
01 · AI-powered social media management
Social Neuron
From brand brief to scheduled posts across every major platform. Closed learning loop on what performs. Hosted in the EU, no third-party ad trackers.
Visit socialneuron.com
Cosmo Codex01 — Computational privacy
Software, consulting, and research for privacy-first organisations.
What's inside
Pick a thread. The newest research, the consulting we offer, the products we ship, or the methodology behind every published claim.
The most recent publication
Every Cosmo Codex research piece carries its evidence with it. Citations are specific. Methodology is published. If a claim isn't sourced, it isn't made.
Browse the archive16 Jul 2026·9 min read
Federated learning, differential privacy, and trusted execution environments let organisations train and run AI on sensitive data that regulation or competition keeps locked in place. A grounded look at what has actually shipped, what the regulators say, and where the claims outrun the evidence.
Read articleEngagements
Agent evaluation, privacy engineering, AI governance, and data protection work for UK organisations. Every engagement ends with technical findings, prioritised controls, and public-safe evidence where useful.
All engagementsShipping software
Independent comparison and on-platform content tooling, built on the same standards we recommend to clients. No ad trackers, no affiliate-driven outputs.
All productsLive
Independent VPN comparison built around a published evidence methodology. 28 criteria, 3,469+ sourced records, no affiliate-driven rankings.
Live
End-to-end content creation platform taking you from brand brief to scheduled posts across YouTube, TikTok, Instagram, Facebook and LinkedIn. DPIA completed, EU-hosted.
How we score
EQS — our Evidence Quality Score — assigns every published rating a number from −6 to 23 based on eight weighted components. Methodology versioned, replicable, and citable.
Read the methodologyEQS formula
EQS = Σ (wi · ci)
§ 02 · Manifest
Our work starts with primary law, standards, benchmark methods, and protocol specifications. It ends in testable controls: threat models, evaluation harnesses, privacy engineering decisions, and evidence logs.
── Assurance inputs
Law · Standards · Benchmarks
── Engineering controls
Eval · PETs · Architecture
Why we exist
The default model of modern software is extraction. We build the alternative. Computation stays local. AI runs on the user's device. Research is held to evidence the reader can verify.
§ 03 — In market
Each one is a proof point. The privacy choices we argue for in consulting and research are the ones we build with.

01 · AI-powered social media management
From brand brief to scheduled posts across every major platform. Closed learning loop on what performs. Hosted in the EU, no third-party ad trackers.
Visit socialneuron.com
02 · Evidence-based VPN comparison
28-criteria evaluation across 3,469+ sourced records. Methodology is public; placements are reproducible. No affiliate-driven rankings.
Visit thevpnmatrix.comWhat we build
01 / Social Neuron
LiveEnd-to-end content creation platform that takes you from brand brief to scheduled posts across YouTube, TikTok, Instagram, Facebook, and LinkedIn. Performance from each post informs the next. DPIA completed, EU-hosted, no third-party ad trackers.
Read more02 / TheVPNMatrix
LiveIndependent VPN comparison built around a published evidence methodology. 28 criteria, 3,469+ sourced records, no affiliate-driven rankings. Placement reflects the evidence, not the payout. Aggregate first-party stats only.
Read more03 / Hearth
Coming soonA local-first AI runtime. Run capable language models on your own hardware (laptop, desktop, on-prem) with native context for your files, notes, and tools. No data leaves the device unless you choose to send it. Currently in private development.
§ 04 — Methodology
We reduce claims to sources, tests, risks, and outputs. Public work shows citations; client work keeps the technical artefacts confidential.
Claim processing path
Source
Primary record, standard, benchmark result, or reproducible test artefact.
Test
Boundary condition, rerun path, sampling window, and known failure mode.
Risk
Independence, conflict, recency, scope, and privacy/security impact.
Output
Public citation, client finding, remediation ticket, or evidence log.
The detailed public scoring method lives in How we score VPN evidence. For client work, the same evidence loop is applied behind a confidentiality boundary.
§ 05 — Specimen · Evidence record
A single record from the TheVPNMatrix evidence database, with every component of the Evidence Quality Score visible. This is what every claim on the site is backed by.
── Claim
Mullvad operates RAM-only VPN servers. No data persists to disk between reboots.
Primary source
Mullvad VPN AB · Server infrastructure
mullvad.net/servers · retr. 2026-04-12
Independent verification
Audit by Assured AB · July 2025
Methodology and findings published
── Score breakdown
EQS · 8 components
Type · Primary
Direct from provider
Grade · A
Comprehensive, with audit appendix
Source quality · Verified independent
Audited technical disclosure
Independence
Third-party audit by Assured AB
Scope
Full infrastructure documented
Reproducibility
Audit methodology published
Age · Fresh
Retrieved 2026-04-12
Conflict of interest · None
No undisclosed relationship
Evidence Quality Score
21/ 21
Classification
● Strong record
Eligible for public scoring
Every other claim on TheVPNMatrix carries one of these. If a placement surprises you, the records that produced it are public.
Trust by design
Every privacy claim documented. Every framework citation specific. Every dependency disclosed.
01 — Methodology
Eight-component evidence quality score (−6 to 23). Open methodology, versioned, replicable. Every published rating shows its source records.
02 — Regulation
Article 25 implemented at the architecture layer. DPIAs where required. Records of processing maintained. Lawful basis documented per data flow.
03 — Standards
Privacy Information Management System (PIMS) controls mapped to ISO 27701:2019. Processor agreements where data leaves us. Subject rights honoured.
04 — Telemetry
No Google Analytics. No Facebook Pixel. No ad networks. No fingerprinting. Aggregate operational stats stay first-party and are used for reliability and readership trends, not reader profiles.
By the numbers
Every claim sourced. Every test counted.
Tests passing across products
Sourced evidence records
Evaluation criteria, per VPN
Third-party ad trackers
§ 06 — Exhibit
An excerpt from our litigation-grade response to the Home Office consultation on facial recognition (DEP2025-0828).
── Submission · executive summary
“Mass biometric surveillance of public spaces without judicial pre-authorisation, statutory basis, or adequate equality protections is incompatible with ECHR Articles 8, 10, 11, and 14, Data Protection Act 2018 Part 3, and the Public Sector Equality Duty under the Equality Act 2010 s.149.”
Home Office DEP2025-0828 · response of record · 11 February 2026
Read the full submissionHow we help
Technical privacy, AI agent assurance, data protection, and governance for UK organisations. We connect policy claims to architecture, tests, controls, and evidence.
Technical foundation
The primitives we research, apply, and build with.
Maths you can verify, not policies you have to trust.
Compute on data without seeing it.
Prove things about yourself without giving up everything.
What we are watching, testing, and contributing to.
Research
Federated learning, differential privacy, and trusted execution environments let organisations train and run AI on sensitive data that regulation or competition keeps locked in place. A grounded look at what has actually shipped, what the regulators say, and where the claims outrun the evidence.
Our litigation-grade response to the Cabinet Office consultation on digital identity (CP 1498). Conditional support in principle, ten demands in primary legislation.
A transparent, reproducible evidence-scoring system across 28 criteria. Every claim on TheVPNMatrix.com is backed by a record in this database.