Online harms rarely remain confined to one surface.
A harmful interaction may begin in a public community, move into private messaging, continue on another platform, and eventually involve a payment service or marketplace. Each organization sees only part of the trajectory. Important context remains fragmented across different tools, policies, and data models.
The industry does not simply need more alerts. It needs a responsible way to connect the signals that already exist.
Turnkeeper's long-term goal is to help establish shared technical standards and governance policies for exchanging safety intelligence, reviewing it consistently, and preparing lawful, human-authorized escalations when appropriate.
From Disconnected Signals to Reconstructable Cases
Platforms receive safety signals from many sources:
- User reports
- Internal detection systems
- Open-source tools such as Osprey
- Specialized safety classifiers
- Account and behavioral systems
- Trusted external programs
- Human investigators
These systems often describe similar events in incompatible ways. They may use different confidence levels, evidence requirements, identifiers, retention periods, and policy categories.
That fragmentation makes collaboration difficult. It can also make safety decisions harder to explain, reproduce, correct, or appeal.
Turnkeeper aims to help create a common language for transforming bounded signals into reconstructable cases. That language should preserve where information came from, what it means, how certain it is, and what limitations apply to its use.
A signal should remain a signal. It should not become an accusation simply because it crossed organizational boundaries.
Standards and Policy Must Develop Together
Technical interoperability alone is not enough.
A specification can define how systems exchange information, but policy must determine whether that exchange is legitimate and responsible. The same infrastructure that helps platforms identify serious harm could also produce privacy violations, discriminatory outcomes, excessive monitoring, or decontextualized accusations if it lacks strong governance.
That is why we believe any industry standard must address five connected layers.
Safety Signals
A shared signal format should describe a bounded observation and include:
- Signal type and applicable harm category
- Source and detector provenance
- Confidence and evidence tier
- Relevant time boundaries
- Permitted purpose
- Expiration and retention requirements
- Opaque references to supporting evidence
- Correction and revocation status
Raw conversations, media, legal identities, and other sensitive material should remain within the originating platform whenever possible.
Reconstructable Cases
Individual signals rarely tell the whole story. A case standard should help authorized reviewers understand:
- What was directly observed
- What was inferred
- Which signals corroborate one another
- What counterevidence exists
- Which relationships remain uncertain
- What information is missing
- Which policy and system versions were applied
This separation is essential. Observations, machine inferences, reviewer conclusions, and platform actions should remain distinct throughout the life of a case.
Human Review
Shared information should support investigation, not replace it.
A review standard should define the qualifications and authorization required for different case types, when a second reviewer is necessary, how disagreement is recorded, and what rationale must accompany a conclusion.
Receiving platforms must independently evaluate shared signals under their own policies. No organization's decision should automatically become another organization's enforcement action.
Escalation and Reporting
Some cases may eventually require escalation to a hotline, regulator, law-enforcement agency, or another legally authorized recipient.
Turnkeeper's goal is not to decide that a person committed a crime or determine whether a platform has a legal reporting obligation. Those judgments belong to the responsible organization, trained specialists, and qualified counsel.
The standard can instead define how an authorized organization prepares a complete and accountable handoff:
- Applicable jurisdiction and reporting category
- Required evidence and source provenance
- Reviewer and legal authorization
- Chain-of-custody information
- Supporting attachments
- Submission status and receipt
- Corrections or supplemental information
Turnkeeper should help make an authorized report complete and reconstructable. It should not make the reporting decision itself.
Network Governance
Cross-platform safety infrastructure requires more than APIs.
A governed network needs participant vetting, minimum evidence requirements, purpose limitations, access controls, auditing, misuse detection, correction procedures, and meaningful consequences for improper sharing.
It must also provide redress when signals are wrong, outdated, misleading, or matched to the wrong person or account.
What Turnkeeper Will Not Build
We do not want to create an opaque industry blacklist.
Turnkeeper will not treat shared signals as definitive proof, assign universal danger scores, or allow unreviewed information to trigger automatic punishment.
We will not assume that every platform shares the same policies or legal obligations. We will not collapse detection, adjudication, and action into a single automated decision.
Every participating organization must retain authority over its own users, policies, investigations, and actions.
Building on Existing Work
We are not starting from an empty field.
Programs such as the Tech Coalition's Lantern demonstrate the value of responsible cross-platform signal sharing. Lantern also establishes an important principle: participating organizations independently review signals and determine appropriate action under their own policies and legal obligations.
Open-source projects such as ROOST's Osprey are making powerful investigation infrastructure available to more safety teams.
Turnkeeper's goal is to help these systems, and the many proprietary systems already used by platforms, communicate through a shared and accountable framework.
How We Intend to Contribute
We plan to approach standardization as an open, collaborative process.
Our initial work will focus on:
- Publishing versioned specifications for safety signals, findings, review records, and authorized escalation packages
- Building reference adapters for open-source and first-party safety systems
- Testing the specifications through narrowly scoped design-partner pilots
- Establishing privacy, human-rights, security, and redress requirements before enabling cross-platform exchange
- Working with practitioners, survivors, safety organizations, civil-society groups, legal experts, and platform operators
- Creating conformance tests so implementations can demonstrate that they preserve provenance and enforce the standard's safeguards
- Reporting what we learn, including failures, false positives, disagreements, and limitations
The technical specification should be open. Trust cannot depend on a protocol that participants are unable to inspect.
Turnkeeper can provide managed infrastructure, operational controls, auditing, and support for organizations that need to use the standard safely in production.
Where This Work Stands Today
Turnkeeper Ward is available only through a private pilot. It currently helps participating platforms connect privacy-minimized signals, reconstruct patterns over time, support specialist review, and keep downstream actions under customer control.
Live cross-platform exchange feeds, cross-organization actor graphs, and any official Lantern or ThreatExchange compatibility relationship remain Roadmap. They must not move into production simply because the matching technology is feasible.
We intend to develop this direction with qualified design partners, independent safety expertise, privacy and human-rights review, and measurable stop conditions.
The Goal
We want online platforms to see enough of the wider safety picture to act responsibly without centralizing raw user data or transferring decision authority to an external system.
That means connecting signals while preserving context. Reconstructing cases without overstating certainty. Supporting collaboration without enabling indiscriminate surveillance. Preparing lawful escalations without automating accusations.
Our mission is to standardize how platforms exchange safety intelligence and turn it into accountable, human-reviewed action.
The difficult work will be ensuring that this standard protects the people it is intended to serve. We believe that work must begin with governance, transparency, and shared responsibility, not after the network has already been built.
Join the Work
If you operate a platform, build safety infrastructure, conduct specialist review, represent affected communities, or work on privacy and human-rights safeguards, we want to learn from you.
Explore Turnkeeper Ward:
Request a design-partner conversation:
