Skip to main content

Trust, Safety & Integrity

Built for UK regulatory posture from day one.

The legal and governance infrastructure here was built before the feature set. A platform holding operational records needs it, and so do the communities that use one.

Live capabilityBuilt for UK GDPRBuilt to support the Online Safety ActICO registered — ZC184449

The Compliance Backbone

Nine governance and safety capabilities are available in the current build.

Each item below is available in the current build. Where hardening work is ongoing, the card says so.

UK GDPR

DSAR Case-Management Workflow

Article 15 (access) and Article 17 (erasure) requests are handled through a structured case-management workflow. Statutory one-month deadlines are tracked automatically. Identity verification and Director sign-off on erasure are enforced.

Core workflow live. Object-storage hardening in progress — some attachment handling is still being strengthened.

Integrity

Dedicated Audit Trails

Sensitive platform and operational actions — record access, searches, support sessions, staff bypasses — are written to dedicated audit trails. Selected evidentiary records carry database-level immutability controls (DB triggers); coverage is being expanded and verified across the remaining modules.

Safety

Mandatory Escalation Routing

Reports involving CSAM, terrorism, credible threats, or court orders are automatically routed to the platform Trust, Safety & Integrity queue. Community Directors and staff cannot suppress, close, or redirect these reports — the pipeline is enforced at platform level.

Governance

Sanction Ladders & Appeals

Two parallel five-rung sanction ladders — one for platform users, one for communities. Each rung has documented authority, a mandatory cooling-off period, and a formal appeal window. No one is removed or suspended without a documented trail.

Authority

Sign-Off Authority & Director Break-Glass

Consequential actions are gated by the role registry — only the correct authority can take them. A Director break-glass mechanism exists for genuine emergencies; every invocation is logged with a mandatory reason (minimum 50 characters), timestamped and irrevocable.

Records

Compliance, Risk & Data Registers

A live breach register (Article 33/34 notification timelines tracked), data retention schedule, sub-processor register, ICO correspondence log, and DPIA register — each maintained as a structured record in the platform.

Regulation

Online Safety Act Reporting

A first-party "Report a Problem" tool surfaces in every community. Reports are routed into the mandatory escalation pipeline for triage, with full audit trail. The platform is structured for OSA obligations — regulated services can meet their transparency requirements.

Age

Age Gating

A minimum age of 13 is required to hold a platform account, in line with UK data protection law (GDPR Article 8 and UK GDPR equivalent). Subscriptions require an age declaration of 18 or over. The age gate is enforced during mandatory onboarding — before ordinary platform access — and again at the subscribe flow.

Isolation

Multi-Tenant Data Isolation

Every tenant-scoped query filters on the community's own tenant ID, and automated cross-tenant test suites run on every merge. Independent security reviews (May–July 2026) found no cross-tenant data leak.

Application-level scoping is the live isolation layer. Database-level row-level security is deployed as a staged backstop and is still being hardened before it is enforced independently of the application.

The User Model

Platform Users and Community Directors

The platform has two distinct account types with separate rights, obligations, and data-protection roles.

PU

Platform User

Free account

Anyone who creates an account on OpsCentre via Discord OAuth. A Platform User can join communities and participate in roleplay. They have no billing relationship with OpsCentre, but they hold a platform account with the full protections of the Privacy Policy and Terms of Service.

  • Self-serve DSAR (access & erasure)
  • Sanction appeal rights (user ladder)
  • Audit trail of all actions against their account
  • Request account closure at any time

Platform-Staff Accountability

What platform staff can and cannot do in your community

Trust runs in both directions. These are the governance rules that apply to OpsCentre staff when handling a community.

Session audit trail

Platform-staff access runs through recorded support sessions — which staff member, which community, when, and under which session type. Record access and searches performed inside RMS and LEDS during a session are written to those modules' audit trails.

Time-bounded support sessions

Support sessions auto-expire after one hour, so access does not persist indefinitely. Platform Management can extend a running session; every extension is recorded — who extended it, and when.

Consent-first access

Routine support access starts with your community: staff can only open a community-requested session against an open request raised by your own admins, and sessions are visible to the community by default. A narrow, Director-of-OpsCentre- authorised exception exists for safeguarding and legal investigations where advance visibility would defeat the purpose; it is logged at platform level.

Withdrawal and appeal

Your admins can cancel an open support-access request at any time before it is actioned, and can ask platform Management to end a running session. Any consequential action taken by platform staff is subject to the same appeal and review process as any other sanction.

Questions about data or compliance?

Contact the Data Protection team at [email protected]. We respond without undue delay and at the latest within one month (UK GDPR Art. 12). For Trust, Safety & Integrity matters, use [email protected].