Online Safeguarding & Cyber Agency
Safeguarding, cyber safety, records and OSINT support
Logged in as:

HOME

The Online Safeguarding & Cyber Agency (OSCA) is a civilian-led digital safeguarding and online harm prevention initiative. OSCA exists to help identify, document, review, and refer concerns involving online abuse, cyber-enabled harm, exploitation, harassment, impersonation, threats, doxxing, and behaviour that may place individuals, particularly young or vulnerable people, at risk.

OSCA does not replace the police, emergency services, social services, or any statutory safeguarding body. Our role is to provide a structured, responsible, and confidential route for concerns to be raised, assessed, recorded, and, where appropriate, referred to the correct external organisation or authority.

OSCA uses lawful open-source intelligence, structured reporting tools, and internal review processes to assess digital safeguarding concerns. We only consider information that is publicly accessible, lawfully obtainable, and relevant to the concern being reviewed. OSCA does not engage in hacking, account compromise, entrapment, covert surveillance, or any activity requiring legal authority.

Reports submitted to OSCA are reviewed by authorised personnel and handled in accordance with our privacy, safeguarding, and data handling standards. Where a report indicates a credible risk, suspected criminal activity, or a safeguarding concern involving a minor or vulnerable person, OSCA may signpost, escalate, or refer the matter to appropriate external agencies.

Our purpose is to support safer online spaces by preserving relevant information, reducing harm, and helping concerns reach the correct channels. If you believe you or someone else is at immediate risk of harm, you should contact emergency services directly.

ABOUT OSCA

The Online Safeguarding & Cyber Agency was created to support responsible digital safeguarding, online harm awareness, and evidence preservation. OSCA focuses on concerns where online behaviour may create risk, distress, exploitation, reputational harm, or safeguarding vulnerability.

Although OSCA uses the word “Agency” in its name, OSCA is not a government agency, police force, regulator, or statutory authority. OSCA is a civilian-led organisation that operates within strict boundaries and does not claim legal powers beyond those available to ordinary members of the public.

OSCA’s work is based on lawful observation, structured reporting, internal review, and appropriate referral. We aim to ensure that concerns are not ignored, exaggerated, mishandled, or escalated without proper assessment.

OSCA does not confront suspects, conduct arrests, issue legal orders, access private systems, or interfere with official investigations. Where a matter appears to require statutory intervention, OSCA will encourage or direct reporting to the appropriate authority.

Our approach is built around professionalism, confidentiality, safeguarding awareness, data minimisation, and respect for lawful process.

REPORTING

If you believe you have witnessed online harm, inappropriate behaviour, cyber-enabled abuse, exploitation, harassment, impersonation, doxxing, threats, or activity that places an individual at risk, you may submit a report to OSCA.

OSCA reviews submitted information to assess whether there may be a safeguarding concern, legal risk, or ongoing threat. Where appropriate, OSCA may preserve relevant details, provide signposting, or refer the matter to a recognised external agency, safeguarding body, platform safety team, or law enforcement route.

When submitting a report, you should provide clear, factual, and relevant information. This may include usernames, profile links, public posts, screenshots, dates, times, platform names, and a short explanation of the concern. Digital evidence should remain unaltered wherever possible to preserve accuracy and context.

OSCA uses lawful open-source intelligence methods to verify publicly available information connected to reports. We do not access private accounts, bypass security controls, use compromised credentials, obtain leaked private data, or perform intrusive monitoring.

Reports submitted maliciously, fraudulently, or with knowingly false information may be rejected. Where a false report appears to place another person at risk, OSCA may take further action, including restricting access to OSCA services or referring the matter where appropriate.

Emergency situations, immediate threats to life, active violence, or urgent welfare concerns should be reported directly to emergency services.

SAFEGUARDING AND CSAM

OSCA treats safeguarding concerns involving children, young people, and vulnerable individuals with elevated priority. Any report suggesting grooming, exploitation, coercion, blackmail, sexual abuse, or serious risk may be escalated more urgently than a general online harm report.

If a report indicates the possible existence of Child Sexual Abuse Material, OSCA will not request, obtain, store, download, analyse, redistribute, or review that material. Members of the public must not send illegal material to OSCA.

OSCA’s involvement in such matters is limited to recording non-illegal contextual information, such as usernames, public profile links, platform names, timestamps, report references, and other lawful details that may assist appropriate reporting routes.

Where appropriate, OSCA may direct the reporter to recognised child protection, platform, law enforcement, or online safety reporting channels. OSCA does not independently investigate illegal content and does not replace the responsibility of law enforcement or authorised bodies.

Any concern involving immediate danger to a child or young person should be reported directly to emergency services or the relevant statutory safeguarding authority.

OPERATION WOLVERINE

Operation Wolverine is OSCA’s structured online safeguarding and digital risk review framework. It is designed to support the assessment of serious online concerns where there may be repeated harmful behaviour, coordinated harassment, exploitation, impersonation, or risk to vulnerable individuals.

Operation Wolverine does not grant OSCA investigators any special legal powers. All work under this framework must remain lawful, proportionate, non-intrusive, and limited to information that can be accessed legally.

Cases reviewed under Operation Wolverine may involve evidence preservation, open-source verification, risk classification, internal safeguarding review, and referral recommendations. OSCA does not confront individuals, conduct sting operations, impersonate officials, or interfere with live police matters.

The purpose of Operation Wolverine is to ensure that serious concerns are handled consistently, responsibly, and with appropriate oversight.

PENAL CODES AND LEGISLATION REFERENCES

OSCA may use legal references, offence categories, penal codes, Acts, sections, or legislation notes to help classify reports and understand the possible nature of an alleged offence.

These references are used for internal assessment, case organisation, and referral context only. OSCA does not provide legal advice, determine guilt, issue charges, decide sentencing, or make findings of criminal liability.

Where UK matters are assessed, OSCA may refer to UK legislation, including Acts and sections, to describe the possible legal context of a concern. Where non-UK matters are assessed, references may depend on the relevant country, state, or jurisdiction.

Any legal reference used by OSCA should be treated as a preliminary classification, not a legal conclusion.

CRISIS AVERSION PROGRAMME

The OSCA Crisis Aversion Programme exists to provide support, listening, and signposting for individuals who may be experiencing distress, online pressure, harassment, crisis, or emotional vulnerability.

The programme is not an emergency service, medical service, therapy provider, or replacement for professional mental health care. Its purpose is to help individuals identify safer next steps and connect with appropriate support organisations.

Personnel working within this programme must receive appropriate training and must act within their role boundaries. They must not present themselves as clinicians, therapists, emergency responders, or statutory safeguarding professionals unless they hold that role separately outside OSCA.

If you or someone you know needs to talk to someone, you can call Samaritans free on 116 123. In the UK, you can also text SHOUT to 85258 for free, confidential crisis text support.

If there is an immediate risk to life, serious injury, or urgent danger, contact emergency services immediately.

TERMS OF SERVICE

By using OSCA services, you acknowledge that OSCA is a civilian-led safeguarding and online harm prevention organisation. OSCA is not a police force, government body, regulator, emergency service, or statutory safeguarding authority.

OSCA may allow reports to be submitted anonymously. However, there may be circumstances where further information is required to clarify a concern, support safeguarding action, or comply with legal obligations.

OSCA does not guarantee that any report will result in action, investigation, referral, platform removal, police involvement, or any specific outcome. Each report is assessed based on the information provided, apparent risk, credibility, relevance, and OSCA’s internal safeguarding criteria.

OSCA reserves the right to close, reject, or discontinue a case where the information provided does not indicate a credible safeguarding concern, legal risk, or ongoing threat.

OSCA may review publicly accessible online information where there is a credible safeguarding concern, even if a formal report has not been submitted. Any such review must remain lawful, proportionate, non-intrusive, and limited to information available through legitimate public access.

OSCA will not assist, facilitate, encourage, or endorse harassment, retaliation, doxxing, extortion, hacking, malware deployment, unauthorised access, RAT usage, account compromise, impersonation, threats, intimidation, or any conduct intended to cause unlawful harm.

Users must not submit illegal material to OSCA. This includes, but is not limited to, Child Sexual Abuse Material, stolen private data, malware, unlawfully obtained credentials, or content that would be illegal to possess, distribute, or access.

OSCA may restrict or remove access to its services where a user abuses reporting tools, submits false information, attempts to misuse OSCA systems, threatens staff, or acts in a way that creates risk to others.

Investigator Terms

Individuals seeking OSCA investigator status may be required to verify their identity before being granted access to OSCA systems.

Investigators must conduct themselves professionally, lawfully, and respectfully when representing OSCA online or offline.

Investigators must not impersonate police officers, government officials, emergency personnel, social workers, platform employees, or any other official role.

Investigators must not disclose case information to any external party except where disclosure is authorised, legally justified, and directed toward appropriate law enforcement, safeguarding, platform safety, or statutory bodies.

Investigators must comply with applicable data protection law, confidentiality requirements, OSCA policies, and any safeguarding procedures relevant to their role.

Investigators must not use OSCA systems for personal disputes, retaliation, curiosity searches, unauthorised background checks, harassment, intimidation, or private investigations outside OSCA’s approved case process.

Criminal history checks, DBS checks, or equivalent screening may be requested where lawful, proportionate, and relevant to the role being applied for.

Identity records, application details, and investigator access records must be stored securely and only accessed by authorised personnel.

OSCA reserves the right to suspend or remove investigator access where conduct falls below organisational standards, creates risk, breaches confidentiality, or violates OSCA policy.

PRIVACY POLICY

OCSA Privacy Policy

Last Updated: 12/6/2026
Organisation: Online Safeguarding & Cyber Agency
Lead of Privacy & Data Protection: Tanner K.
LPDP Email: kitchenst@osca-safeguarding.co.uk


1.0.1: Introduction

OSCA - Online Safeguarding & Cyber Agency collects and handles personal data for safeguarding, cyber-safety, investigation, reporting, administrative, and security purposes. This policy explains what information OSCA may hold, why it is held, how it is protected, who may access it, and how individuals can request access, correction, restriction, or removal.


1.0.2: Organisation Status

OSCA is an independent safeguarding and cyber-safety organisation. OSCA is not a police force, government agency, court, statutory authority, or emergency service, and does not claim official law-enforcement powers. Where a matter involves immediate danger, suspected criminal activity, child safeguarding, or serious harm, OSCA may advise contact with the appropriate authority or make a lawful referral where necessary.


1.0.3: Data Controller

For the purposes of UK data protection law, OSCA is responsible for deciding why and how personal data is collected, stored, reviewed, shared, restricted, or deleted. Privacy and data protection requests should be sent to [insert privacy email] with enough information to identify the relevant record or concern.


1.0.4: Information OSCA May Collect

OSCA may collect names, usernames, aliases, contact details, account identifiers, reports, concerns, case notes, evidence, screenshots, messages, links, dates, times, staff actions, audit logs, record flags, risk notes, and other information needed to assess safeguarding, cyber-safety, misconduct, or investigation-related matters.


1.0.5: Investigation Records

OSCA investigation records may include a case ID, subject details, reporter details, allegations, evidence, notes, staff comments, review outcomes, flags, attachments, and a record of actions taken. Records should be factual, relevant, proportionate, and should clearly separate confirmed information from allegations, opinions, or unverified claims.


1.0.6: Sensitive and Special Category Data

Some records may include sensitive information, such as safeguarding concerns, age, vulnerability, health information, or other special category data. OSCA will only collect and use this information where it is necessary, relevant, proportionate, and connected to a valid safeguarding, safety, investigation, legal, or administrative purpose.


1.0.7: Criminal Offence and Allegation Data

Some OSCA records may include allegations, suspected offences, harmful behaviour, misconduct, safeguarding risks, or evidence linked to possible criminal activity. OSCA does not decide criminal guilt, and such records are kept only for assessment, safeguarding, review, accountability, or referral purposes where there is a lawful reason to do so.


1.0.8: Why OSCA Uses Personal Data

OSCA may use personal data to receive and assess reports, manage investigations, review safeguarding or cyber-safety risks, contact relevant people, preserve evidence, maintain audit logs, manage staff access, prevent misuse of systems, support internal decisions, handle complaints, and make lawful referrals where serious risk or harm is identified.


1.0.9: Lawful Basis

OSCA may rely on lawful bases such as legitimate interests, consent, legal obligation, or vital interests, depending on the situation. Where special category or criminal offence data is involved, OSCA will consider whether additional legal conditions, safeguards, restrictions, or policy documentation are required before processing or retaining the information.


1.1.0: Access Controls

Access to OSCA systems and records is restricted to authorised users with a valid need to access the information. OSCA may use passwords, roles, permissions, session controls, supervisor access, and audit logs to reduce unauthorised access, because apparently “don’t snoop through records” still needs engineering support.


1.1.1: Audit Logging

OSCA may record user activity including logins, record views, record creation, edits, deletions, exports, flag changes, permission updates, and administrative actions. These logs are used to protect the integrity of OSCA systems, investigate misuse, maintain accountability, and support internal reviews.


1.1.2: Sharing Information

OSCA will only share personal data where it is lawful, necessary, and proportionate. Information may be shared with authorised OSCA staff, safeguarding contacts, platform safety teams, technical providers, legal advisers, or appropriate authorities where serious harm, safeguarding risk, legal need, or system security requires it.


1.1.3: Data Retention

OSCA will not keep personal data for longer than necessary. Retention periods may depend on the seriousness of the matter, safeguarding relevance, investigation status, legal risk, audit requirements, and whether the information is still needed for accountability, protection, dispute handling, or system security.


1.1.4: Deletion, Restriction, Redaction, and Removal Timescales

Individuals may request deletion, restriction, correction, or review of their personal data by contacting OSCA. OSCA will respond to valid removal requests within the legally required timescale, normally within one calendar month, unless the request is complex or the law allows an extension. OSCA may refuse, delay, or limit removal where the person is involved in an active investigation, an open safeguarding risk or concern, an unresolved complaint, an audit or security review, or where the data must be retained for lawful safeguarding, evidential, legal, accountability, or legitimate investigation purposes. Where OSCA cannot lawfully or safely remove a full record, the record may instead be restricted, anonymised, or redacted, with identifying details replaced by labels such as “REDACTED” or “CLASSIFIED” where appropriate.


1.1.5: Accuracy of Records

OSCA will take reasonable steps to keep records accurate, fair, and up to date. Where information is disputed, OSCA may correct it, add a dispute note, restrict access during review, remove unsupported material, or retain the information with added context where there is a lawful reason to do so.


1.1.6: Data Subject Rights

Individuals may have rights to access, correction, deletion, restriction, objection, and information about how their data is used. These rights are not absolute, and OSCA may need to verify identity or refuse part of a request where disclosure would affect safeguarding, confidentiality, system security, legal obligations, or the rights of others.


1.1.7: Subject Access Requests

Individuals may request a copy of personal data OSCA holds about them by submitting a Subject Access Request, also known as a SAR. Where a SAR is accepted for processing, OSCA may issue the requester a 7-digit SAR request number for reference, evidence, tracking, and internal audit purposes. OSCA may require reasonable proof of identity before releasing records to confirm that the requester is the individual entitled to receive the information. The response timescale may begin once the required identity information has been received. All SAR requests must be processed through the Lead Investigator at camerons@osca-safeguarding.co.uk. OSCA will normally respond within one calendar month, unless the request is complex, unclear, requires identity verification, or the law allows additional time.


1.1.8: Children and Safeguarding

Where records involve children, young people, vulnerable people, exploitation, abuse, threats, or serious harm, OSCA will handle the information with additional care. Where appropriate, OSCA may advise referral to parents, guardians, schools, safeguarding bodies, police, emergency services, or other suitable organisations.


1.1.9: Security

OSCA uses reasonable technical and organisational measures to protect personal data, including access controls, account permissions, secure hosting, audit logs, limited administrative access, and internal rules on confidentiality. No online system is perfectly secure, because the internet is a flaming skip with login forms, but OSCA will take reasonable steps to reduce risk.


1.2.0: Data Breaches

If OSCA becomes aware of a suspected personal data breach, it will assess what happened, what data was affected, who may be at risk, whether containment is possible, whether affected individuals should be informed, and whether the ICO or another authority must be notified.


1.2.1: Third-Party Services

OSCA may use third-party services for hosting, email, databases, backups, logging, communications, or website operation. Where these providers process personal data, OSCA will aim to use services with appropriate security and data protection safeguards.


1.2.2: Cookies and Website Logs

OSCA may use necessary cookies, login sessions, security logs, IP records, browser information, and error logs to operate and protect the website. Non-essential cookies or analytics should only be used where users are clearly informed and consent is obtained where required.


1.2.3: Complaints

Anyone concerned about how OSCA handles personal data should contact [insert privacy email] so the matter can be reviewed. Individuals also have the right to complain to the Information Commissioner’s Office if they believe their data protection rights have been breached.


1.2.4: Changes to This Policy

OSCA may update this Privacy Policy when its systems, legal obligations, data handling, or investigation processes change. The latest version will be published on the OSCA website with an updated date.

SAFEGUARDING POLICY

OSCA recognises that online harm can create real-world risk, particularly for children, young people, vulnerable adults, victims of harassment, and individuals experiencing crisis, exploitation, coercion, blackmail, stalking, or threats. Safeguarding concerns will be assessed based on risk, credibility, urgency, available evidence, the involvement of vulnerable persons, and the potential for ongoing or escalating harm.

Where a safeguarding concern is reported, OSCA may open an internal investigation or review to understand the nature of the concern, assess possible risk, and decide what action may be appropriate. Investigations may involve reviewing submitted reports, screenshots, messages, links, usernames, public online material, witness information, previous related records, and any other relevant evidence provided to OSCA. OSCA will aim to keep investigation records factual, proportionate, and clearly separated between confirmed information, allegations, opinions, and unverified claims.

OSCA investigations must be conducted lawfully, fairly, and within organisational role boundaries. OSCA personnel must not use deception, unauthorised access, hacking, impersonation, harassment, threats, or any other improper method to obtain information. Investigators should only collect information that is relevant to the concern being assessed and should avoid storing unnecessary personal data.

OSCA personnel must act within their role boundaries at all times. OSCA does not replace statutory safeguarding professionals, police, emergency services, mental health services, social care, schools, local authorities, or qualified clinicians. Where a concern appears to require statutory intervention, OSCA may recommend, support, or signpost referral to the appropriate external body. Where there is an immediate risk to life, safety, or welfare, emergency services should be contacted directly.

OSCA will handle safeguarding and investigation information sensitively, securely, proportionately, and on a need-to-know basis. Confidentiality is important, but it may be overridden where disclosure is necessary to protect a person from serious harm, prevent further abuse or exploitation, support safeguarding action, or comply with legal obligations.

JOIN OSCA / INVESTIGATOR APPLICATIONS

OSCA is not currently accepting new investigator applications.

At this time, recruitment for investigator, safeguarding, cyber-safety, and internal OSCA roles is closed. Any application forms, interest messages, or requests to join as an investigator may not be reviewed until recruitment is reopened.

OSCA may reopen applications in the future when there is an operational need, appropriate supervision capacity, and suitable onboarding processes available. Any future recruitment updates will be published through official OSCA channels.

Please do not submit sensitive personal information, investigation material, safeguarding reports, or private documents as part of a recruitment enquiry while applications are closed. Safeguarding concerns and online harm reports should be submitted through the appropriate OSCA contact route instead.

CONTACT

You can contact OSCA to submit a concern, request information, ask about safeguarding processes, or make a general enquiry.

For online harm reports, please provide clear, factual, and relevant information where possible. This may include usernames, platform names, profile links, dates, screenshots where lawful, and a brief explanation of the concern.

Do not send illegal material, hacked data, stolen credentials, malware, private content obtained without consent, or any material that would be unlawful to possess, share, or distribute.

If your concern involves immediate danger, risk to life, active violence, urgent welfare needs, or an ongoing emergency, contact emergency services directly. OSCA does not operate as an emergency response service and cannot guarantee immediate action.

For emotional distress or crisis support in the UK, you can contact Samaritans by calling 116 123, or text SHOUT to 85258.

OSCA will review messages as soon as reasonably possible and may prioritise reports based on safeguarding risk, urgency, available evidence, and potential harm.

Lead Investigator

Cameron S.
camerons@osca-safeguarding.co.uk

Lead of Privacy & Data Protection / Assistant Lead Investigator

Tanner K.
kitchenst@osca-safeguarding.co.uk

Commanding Investigator

N/A

PARTNERED ORGANISATIONS

As part of OSCA's mission to successfully ensure the safety of individuals, and other organisations, we partner with organisations to ensure this. below are the partnered organisations we are affiliated with.

OSCA Agent Database

Total Records

From MySQL

Open / Active

Status based estimate

High Risk

Flag/risk based estimate

Signed In

Agent session

Database Status

Checking MySQL database connection...

Create Record

Flags

Select a record type to show the correct OSCA flags for that record.
Flags are record-specific. Only flags for the selected record type can be saved.

Charges

No charges added.

Intelligence Log Information

Contact / Engagement Log Information

Arrest / Custody Fields

Lookup Records

Command Oversight

Supervisory Panel

Command roles can view operational health and open records. Only Lead Investigator / legacy admin roles get edit and close controls.

Server / MySQL

Waiting...

Records

Total MySQL records

Open Records

Open / active estimate

Security Events

Suspicious audit count

Panel locked until loaded.

Open Records

Load the panel to view open records.

Recent Activity Overview

Load the panel to view activity.

Internal Trello Board

Create internal OSCA tasks and move them through Not Started, In Progress, and Completed. Moving a card updates Google Sheets.

Not Started

Loading tasks...

In Progress

Loading tasks...

Completed

Loading tasks...

OSINT Suite

Open-source intelligence links are generated for investigator review. They are not confirmed evidence until manually verified.
Authorised Audit Review

Audit Logs

Protected Website Builder

Website / Page Editor

Edit approved OSCA public page content from inside the protected database/admin area. Saves update the live index.html after a server-side backup.

Editor locked.