Your Safety Net Starts Too Late
- BY
- ROOT TEAM
- PUBLISHED
- SEPTEMBER 2, 2026
- READING TIME
- 9 MIN READ
Every system built to protect people from online abuse waits for the moment that matters least. It waits for publication, when the harm already happened at the threat. This is why that gap exists, and the one rule that closes it.
There is a woman we keep coming back to. Call her R. One evening a message arrives on her phone. A private photo of her, and a demand. Money by tomorrow night, or it goes to her family. She does not know if the photo is real or generated. She has told no one. She is not sure she can tell anyone.
Here is the part of her story that almost everyone gets wrong. The worst moment was not when she hit publish on anything, because she never published anything. The worst moment was that message. The fear of what her family would think. The isolation of carrying it alone. The knowledge that someone held something over her and she had no way to push back.
By the time any official system would start helping her, that worst moment would be long over.
The system wakes up after the harm
The entire infrastructure built to respond to image based abuse is pointed at the wrong event. A victim reports, but only once content has actually appeared online. The system then responds with takedown requests, platform reports, and sometimes prosecution. Every part of the machine is tuned to the instant an image goes public.
This is backwards, and it is backwards in a way that matters enormously.
The damage does not begin at publication. It begins at the threat. The coercion, the fear, the extortion, the isolation, these are not warnings that harm is coming. They are the harm itself. And during the phase when a woman is experiencing them, no existing system is built to catch her. She cannot go to the police, because nothing has been published. She cannot report to a platform, because the content is not public. She cannot get a legal order, because there is no documented abuse in progress yet. Every institutional pathway requires the harm to have already happened.
In an honour based context this gap is not an inconvenience. It is lethal. The threat to send an image to family carries the same weight as actually sending it. A woman does not need the image to be public to lose her safety, her autonomy, or her life. But the systems designed to protect her wait for exactly that.
Why the gap exists
The structural reason is that anti abuse infrastructure is built around evidence collection, and evidence collection assumes the misdeed has already happened. Takedown needs the content to exist on a platform. Legal proceedings need documented publication. Blocking networks need the image to compute a hash. Every capability is designed to act on the artifact, never on the moment a person first feels unsafe.
So the systems all share a single fatal design. To get help, a victim must surrender the one thing she cannot afford to give.
To report, she must share the image. To preserve evidence, she must upload it somewhere. To prove abuse, she must show it to someone. Every path to protection asks her to hand over the material that endangers her, and then to trust that a database full of other people's most private moments will never be the next thing to fail.
This creates a perfectly rational fear of the systems themselves. A woman in danger asks the obvious questions. Who holds this? How is it stored? What happens if you are breached? In a context where exposure can end a life, these are not abstract risks. They are survival calculations. And when the answer to every question is that the system will hold the image that is being used against her, she makes the only choice that makes sense. She stays silent.
The gap feeds itself
Here is the cruelest part. Because women do not report during the threat phase, institutions collect no data on how common coercion actually is. Without data, there is no mandate to build proactive systems. Without proactive systems, women keep suffering alone in the gap. The absence of reports is quietly read as the absence of harm, when in truth it is the strongest evidence of how broken the door is.
And when publication finally does happen, the report that arrives is already damaged. The evidence is scattered. The timeline is unclear. The victim has endured the worst of it alone and is now being asked to produce a clean record on demand. The investigation starts uphill. Meanwhile the institution that collected her private image as evidence is now itself a vulnerability. The material exists. People have access. Systems get breached. The very organization built to protect her becomes another vector for revictimization.
We have seen this pattern repeat across platform safety teams, hotlines, and national response schemes. The tool sounds responsible. We collect the evidence. It sounds thorough. And it is the moment the instrument of protection starts to become the thing it was meant to defend against.
The rule that changes it
We have spent years teaching people to trace a problem to its root cause instead of its symptom. This is the same discipline applied to the most human system there is. So here is the rule, stated plainly.
A safety system should be measured not by the harm it cleans up, but by the harm it prevents from ever beginning. And the architecture that honors that rule does two things no reactive system does.
First, it activates on the threat, not the publication. A credible threat becomes the entry point, the moment a person says someone is endangering them, whether or not anything has gone public. Protection begins when the fear begins, because that is when the person is actually in danger.
Second, it refuses to hold the material that endangers the person. The image never enters the system. Not as a policy promise, but as a technical impossibility. A fingerprint is computed on the victim's own device and only the hash moves on, so platforms can block a match later without the picture ever leaving her phone. The system stores the threat evidence richly, the messages, the sender, the demands, and refuses the photograph entirely. A breach of such a system would reveal threat correspondence, never the weaponized material, because the material was never there to be taken.
What gets built differently
Once you accept the rule, the design choices stop being hard. The threat report triggers immediate safety guidance and a tamper evident record. A transparent risk engine surfaces signals for a human reviewer, but never decides alone. A minor forces a safeguarding path. A threat of violence forces human review. High risk cases never proceed on automation, because the illusion of automation is the most dangerous object in any room holding human vulnerability.
The system does not pretend to be more than it is. It guides a victim to the official blocking service instead of claiming to submit on her behalf. It prepares structured referral packets that contain no image bytes. It makes its own limits visible and honest, because honesty is the only currency a terrified person will trust.
We built a version of this. The encrypted vault that refuses images. The tamper evident ledger. The explainable risk engine. The integration seam with a guided handoff. We proved with tests that the vault rejects the image two different ways, that a minor forces the safe path, that the referral packet contains no picture anywhere. What took the human reviewers with credibility training, the forensic support, the partnerships, the sustained trust that no solo team can manufacture, those remain the real cost. Software was the easy part. Trust is the expensive part. Any honest budget has to lead with the trust.
The uncomfortable conclusion
The task of protecting people from image based abuse keeps failing not because the technology is hard, but because the design is oriented toward the wrong moment and the wrong object. It waits for publication, and it demands the image. Both choices are wrong, and both are fixable the moment you stop confusing the artifact with the harm.
The harm is the threat. The harm is the surrender. The harm is the silence that a system forces a terrified person into by asking her to hand over the very thing that endangers her. A real safety net starts at the moment she is threatened, holds nothing that can hurt her if it is breached, keeps humans in the loop, and measures itself by the damage that never happened.
Try it this week
Think about the last safety feature, content policy, or reporting flow your own team shipped. Ask two questions about it. At what moment does it first begin helping a person, at the moment of the threat or at the moment of the artifact? And what does it require that person to hand over to get that help? If the answer to the first is that it waits, and the answer to the second is the material that endangers them, then you have not built a safety net. You have built a door that opens after the fire, and asks the person inside to bring the thing that is burning. Whatever you are building, find a way to start the safety earlier and hold less. That is where the cause lives, and that is where the fix has to begin. Finding the cause is our daily work.