Cosmo Codex
cosmocodex

01 — Computational privacy

Computational
privacy1,
engineered2.

1.
The property of a system whose operation can be verified without disclosing the data it operates on.
2.
Built into the architecture, attested at the boundary, audited by anyone who cares to.

Software, consulting, and research for privacy-first organisations.

  • On-device
  • Evidence-based
  • Open methodology
Scroll · § 02 ManifestCo. № 16627148
22 May 2026·Today·Reading · NIST FIPS 203 (ML-KEM) standardisation06 May 2026·Submission·Cabinet Office CP 1498 · digital identity08 Apr 2026·Article·How we score VPN evidence: methodology explained19 Mar 2026·Article·What is Privacy-by-Design and why it matters for UK businesses15 Mar 2026·Article·A practical guide to GDPR compliance for UK startups10 Mar 2026·Article·AI governance: what UK businesses need to know in 202611 Feb 2026·Submission·Home Office DEP2025-0828 · facial recognitionAug 2025·Filed·Company incorporated · Companies House № 1662714822 May 2026·Today·Reading · NIST FIPS 203 (ML-KEM) standardisation06 May 2026·Submission·Cabinet Office CP 1498 · digital identity08 Apr 2026·Article·How we score VPN evidence: methodology explained19 Mar 2026·Article·What is Privacy-by-Design and why it matters for UK businesses15 Mar 2026·Article·A practical guide to GDPR compliance for UK startups10 Mar 2026·Article·AI governance: what UK businesses need to know in 202611 Feb 2026·Submission·Home Office DEP2025-0828 · facial recognitionAug 2025·Filed·Company incorporated · Companies House № 16627148

§ 02 · Manifest

What we cite. What we build with.

Our consulting work is grounded in primary statute and case law. Our products are built on a well-defined stack of privacy-enhancing primitives. Both inform each other.

── Citations

Law · Standards · Cases

  • 01UK GDPR · Art. 25
  • 02DPA 2018 · Part 3
  • 03EU AI Act · risk tiers
  • 04ECHR · Art. 8, 10, 11, 14
  • 05Equality Act 2010 · §149
  • 06PACE 1984
  • 07ISO 42001
  • 08ISO 27701
  • 09NIST FRVT · pt. 3
  • 10OSA 2023 · Ofcom codes
  • 11CP 1498 · digital identity
  • 12DEP2025-0828 · FR

── Primitives

Crypto · PETs · Architecture

  • 01FHE · homomorphic encryption
  • 02ZKP · zero-knowledge proofs
  • 03SMPC · multi-party computation
  • 04SD-JWT VC · selective disclosure
  • 05BBS+ · unlinkable presentation
  • 06W3C VC · verifiable credentials
  • 07DIDs · decentralised identifiers
  • 08TEE · trusted execution
  • 09On-device inference
  • 10Federated learning
  • 11Differential privacy
  • 12Post-quantum cryptography

Why we exist

Your data should never leave your device.

The default model of modern software is extraction. We build the alternative. Computation stays local. AI runs on the user's device. Research is held to evidence the reader can verify.

§ 03 — In market

Two products, both shipping.

Each one is a proof point. The privacy choices we argue for in consulting and research are the ones we build with.

Product record · 01socialneuron.comLive
Social Neuron homepage

01 · AI-powered social media management

Social Neuron

From brand brief to scheduled posts across every major platform. Closed learning loop on what performs. Hosted in the EU, no third-party trackers.

Visit socialneuron.com
Product record · 02thevpnmatrix.comLive
TheVPNMatrix homepage

02 · Evidence-based VPN comparison

TheVPNMatrix

28-criteria evaluation across 3,469+ sourced records. Methodology is public; placements are reproducible. No affiliate-driven rankings.

Visit thevpnmatrix.com

What we build

Products

01 / Social Neuron

Live

Social Neuron

End-to-end content creation platform that takes you from brand brief to scheduled posts across YouTube, TikTok, Instagram, Facebook, and LinkedIn. Performance from each post informs the next. DPIA completed, EU-hosted, no third-party trackers.

Read more

02 / TheVPNMatrix

Live

TheVPNMatrix

Independent VPN comparison built around a published evidence methodology. 28 criteria, 3,469+ sourced records, no affiliate-driven rankings. Placement reflects the evidence, not the payout. Quarterly source audits, no third-party trackers.

Read more

03 / Hearth

Coming soon

Hearth

A local-first AI runtime. Run capable language models on your own hardware (laptop, desktop, on-prem) with native context for your files, notes, and tools. No data leaves the device unless you choose to send it. Currently in private development.

Local LLMsOn-Device InferenceEdge AIConfidential Computing
Read more

§ 04 — Methodology

How we score evidence.

Every claim on TheVPNMatrix is backed by a record. Every record carries an Evidence Quality Score: eight components, computed from the source. If you disagree with a placement, you can examine the components that produced it.

Specimen · Evidence Quality Score

Formula

EQS=T+G+Q+I+S+R+A+C
Range · −6 to 23Strong record · 14–18Exclusion threshold · < 8
T1–5

Type

Primary, community-replicable, secondary, tertiary.

G1–5

Grade

Awarded A–E on completeness and rigor.

Q1–5

Source quality

Academic, government, reputable press, blog, unverified.

I0–2

Independence

Distance from the subject of the claim.

S0–2

Scope

How comprehensive the underlying analysis is.

R0–2

Reproducibility

Can someone else re-run the test and check the result?

A0 to −3

Age

Fresh, recent, older, stale. Time decays score.

C0 to −3

Conflict

Disclosed soft conflict, undisclosed hard conflict.

The full methodology lives in our research piece How we score VPN evidence. The database it produces is 3,469+ records and counting.

§ 05 — Specimen · Evidence record

One claim, fully scored.

A single record from the TheVPNMatrix evidence database, with every component of the Evidence Quality Score visible. This is what every claim on the site is backed by.

Record#00342
Criterion · Server architectureLast audited · 12 Apr 2026

── Claim

Mullvad operates RAM-only VPN servers. No data persists to disk between reboots.

Primary source

Mullvad VPN AB · Server infrastructure

mullvad.net/servers · retr. 2026-04-12

Independent verification

Audit by Assured AB · July 2025

Methodology and findings published

── Score breakdown

EQS · 8 components

  • T

    Type · Primary

    Direct from provider

    5 / 5
  • G

    Grade · A

    Comprehensive, with audit appendix

    5 / 5
  • Q

    Source quality · Verified independent

    Audited technical disclosure

    5 / 5
  • I

    Independence

    Third-party audit by Assured AB

    2 / 2
  • S

    Scope

    Full infrastructure documented

    2 / 2
  • R

    Reproducibility

    Audit methodology published

    2 / 2
  • A

    Age · Fresh

    Retrieved 2026-04-12

    0 / 0
  • C

    Conflict of interest · None

    No undisclosed relationship

    0 / 0

Evidence Quality Score

21/ 21

Classification

● Strong record

Eligible for public scoring

Every other claim on TheVPNMatrix carries one of these. If a placement surprises you, the records that produced it are public.

Evidence ledger

Claims need records.

We avoid billboard statistics unless the source can be inspected. Public claims are treated as records with owners, cadence, and release-time checks.

RecordControlEvidenceCadence

EQS-003469

VPN evidence records

3,469 sourced records

Quarterly source audit

DPIA-SN-2026

Social Neuron DPIA

Completed before public launch

Reopened on material feature change

SITE-TELEMETRY

Marketing-site telemetry

No analytics pixel or tracking cookie

Checked on release

PETS-RESEARCH

Privacy-enhancing technology notes

Research mapped to implementation gates

Updated when claims change

§ 06 — Exhibit

From the casebook.

An excerpt from our litigation-grade response to the Home Office consultation on facial recognition (DEP2025-0828).

ExhibitA
Filed · 11 Feb 2026Folio · 01 / 01

── Submission · executive summary

Mass biometric surveillance of public spaces without judicial pre-authorisation, statutory basis, or adequate equality protections is incompatible with ECHR Articles 8, 10, 11, and 14, Data Protection Act 2018 Part 3, and the Public Sector Equality Duty under the Equality Act 2010 s.149.

Home Office DEP2025-0828 · response of record · 11 February 2026

Read the full submission

How we help

Consulting for UK organisations.

Data protection, AI governance, and online safety compliance for UK organisations. Every engagement ends in a prioritised, specific remediation plan.

  • GDPR compliance audits
  • DPIA & impact assessments
  • AI governance frameworks
  • Online Safety Act assessments
  • Privacy-by-design reviews
  • Advisory retainers · workshops

Technical foundation

Privacy-enhancing technologies

The primitives we research, apply, and build with.

Lead

Cryptographic privacy

Math you can verify, not policies you have to trust.

  • ·Homomorphic Encryption (FHE)
  • ·Zero-Knowledge Proofs
  • ·Secure Multi-Party Computation
  • ·Post-Quantum Cryptography

Confidential computing

Compute on data without seeing it.

  • ·Trusted Execution Environments
  • ·On-Device AI / Edge Inference
  • ·Federated Learning
  • ·Differential Privacy

Identity & sovereignty

Prove things about yourself without giving up everything.

  • ·Self-Sovereign Identity
  • ·Verifiable Credentials
  • ·Selective Disclosure (BBS+)
  • ·Age Assurance Mechanisms

Emerging

What we are watching, testing, and contributing to.

  • ·FHE Hardware Acceleration
  • ·Confidential AI
  • ·Machine Unlearning
  • ·Post-Quantum ZKPs