Trust & Safety
The honest version: privacy-first doesn't mean lawless. Here's what we audit, what we disclose, how we respond to reports, and what we do when the state comes asking.
The four pillars
P1
SOC 2, annual pentests, bug bounties, and cryptography that's actually peer-reviewed.
Jump ↓P2
Clear platform rules. Space admins set their own. Humans review appeals.
Jump ↓P3
Every six months we publish numbers — takedowns, warrants, incidents, outages.
Jump ↓P4
We follow it. We also challenge it when it's overbroad. Here's the line.
Jump ↓Pillar 01 · Security
SOC 2 Type II
Feb 2025
BDO · Report on request under NDAPentest
Jan 2025
NCC Group · 0 critical, 2 high (resolved)Crypto review
Oct 2024
Trail of Bits · public reportGDPR DPA
Current
Signed with 8,400+ customersBug bounty program
Scope includes app, API, web, and the reference protocol implementation. Out of scope: social engineering, third-party vendors, self-XSS. PGP key: 0x8E1D4A2F.
Pillar 02 · Moderation
Enforced by Clikkin. These are the lines no space can opt out of.
Violations can result in account termination. Space admins who knowingly harbor these are terminated with their spaces.
Set by admins. Must be more restrictive than platform rules, never less. Members see them on join.
Clikkin doesn't second-guess a space's internal moderation unless it crosses into L1.
If we're wrong
A trained human, not the model that flagged it, reviews every appeal. If we were wrong, we say so publicly, restore the content, and log what we changed.
Pillar 03 · Transparency
Published March and September. This table covers July – December 2024. The full PDF with methodology is at the bottom.
Total user reports
82,411
Content removed
11,240
Accounts terminated
1,019
Appeals granted
24%
Government requests
67
NCMEC reports filed
118
Uptime
99.98%
Security disclosures
43
Government requests · H2 2024 detail
| Requesting country | Type | Count | Complied | Challenged | Rejected |
|---|---|---|---|---|---|
| United States | Subpoena | 28 | 18 | 7 | 3 |
| United States | Search warrant | 12 | 10 | 2 | 0 |
| United States | Preservation order | 8 | 8 | 0 | 0 |
| United Kingdom | RIPA / IPA | 5 | 0 | 2 | 3 |
| Germany | NetzDG | 4 | 3 | 1 | 0 |
| France | Court order | 3 | 1 | 1 | 1 |
| Other (6 countries) | Mixed | 7 | 2 | 3 | 2 |
"Challenged" = we went to court or filed a formal objection. "Rejected" = refused on procedural or scope grounds without litigation. Where permitted, we notified the affected user.
Warrant canary
As of March 14, 2025, Clikkin has not received any National Security Letter, FISA order, or other secret court order that would prevent us from saying so. If this statement disappears in a future update, assume otherwise.
-----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQTyVm0dKAj... [truncated · full at /canary.txt] -----END PGP SIGNATURE-----
Pillar 04 · Rule of law
For law enforcement
Our Law Enforcement Guidelines specify what data is available, required legal process, emergency channel, and response timelines. Legal process must be served on our registered agent:
Clikkin, Inc.For requests involving imminent risk of death or serious physical injury only. Verified through a law-enforcement portal; do not call unverified numbers.
Access the LE portal →Report something
Long-press in the app, or hit the ⋮ menu. We respond within 24 hours; urgent safety threats within 1 hour.
In-app is fastest →contact@clikkin.com · PGP key 0x8E1D4A2F. Bounties up to $10,000. 24-hour acknowledgement.
Submit a properly-formed notice via our designated agent. We process within 10 business days and forward to the poster.
File a DMCA →If you or someone you know is in crisis, we can't replace a hotline. Resources by country, and how we route sensitive reports internally.
Crisis resources →