Domain Atlas / Content moderation & editorial AI
StopNCII & Take It Down
StopNCII.org (operated by the Revenge Porn Helpline within the UK charity SWGfL, developed with Meta, launched December 2021) and Take It Down (operated by the US National Center for Missing & Exploited Children, launched February 2023) run one on-device hash-removal mechanism in two configurations: the person who holds the material generates a hash on their own device, only the hash leaves the device, the original is never uploaded or stored, third-party submission is refused and eligibility is self-attested, and participating platforms match the hash against uploads on public or unencrypted surfaces, reviewing any match under their own policies. StopNCII states its algorithms as PDQ and PhotoDNA for photos and MD5 for videos; independent researchers verified by inspecting the Take It Down web client that it runs PDQ. The operators' own volume reports — advocacy-tier counts of reporting behaviour, never incidence — were 2 million images protected across more than 785,000 cases by November 25, 2025 on the StopNCII side (a reported 97 percent increase over 2024, 17 industry partners) and 130,000+ submissions covering 273,000+ images and videos in 2025 on the Take It Down side, up from 83,000+ submissions in 2024. As fetched 2026-08-27 the two partner rosters overlap and diverge (YouTube on the minor index only, X on the adult index only, Discord on neither), encrypted surfaces are outside both by design, and Google announced on September 17, 2025 that it will use StopNCII hashes in Search — an announcement scoped to Search results, with Google absent from the StopNCII partners page as fetched the same day.[6]
What happened
StopNCII.org, launched in December 2021 by the Revenge Porn Helpline within the UK charity SWGfL and developed with Meta, and Take It Down, launched in February 2023 by the US National Center for Missing & Exploited Children, are two named configurations of one mechanism — and this case file is about the pair, because neither alone supports a derivable picture. The mechanism: an adult who holds intimate material of themselves (StopNCII), or a person who was under 18 when the material was made (Take It Down), opens a web client that computes a perceptual hash of the material on their own device. Only the hash leaves the device; the original is never uploaded, never stored, and never seen by any operator. Third-party submission is refused and eligibility is self-attested. The hash enters the operator's bank and is shared with participating platforms, whose matching systems — self-hosted or supplied by vendors such as Thorn's Safer — compare it against uploads on public or unencrypted surfaces. A match surfaces the uploaded content to the platform's own trust-and-safety review, which decides under the platform's own policy whether to act: a hash match obliges nobody, and every removal is a human platform decision. StopNCII states its algorithms plainly — the PDQ perceptual-hash tool and PhotoDNA for photos, MD5 for videos — and independent researchers verified by inspecting Take It Down's web client that it runs PDQ. The two configurations then diverge, by design, into a natural experiment on the victim channel: StopNCII gives the reporter a case number, a PIN and a status page (updates can take 3 to 5 days) and services whole-case withdrawals against credentials the operator does not store and cannot reset; Take It Down is anonymous by construction, with no status channel, no notification of matches, and no withdrawal mechanism at all. StopNCII states that hashes persist after a reporter deletes the image, are shared with new partners as they join, and that participating companies "reserve the right to continue enforcing their policies once they've acquired knowledge of the hash" — so an entry's reach grows after submission, and a withdrawal, where one exists, retracts the bank's copy but not the partners'.
The scale and the gaps are both documented, and the figures are the operators' own. SWGfL reported on November 25, 2025 that StopNCII hashes were protecting 2 million images across more than 785,000 cases — a 97 percent increase over 2024 — with 17 industry partners; NCMEC's dashboard reports Take It Down submissions rising from 83,000+ (166,000+ hashes) in 2024 to 130,000+ covering 273,000+ images and videos in 2025. These are advocacy-tier counts of reporting behaviour, never incidence, and no operator in this class publishes an audited error rate for its deployed system. Coverage is a patchwork the person reporting cannot see around: as of August 27, 2026, YouTube matches the Take It Down list but not StopNCII's, X matches StopNCII's but not Take It Down's, Discord matches neither, and encrypted messaging surfaces are outside both by design. Google announced on September 17, 2025 that it would begin using StopNCII hashes to proactively remove non-consensual intimate imagery from Search results — an announcement scoped to Search, rolling out over months, and Google did not appear on the StopNCII partners page as fetched the same day the rosters above were. The operators also document the match-error surface themselves: cropped, filtered or clipped material may defeat the original hash, video and image hashes are different formats, and the index reaches participating platforms only. On the adversarial side, an evaluation presented at the USENIX Security conference in 2023 demonstrated efficient targeted second-preimage and detection-avoidance attacks against PhotoDNA and PDQ, concluding existing perceptual hash functions are likely insufficiently robust for adversarial settings. When this system fails, nobody is falsely accused: every documented failure is a protection gap — a non-participating platform, an encrypted surface, a re-encoded copy, a partner copy a withdrawal cannot reach, a status question the anonymous configuration can never answer.
The governance event of the record has an unusually clean shape. In 2023-2024, researchers at Royal Holloway and partner institutions reconstructed recognizable pre-images — hair colour and length, face shape, other facial features, some background — from PDQ, PhotoDNA, NeuralHash and aHash hashes, using an off-the-shelf conditional image-to-image generative network trained on 1,000 public celebrity-face images on 2015-era consumer hardware, with mean perceptual similarity of 60.10 percent for PDQ and 74.04 percent for PhotoDNA. The measurements were made on a public celebrity-face benchmark, never on any reporter's material; the authors concluded the hashes should be treated as sensitive in the same way as the original images. The same team quoted Take It Down's FAQ — "No, images and videos cannot be reverse engineered or created from the hash values shared with NCMEC." — reported that answer to be wrong, wrote to the operator twice between August and December 2023, received no reply, and recorded that the website did not change. The sentence was still on the FAQ page on August 27, 2026. Meanwhile the voluntary index is being pulled into a mandatory legal regime on both sides of the Atlantic. The US TAKE IT DOWN Act's notice-and-removal duty took effect May 19, 2026: covered platforms must remove reported non-consensual intimate imagery and known identical copies within 48 hours of a valid request, enforced by the Federal Trade Commission (FTC), with compliance letters sent to fifteen major companies — including Alphabet, Discord and X, companies that do not all participate in either voluntary hash index. The UK made NCII sharing a priority offence under the Online Safety Act in 2024, brought a creation offence into force on February 6, 2026, expects Ofcom's hash-matching code measures in force from summer 2026, and has announced a 48-hour takedown amendment with penalties up to 10 percent of worldwide turnover. Separately, a University of Michigan audit study (ACM CSCW 2026) reported 50 synthetic-persona deepfake images through X's own victim-facing channels: reports filed under the Digital Millennium Copyright Act (DMCA) achieved 100 percent removal within about 25 hours, while reports through the non-consensual-nudity mechanism achieved zero removals over 21 days — a study of the platform's report flow, not of hash matching, and independent evidence that a platform's participation in a hash program can coexist with a non-functioning victim-facing report channel.
The sociotechnical reading
The defining fact of this deployment class is that its central protection and its central weakness are the same design decision. Hashing on the victim's device means the material never leaves their control — the strongest data-minimization posture in this atlas, and the reason a person in the worst week of their life can use the service at all. It also means the index can never be verified against anything by anyone: no analyst assesses a submission in either named configuration, eligibility is self-attested, and the reference material an entry would be checked against exists nowhere any operator can reach. Verification of this artifact is possible only where a platform already holds the material — exactly where the exposure the design exists to prevent has already occurred. The Lab network draws that as structure rather than prose: the submission write runs at full strength with nothing but a mechanical validity screen in front of it, the operator's bank carries no inbound check at all, and the only substantive check anywhere in the system is the platform's own policy review of a match, in a different organisation from the index. The pairing is what makes any of this measurable. Two operators run the same mechanism with opposite victim-channel designs — case, PIN, status and withdrawal on one side; anonymity, no status, no notification, no withdrawal on the other — so each is the other's controlled contrast, and the propagation facts on the record are StopNCII's own: hashes outliving the material, partner copies beyond a withdrawal's reach, rosters that grow and churn. A neighbouring deployment shows what the missing gate looks like when the content class permits one: the Internet Watch Foundation's hotline — a child-sexual-abuse-material service, a different content class and no part of this pair — has a trained analyst assess every report against published legal guidelines before anything is listed, which is the assessment-before-listing step the on-device design forecloses by construction.
The record's second lesson is about what happens when the only outside check has no reach. The independent security evaluation is the strongest examination this artifact has ever received, performed without operator cooperation through the public web client, and it produced a specific, reproducible, published contradiction of the operator's printed privacy reassurance. The disclosure loop then failed completely and measurably: two letters, no reply, no site change, and the contradicted sentence still live three years later — while the operators' volume figures doubled and lawmakers on two continents began converting the voluntary mechanism into legally load-bearing infrastructure, without ever adding an audit surface. The honest boundaries matter as much as the findings. The reconstruction magnitudes describe the invertibility of the hash class on a public benchmark, not any individual's exposure. The volume figures are operator self-reports and count reporting behaviour, not abuse. The Michigan audit tested a platform's report channel, not the hash pipeline, and it is used here only to keep those two channels separate. The statutes mandate answering removal requests; they do not mandate joining an index, and nothing about them audits one. And the failure modes of this protective system are gaps, not accusations: the map's open pathways are the places where a person who did everything right remains unprotected — and, in the anonymous configuration, will never know either way.
The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library.