Policy
Community Safeguards
Draft · pre-pilot
This page summarizes, in policy form, the safeguard commitments described on the Safeguards page. They apply to how RR conducts research and pilot design today, and they are the baseline requirements for any future platform.
Commitments
- Purpose limitation. Data may only be used for defined civic-response purposes. Repurposing information for monitoring, profiling or unrelated enforcement is prohibited by design and by policy.
- Data minimization. The system collects only the information necessary for the specific incident. If a report about a flooded road doesn’t need a name, a name isn’t collected.
- Protected reporting. Reporter details are not publicly displayed. Participation happens under masked identifiers so that reporting a hazard never exposes the reporter.
- Verification before reward. No one is rewarded simply for accusing someone. Any incentives are linked to verified, useful and responsible participation — confirmed hazards, emergency assistance and reliable public-interest information.
- Human review. High-risk reports require trained human review. Automated signals can help prioritize, but they do not make consequential decisions on their own.
- Anti-retaliation measures. The system is designed to protect reporters and prevent targeted harassment, including protections against attempts to unmask or intimidate participants.
- Corrections and appeals. People and institutions must have a clear process to challenge inaccurate information, request corrections and appeal decisions that affect them.
- Data retention limits. Sensitive data is not retained indefinitely. Retention schedules are defined per data category and enforced technically, not just contractually.
- Independent oversight. Governance includes civil-society, legal, technical and community representation with real authority to review, pause and change how the system operates.
- Auditability. Sensitive access, report changes and institutional actions are logged in tamper-evident records available to oversight bodies.
- Security. Encryption in transit and at rest, role-based access, secure authentication and regular independent security assessment are baseline requirements.
During the pre-pilot stage
- Community engagement is voluntary, informed and documented.
- No community data is collected beyond what participants knowingly contribute to research sessions.
- Findings that identify individuals are not published without consent.
- Communities can withdraw from design engagement at any time.
