • Use a spare device and made-up details for hands-on tests.
  • Keep review files in a private, access-controlled folder.
  • Check “not answered” findings yourself before relying on them.
  • Share reports only after every finding is decided.

Don't

  • Type real survivor names, stories, or locations into any product you test.
  • Share a draft report as if it were final.
  • Read “nothing found” as “nothing wrong.”
  • Test a product's security without the company's permission.

13

Review criteria

10 parts, 40 review questions, criteria version 0.3.0. These criteria make up the survivor-safety review framework.

What the product promisesQuestion the claim3

Survivors change their behavior based on what they believe a feature guarantees. The gap between the promise and the reality is where false reliance comes from.

  1. What promises does the product make about safety, concealment, privacy, encryption, anonymity, or legal value?Answered by: Public sources
  2. Is there independent evidence (testing, audit, credible third-party review) supporting those promises, or only the vendor's own statements?Answered by: Public sources, The company or product team
  3. Does the developer show survivor-safety expertise or partnership with domestic violence organizations?Answered by: Public sources, The company or product team
What happens when it failsQuestion the claim3

A visible failure is inconvenient. A silent failure creates false reliance at the worst possible moment.

  1. Does the product explain behavior with no signal, poor Wi-Fi, location off, Low Power Mode, a locked screen, backgrounded or force-closed app, or after a restart?Answered by: Public sources, The company or product team, Hands-on testing
  2. If an emergency feature (SOS, location share, SMS, email) fails, does the user find out?Answered by: The company or product team, Hands-on testing
  3. Does the product acknowledge that AI answers can be incomplete or wrong, and does that acknowledgment match how the product describes its own abilities?Answered by: Public sources, Hands-on testing
What information it collects or createsFollow the data3

A name is only one way to identify someone. Abuse narratives, locations, children's ages, and court dates can identify a survivor without it.

  1. Beyond names and email, what sensitive information does the product collect or invite: abuse narratives, location, children's information, court details, employer, health, photos, audio, immigration circumstances, device identifiers?Answered by: Public sources, Hands-on testing
  2. Do the device permissions requested match the features? Is location required, or offered only while needed with manual entry as an alternative?Answered by: Public sources, Hands-on testing
  3. Does the product collect only what its features need, with privacy-protective settings on by default?Answered by: Public sources, The company or product team, Hands-on testing
Where the information goesFollow the data3

The company whose logo is on the screen is often one layer of many: chat platforms, AI providers, cloud hosts, analytics, email and SMS vendors, and human administrators.

  1. Which third parties receive user information (hosting, analytics, crash reporting, chat platform, AI model provider, email/SMS)? Are they disclosed?Answered by: Public sources, The company or product team
  2. Do third parties observed loading on the public site match what the privacy policy discloses?Answered by: Public sources
  3. For AI features: which chat platform and model provider process conversations, and do their default retention and owner-access settings apply?Answered by: Public sources, The company or product team
Who can see itFollow the data3

'Encrypted' says data is protected somehow. It does not say who else still holds a key.

  1. If encryption is claimed: encrypted from whom? Who controls the keys, and can the provider decrypt user records?Answered by: Public sources, The company or product team
  2. Can staff, contractors, or human reviewers read user content? Is admin access protected (MFA, role separation, access logging)?Answered by: Public sources, The company or product team
  3. Does the product explain how it responds to law-enforcement or civil legal demands for records?Answered by: Public sources, The company or product team
How long it stays, and what Delete really deletesFollow the data3

A Delete button might remove something from one screen while copies remain in backups, logs, analytics, exports, and vendor systems.

  1. Is there a stated retention period for each kind of data?Answered by: Public sources, The company or product team
  2. When a user presses Delete or requests deletion, where does the information still exist (backups, logs, analytics, exports, staff inboxes, AI provider or chatbot dashboards, synced devices)?Answered by: Public sources, The company or product team
  3. Is there a plan for user data if the product or organization shuts down (notice, export, deletion)?Answered by: Public sources, The company or product team
What traces of use remainFollow the data2

Hidden from the screen is not the same as hidden from the device. Discovery of a safety app can itself be dangerous.

  1. What evidence of use could remain on the device or connected accounts: download/purchase history, installed-app lists, storage use, permission settings, notifications, location or microphone indicators, recent-app views, browser history, cloud backups, synced devices?Answered by: Public sources, Hands-on testing
  2. Does the product tell users which traces its disguise or quick-exit features do not remove?Answered by: Public sources
What is missingNotice what's missing8

What a survivor-facing product never explains is often more revealing than what it says.

  1. Is there a dated privacy policy (and can prior versions be identified)?Answered by: Public sources
  2. Is there a list of vendors or processors?Answered by: Public sources
  3. Is there a security contact or vulnerability disclosure process (for example security.txt)?Answered by: Public sources
  4. Is there a described breach or incident-response process, including user notification?Answered by: Public sources, The company or product team
  5. Has anyone other than the creator reviewed or tested the product?Answered by: Public sources, The company or product team
  6. Is there evidence of ongoing maintenance (update cadence, support contact, who fixes it when platforms or laws change)?Answered by: Public sources
  7. Are plain-language warnings shown at the moment of disclosure, not only in a policy?Answered by: Hands-on testing
  8. Does the product address children's information?Answered by: Public sources
Public signals of security engineeringNotice what's missing6

Standard web security protections help prevent someone from intercepting survivor traffic, altering pages, or stealing records. Only passive, public observations are assessed here.

  1. Does the public site send standard web security protections (such as strict HTTPS, content restrictions, or frame protection to prevent clickjacking)?Answered by: Public sources
  2. Does the site set tracking or analytics cookies on first visit before any choice is offered?Answered by: Public sources
  3. Are private third-party API keys, crisis communication tokens (e.g. Twilio, SendGrid), or administrative cloud credentials exposed in publicly served website code?Answered by: Public sources, The company or product team
  4. Does the application process sensitive operations (such as AI calls or database operations) through a secure server rather than directly from the client browser?Answered by: Public sources, The company or product team, Hands-on testing
  5. Is there evidence of secure-development practices: code review, dependency updates, security testing, a remediation process?Answered by: Public sources, The company or product team
  6. Does the organization's email domain publish protections (SPF and an enforcing DMARC policy) that make it harder for someone to send email pretending to be the service?Answered by: Public sources
How the AI invites disclosureQuestion the claim6

The words around an AI are part of its safety design. Human-like framing can increase disclosure and trust faster than it increases safety.

  1. Does the interface encourage the minimum information necessary and remind users not to include identifying details, especially when inviting more detail?Answered by: Public sources, Hands-on testing
  2. Does the AI present itself as human-like or as having unlimited abilities?Answered by: Public sources, Hands-on testing
  3. If conversations are called anonymous or anonymized: how and when does that happen relative to the chat platform, the model provider, and human review?Answered by: Public sources, The company or product team
  4. For legal or other consequential answers, does the tool cite specific primary sources that a user could check?Answered by: Hands-on testing
  5. If the site embeds a third-party chat tool, do its settings observed in page code limit misuse and exposure (file uploads, rate limiting, allowed domains, a linked privacy policy, lead-collection forms)?Answered by: Public sources, The company or product team
  6. Does the product clearly say it does not provide legal advice and point users to qualified human help (an advocate, attorney, or hotline)?Answered by: Public sources, Hands-on testing

14

Questions

Using the tool

How long does a review take?

Usually about 2 minutes for Standard depth, or about 8 minutes for Extended depth (which adds security claims checks and broader searches).

Can I stop and come back later?

Yes. Press Stop, then Continue to pick up where it left off, or save the review file and use “Open a saved review” later. Nothing is kept on the server, so the file is your only copy.

What if the product has no website?

Enter the company's website and add the App Store or Google Play link. App store listings can be read even when a website can't.

The site blocked the tool. Now what?

Some sites block automated readers. Add the app store link and try again, or review the site by hand using the framework questions.

Trusting the results

Why does it never say a product is safe?

Public information can show what a product claims and what it leaves out, but it cannot prove a product is safe. The decision belongs to a person who knows the survivors it would serve.

Can the AI make things up?

It can draft wrong summaries, which is why every quote is checked word for word against the stored pages, unsupported findings are downgraded, and you decide whether to include or exclude each one.

How do I check a finding myself?

Open any quote to see the full stored page with the passage highlighted, or open the live page at that passage. Use the source search to look for words the finding says are missing.

Why was a finding marked “Company-provided information only”?

When the only available sources are the product's own statements, or an outside service provider describing its own platform, the status is capped. Company statements have not been independently confirmed.

Reports and privacy

What is the difference between the Technical Report and the Survivor Handout?

The Technical Report (detailed Markdown or PDF) includes every finding, full quotes, evidence hashes, and guidance mapping for agency files or developer discussions. The Survivor Safety Handout is an autonomy-supportive, plain-language summary designed for safety planning conversations directly with survivors, focusing on what was found and practical cautions.

When can I share a report?

When every part of the framework was checked, all findings have final decisions (included or excluded), and the summary is accepted (or deliberately left out). A finding flagged for another review still blocks finalization. Until then the report is marked DRAFT.

Is anything stored?

No. The pages and findings live in your browser until you save the review file. The server keeps nothing.

Where should I keep review files?

Somewhere private and access-controlled, like any other sensitive work document. They contain the evidence and your notes.

15

Glossary

45 of 45 terms

Audience export profile
The toggle on the Export screen that switches between the technical report (for advocates, leadership, and developers) and the survivor-facing safety handout (for direct, non-technical safety planning conversations).
Basis
The findings or promises a summary sentence rests on. Code checks every basis; sentences without one are removed or flagged.
Company-provided information only
The only available answer comes from a company describing its own product or service. It has not been independently checked.
Context only
Useful context for understanding the product, but this finding does not identify a specific survivor-safety concern on its own.
Depth check
The rule that sends a thin research question back for broader searches once before “nothing found” is accepted.
Draft report
A report with undecided findings, findings flagged for another review, or an unreviewed summary. Every page says DRAFT.
Evidence clarity by safety topic
Topic-level scores measuring how clearly public evidence resolves questions across five safety domains: Data deletion, Anonymity and traces, Location tracking, Incident response, and Vendor transparency.
Evidence drawer
A modal dialog that opens when any cited passage is selected, displaying the full stored source page with passage highlighting, SHA-256 fingerprint, copy tools, and a list of all findings and claims citing that source.
Final decision
A finding has a final decision when the reviewer chooses Include or Exclude. Setting a finding aside for another review or writing a note does not count as a final decision.
Finding
A finding is one answer, concern, or unresolved question from the review.
Hidden-by-default text
Text in a page's code that is not shown when it loads, such as a collapsed FAQ answer. Kept separate and labeled.
High potential impact
If this finding is accurate, it could materially affect a survivor's safety, privacy, ability to remain undiscovered, access to help, records, evidence, or ability to make an informed choice.
Lower potential impact
This issue may still matter, but its likely consequences are more limited, easier to explain, or less directly connected to immediate survivor safety than higher-impact findings.
Medium potential impact
If this finding is accurate, it could meaningfully affect how an advocate or survivor decides whether, when, or how to use the product, but the likely consequences are less severe or more limited than a high-impact finding.
Needs a safe test on a spare device
Public information cannot answer this question. It needs to be checked on a spare device using made-up information, never real survivor information. (Technical status: needs_testing; routed to device testing steps).
Needs an answer from the company
Public information is not enough to answer this question. The company or product team would need to explain how this works. (Technical status: needs_developer; routed to the developer questionnaire).
Needs another review
A finding set aside for a colleague, supervisor, or another advocate to check. It requires an explanatory note and still requires a final Include or Exclude decision before the review can be finalized.
Not answered by reviewed sources
The sources reviewed did not contain enough information to answer this question. This does not mean the feature or safeguard is missing from the product.
Not yet decided
A finding that has not yet been given a final Include or Exclude decision or set aside for another review.
One source raises a conflicting concern
One reviewed source challenges the apparent answer or raises information that does not fit with it. (Technical status: questioned; grouped under sources disagree).
Operative clause highlighting
Visual emphasis applied to critical safety terms and conditions in quoted evidence, matching words directly relevant to the review criteria.
Out-of-date summary
A safeguard triggered when findings are changed after the summary was drafted. The report remains marked DRAFT until the summary is rewritten to reflect the updated findings.
Potential impact
Potential impact describes how much the issue could matter for survivor safety if the finding is accurate or the described situation occurs. It does not show how likely the issue is, how certain the review is, or whether the product as a whole is safe or unsafe.
Promise
Something the product says about safety, privacy, encryption, anonymity, or legal value, quoted exactly.
Public information answers this
The reviewed public information directly answers this question. This does not mean the answer is favorable, that the safeguard exists, or that the product is safe.
Public verification strength
A heuristic index measuring how strongly findings can be checked against independent observations and official records (Strong, Mixed, or Limited), rather than company assertions alone.
Public website code check
An advanced inspection of publicly delivered JavaScript bundles and front-end scripts for exposed private keys, direct browser connections to cloud AI services, and unencrypted local browser storage.
Rapid triage split view
A dual-pane review layout featuring a quick-navigation index of findings on the left and full finding details with one-key decision buttons on the right.
Read in full
A page the research opened and stored completely, as opposed to a short search excerpt.
Recommendation options
The three reviewer conclusions: Not ready to recommend (point to survivor-safety resources such as NNEDV's Safety Net project), Reconsider after company answers and testing on a spare device, or Could be discussed with cautions.
Research question
One line of web research, such as incidents and regulators, with its own search budget.
Results side rail
A persistent navigation rail on the left side of the results workspace providing instant jumping between the eight review sections (Overview, Findings, Summary, Next Steps, Product, Sources, Export, Ask review), live progress counters, and Alt+1 through Alt+8 keyboard shortcuts.
Review assistant
An interactive AI assistant in the review workspace (Alt+8) that answers questions grounded strictly in the findings, claims, notes, and evidence collected during the current review session. It never stores queries or communicates survivor identities.
Review criteria
The survivor-safety questions every review asks. These criteria make up the review framework.
Review file
The saved file that holds every source, finding, and decision. Your only copy.
Robots.txt
A site's request to automated tools about which pages to skip. The tool honors it by default, but allows reviewers to manually override and read specific skipped pages or the homepage on demand.
Session recording
A service that can record what visitors type and click on a website.
Smart question starters
Preset categorized queries in the review assistant (Safety & Traces, Vendor vs Reality, Hands-On Testing) tuned to the specific findings identified in the assessment.
Source integrity check
A code computed from a page's exact text when retrieved, used to confirm the text has not changed. (Technical detail: SHA-256 fingerprint).
Sources disagree
Different sources reviewed directly contradict each other or raise conflicting concerns about this issue.
Supporting information
In this review, supporting information can include public webpages, records, website observations, and outside sources used to answer review questions. It is not a legal finding or forensic evidence.
Survivor safety handout
An autonomy-supportive plain-language export designed for direct safety planning conversations with survivors without technical jargon.
Website observation
The review recorded information a normal visitor's browser receives from the website, without logging in or probing private systems. (Technical term: passive scan).
Where the supporting information came from
Who produced or directly observed the supporting information across six recognized categories: observed on the public website, independent outside sources, product/company statements, documentation from services the product uses, historical copies from the Internet Archive, or publisher-reported app store declarations. Different source types can support different kinds of conclusions. (Technical term: provenance).
Withheld passage
Text that seemed aimed at AI reviewers rather than people. Removed from the supporting information and listed for you.

Grounded in published guidance

Examples on this page use Example Chat, a fictional product. Print this page for a training handout.