Trust & safety · Abuse prevention

Safety protocols for a privacy-first ecosystem.

Ackaia builds products around confidentiality, but private infrastructure must never become a safe harbor for abuse. We respond to harmful activity while preserving the zero-knowledge boundaries that protect legitimate users.

Child safety priority
No bulk surveillance
Scoped action

Private infrastructure needs real abuse controls.

Priority response

Severe harm first.

CSAM, child exploitation, malware and imminent harm receive urgent review and escalation.

Zero-knowledge boundary

No local keys. No bulk access.

Abuse review does not provide employees with user keys or general access to private files.

Proportional intervention

Action stays scoped.

Shares can be disabled and accounts restricted without weakening encryption for everyone.

Documented limits

Public policy, clear process.

The legal repository explains what Ackaia can review, cannot review and how to report it.

Operational position

Private infrastructure needs real abuse controls.

Ackaia’s trust and safety model is based on proportional intervention: gather only what is necessary, evaluate the report, preserve the service boundary and act against harmful use without weakening protection for legitimate users.

Reports are reviewed through documented policies, scoped evidence and internal protocols rather than general surveillance of private content.

  • Priority · Child safety, malware and imminent harm
  • Boundary · No bulk content surveillance
  • Response · Scoped action and legal escalation

What we act on

Abuse categories that can trigger review, restriction or removal.

Severity, available evidence, public-link context and applicable law determine the response. Unsupported or overbroad reports may be rejected or returned for more information.

  • Child sexual abuse material, exploitation and grooming · Urgent safety review and legally required escalation.
  • Malware and unsafe files · Trojans, ransomware, credential theft and harmful executables.
  • Copyright and piracy · Unauthorized distribution and repeated infringement under applicable law.
  • Phishing and fraud · Impersonation, deceptive links, credential capture and scams.
  • Illegal or severe abuse · Violent threats, exploitation, severe harassment and non-consensual exposure.
  • Spam and service misuse · Automated abuse, evasion, infrastructure misuse and service degradation.

Internal protocol

How an abuse report moves through Ackaia.

The process is designed around proportional action. Ackaia collects only what is necessary to evaluate the report, preserve operational integrity and respect the encryption boundaries of the service.

  • Step 01 · Intake and classification by harm type, urgency, product and available context.
  • Step 02 · Scoped review of report details, public-share metadata, object signatures and account behavior.
  • Step 03 · Risk assessment using report patterns, distribution signals, trust and policy severity.
  • Step 04 · Product-level action such as disabling a share, restricting behavior or suspending an account.
  • Step 05 · Legal escalation for valid requests, child safety, copyright claims and severe abuse.

Zero-knowledge first

Risk assessment does not override encryption.

Ackaia can address abuse without making private user files generally visible to employees. Reports, public-share context, object signatures and operational metadata provide scoped signals while local keys remain with the user.

  • No bulk content surveillance · Private files are not subject to generalized employee scanning.
  • No access to local keys · Abuse review does not provide user encryption keys to Ackaia staff.
  • Proportional intervention · Public links and account behavior can be restricted without weakening encryption for everyone.
  • Documented limitations · Public policies explain what Ackaia can review and what it cannot.

Legal repository and reporting

Help keep private infrastructure safe.

For binding terms, data handling rules and product-specific limitations, use the official legal repository. When reporting abuse, include the public link, suspected violation, relevant context and ownership details when applicable. Do not include unnecessary sensitive personal data.