01 · AI-powered social media management
Social Neuron
From brand brief to scheduled posts across every major platform. Closed learning loop on what performs. Hosted in the EU, no third-party trackers.
Visit socialneuron.com
Cosmo Codex
01 — Computational privacy
Software, consulting, and research for privacy-first organisations.
What's inside
Pick a thread. The newest research, the consulting we offer, the products we ship, or the methodology behind every published claim.
The most recent publication
Every Cosmo Codex research piece carries its evidence with it. Citations are specific. Methodology is published. If a claim isn't sourced, it isn't made.
Browse the archive06 May 2026 · 5 min read
Our litigation-grade response to the Cabinet Office consultation on digital identity (CP 1498). Conditional support in principle, ten demands in primary legislation.
Read articleEngagements
Data protection, AI governance, and online safety work for UK organisations. Every engagement ends with a prioritised, specific remediation plan — not a generic checklist.
All engagementsShipping software
Independent comparison and on-platform content tooling, built on the same standards we recommend to clients. No third-party trackers, no affiliate-driven outputs.
All productsLive
Independent VPN comparison built around a published evidence methodology. 28 criteria, 3,469+ sourced records, no affiliate-driven rankings.
Live
End-to-end content creation platform taking you from brand brief to scheduled posts across YouTube, TikTok, Instagram, Facebook and LinkedIn. DPIA completed, EU-hosted.
How we score
EQS — our Evidence Quality Score — assigns every published rating a number from −6 to 23 based on eight weighted components. Methodology versioned, replicable, and citable.
Read the methodologyEQS formula
EQS = Σ (wi · ci)
§ 02 · Manifest
Our consulting work is grounded in primary statute and case law. Our products are built on a well-defined stack of privacy-enhancing primitives. Both inform each other.
── Citations
Law · Standards · Cases
── Primitives
Crypto · PETs · Architecture
Why we exist
The default model of modern software is extraction. We build the alternative. Computation stays local. AI runs on the user's device. Research is held to evidence the reader can verify.
§ 03 — In market
Each one is a proof point. The privacy choices we argue for in consulting and research are the ones we build with.
01 · AI-powered social media management
From brand brief to scheduled posts across every major platform. Closed learning loop on what performs. Hosted in the EU, no third-party trackers.
Visit socialneuron.com
02 · Evidence-based VPN comparison
28-criteria evaluation across 3,469+ sourced records. Methodology is public; placements are reproducible. No affiliate-driven rankings.
Visit thevpnmatrix.comWhat we build
01 / Social Neuron
LiveEnd-to-end content creation platform that takes you from brand brief to scheduled posts across YouTube, TikTok, Instagram, Facebook, and LinkedIn. Performance from each post informs the next. DPIA completed, EU-hosted, no third-party trackers.
Read more02 / TheVPNMatrix
LiveIndependent VPN comparison built around a published evidence methodology. 28 criteria, 3,469+ sourced records, no affiliate-driven rankings. Placement reflects the evidence, not the payout. Quarterly source audits, no third-party trackers.
Read more03 / Hearth
Coming soonA local-first AI runtime. Run capable language models on your own hardware (laptop, desktop, on-prem) with native context for your files, notes, and tools. No data leaves the device unless you choose to send it. Currently in private development.
§ 04 — Methodology
Every claim on TheVPNMatrix is backed by a record. Every record carries an Evidence Quality Score: eight components, computed from the source. If you disagree with a placement, you can examine the components that produced it.
Formula
Type
Primary, community-replicable, secondary, tertiary.
Grade
Awarded A–E on completeness and rigor.
Source quality
Academic, government, reputable press, blog, unverified.
Independence
Distance from the subject of the claim.
Scope
How comprehensive the underlying analysis is.
Reproducibility
Can someone else re-run the test and check the result?
Age
Fresh, recent, older, stale. Time decays score.
Conflict
Disclosed soft conflict, undisclosed hard conflict.
The full methodology lives in our research piece How we score VPN evidence . The database it produces is 3,469+ records and counting.
§ 05 — Specimen · Evidence record
A single record from the TheVPNMatrix evidence database, with every component of the Evidence Quality Score visible. This is what every claim on the site is backed by.
── Claim
Mullvad operates RAM-only VPN servers. No data persists to disk between reboots.
Primary source
Mullvad VPN AB · Server infrastructure
mullvad.net/servers · retr. 2026-04-12
Independent verification
Audit by Assured AB · July 2025
Methodology and findings published
── Score breakdown
EQS · 8 components
Type · Primary
Direct from provider
Grade · A
Comprehensive, with audit appendix
Source quality · Verified independent
Audited technical disclosure
Independence
Third-party audit by Assured AB
Scope
Full infrastructure documented
Reproducibility
Audit methodology published
Age · Fresh
Retrieved 2026-04-12
Conflict of interest · None
No undisclosed relationship
Evidence Quality Score
21 / 21
Classification
● Strong record
Eligible for public scoring
Every other claim on TheVPNMatrix carries one of these. If a placement surprises you, the records that produced it are public.
Trust by design
Every privacy claim documented. Every framework citation specific. Every dependency disclosed.
01 — Methodology
Eight-component evidence quality score (−6 to 23). Open methodology, versioned, replicable. Every published rating shows its source records.
02 — Regulation
Article 25 implemented at the architecture layer. DPIAs where required. Records of processing maintained. Lawful basis documented per data flow.
03 — Standards
Privacy Information Management System (PIMS) controls mapped to ISO 27701:2019. Processor agreements where data leaves us. Subject rights honoured.
04 — Telemetry
No Google Analytics. No Facebook Pixel. No ad networks. No fingerprinting. The site you're reading sends data to one server: this one.
By the numbers
Every claim sourced. Every test counted.
Tests passing across products
Sourced evidence records
Evaluation criteria, per VPN
Third-party trackers, anywhere
§ 06 — Exhibit
An excerpt from our litigation-grade response to the Home Office consultation on facial recognition (DEP2025-0828).
── Submission · executive summary
“Mass biometric surveillance of public spaces without judicial pre-authorisation, statutory basis, or adequate equality protections is incompatible with ECHR Articles 8, 10, 11, and 14, Data Protection Act 2018 Part 3, and the Public Sector Equality Duty under the Equality Act 2010 s.149. ”
Home Office DEP2025-0828 · response of record · 11 February 2026
Read the full submissionHow we help
Data protection, AI governance, and online safety compliance for UK organisations. Every engagement ends in a prioritised, specific remediation plan.
Technical foundation
The primitives we research, apply, and build with.
Math you can verify, not policies you have to trust.
Compute on data without seeing it.
Prove things about yourself without giving up everything.
What we are watching, testing, and contributing to.
Research
Our litigation-grade response to the Cabinet Office consultation on digital identity (CP 1498). Conditional support in principle, ten demands in primary legislation.
A transparent, reproducible evidence-scoring system across 28 criteria. Every claim on TheVPNMatrix.com is backed by a record in this database.
Privacy-by-Design is a legal requirement under UK GDPR, not just a best practice. This guide explains the seven foundational principles and how UK businesses can implement them.