What's inside

Four ways in.

Pick a thread. The newest research, the consulting we offer, the products we ship, or the methodology behind every published claim.

§ 02 · Manifest

Assurance inputs. Engineering controls.

Our work starts with primary law, standards, benchmark methods, and protocol specifications. It ends in testable controls: threat models, evaluation harnesses, privacy engineering decisions, and evidence logs.

── Assurance inputs

Law · Standards · Benchmarks

  • 01UK GDPR · Art. 25 · data protection by design
  • 02DPA 2018 · Part 3 · law enforcement processing
  • 03EU AI Act · risk classification and controls
  • 04ISO/IEC 42001 · AI management systems
  • 05ISO/IEC 27701 · privacy information management
  • 06NIST AI RMF · map, measure, manage, govern
  • 07NIST FRVT · biometric performance evidence
  • 08OWASP LLM Top 10 · agent and prompt risks
  • 09Ofcom OSA codes · online safety duties
  • 10W3C VC · verifiable credential data model
  • 11CP 1498 · digital identity consultation
  • 12DEP2025-0828 · facial recognition consultation

── Engineering controls

Eval · PETs · Architecture

  • 01Data-flow maps · trust boundaries · asset registers
  • 02Threat models · misuse cases · abuse paths
  • 03Agent eval harnesses · tool-use failure modes
  • 04Prompt-injection tests · retrieval provenance checks
  • 05Telemetry minimisation · retention and access controls
  • 06Differential privacy · aggregate release controls
  • 07ZKPs · selective disclosure · unlinkable credentials
  • 08SMPC · FHE · secure enclave suitability checks
  • 09On-device inference · local-first storage
  • 10Federated learning · private measurement
  • 11Audit trails · approval gates · incident evidence
  • 12Post-quantum migration planning

Why we exist

Your data should never leave your device.

The default model of modern software is extraction. We build the alternative. Computation stays local. AI runs on the user's device. Research is held to evidence the reader can verify.

§ 03 — In market

Two products, both shipping.

Each one is a proof point. The privacy choices we argue for in consulting and research are the ones we build with.

socialneuron.com● Live
Social Neuron homepage

01 · AI-powered social media management

Social Neuron

From brand brief to scheduled posts across every major platform. Closed learning loop on what performs. Hosted in the EU, no third-party ad trackers.

Visit socialneuron.com
thevpnmatrix.com● Live
TheVPNMatrix homepage

02 · Evidence-based VPN comparison

TheVPNMatrix

28-criteria evaluation across 3,469+ sourced records. Methodology is public; placements are reproducible. No affiliate-driven rankings.

Visit thevpnmatrix.com

What we build

Products

01 / Social Neuron

Live

Social Neuron

End-to-end content creation platform that takes you from brand brief to scheduled posts across YouTube, TikTok, Instagram, Facebook, and LinkedIn. Performance from each post informs the next. DPIA completed, EU-hosted, no third-party ad trackers.

Read more

02 / TheVPNMatrix

Live

TheVPNMatrix

Independent VPN comparison built around a published evidence methodology. 28 criteria, 3,469+ sourced records, no affiliate-driven rankings. Placement reflects the evidence, not the payout. Aggregate first-party stats only.

Read more

03 / Hearth

Coming soon

Hearth

A local-first AI runtime. Run capable language models on your own hardware (laptop, desktop, on-prem) with native context for your files, notes, and tools. No data leaves the device unless you choose to send it. Currently in private development.

Local LLMsOn-Device InferenceEdge AIConfidential Computing
Read more

§ 04 — Methodology

Evidence model.

We reduce claims to sources, tests, risks, and outputs. Public work shows citations; client work keeps the technical artefacts confidential.

Claim processing path

Claim->Source->Test->Failure mode->Decision
Public research · citableClient systems · privateOutput · evidence-backed
S

Source

Primary record, standard, benchmark result, or reproducible test artefact.

T

Test

Boundary condition, rerun path, sampling window, and known failure mode.

R

Risk

Independence, conflict, recency, scope, and privacy/security impact.

O

Output

Public citation, client finding, remediation ticket, or evidence log.

The detailed public scoring method lives in How we score VPN evidence. For client work, the same evidence loop is applied behind a confidentiality boundary.

§ 05 — Specimen · Evidence record

One claim, fully scored.

A single record from the TheVPNMatrix evidence database, with every component of the Evidence Quality Score visible. This is what every claim on the site is backed by.

Record#00342
Criterion · Server architectureLast audited · 12 Apr 2026

── Claim

Mullvad operates RAM-only VPN servers. No data persists to disk between reboots.

Primary source

Mullvad VPN AB · Server infrastructure

mullvad.net/servers · retr. 2026-04-12

Independent verification

Audit by Assured AB · July 2025

Methodology and findings published

── Score breakdown

EQS · 8 components

  • T

    Type · Primary

    Direct from provider

    5 / 5
  • G

    Grade · A

    Comprehensive, with audit appendix

    5 / 5
  • Q

    Source quality · Verified independent

    Audited technical disclosure

    5 / 5
  • I

    Independence

    Third-party audit by Assured AB

    2 / 2
  • S

    Scope

    Full infrastructure documented

    2 / 2
  • R

    Reproducibility

    Audit methodology published

    2 / 2
  • A

    Age · Fresh

    Retrieved 2026-04-12

    0 / 0
  • C

    Conflict of interest · None

    No undisclosed relationship

    0 / 0

Evidence Quality Score

21/ 21

Classification

● Strong record

Eligible for public scoring

Every other claim on TheVPNMatrix carries one of these. If a placement surprises you, the records that produced it are public.

Trust by design

Verifiable, not vibes.

Every privacy claim documented. Every framework citation specific. Every dependency disclosed.

01 — Methodology

EQS Methodology

Eight-component evidence quality score (−6 to 23). Open methodology, versioned, replicable. Every published rating shows its source records.

02 — Regulation

UK GDPR by design

Article 25 implemented at the architecture layer. DPIAs where required. Records of processing maintained. Lawful basis documented per data flow.

03 — Standards

ISO 27701 alignment

Privacy Information Management System (PIMS) controls mapped to ISO 27701:2019. Processor agreements where data leaves us. Subject rights honoured.

04 — Telemetry

No third-party ad tracking

No Google Analytics. No Facebook Pixel. No ad networks. No fingerprinting. Aggregate operational stats stay first-party and are used for reliability and readership trends, not reader profiles.

By the numbers

The arithmetic of trust.

Every claim sourced. Every test counted.

0

Tests passing across products

0

Sourced evidence records

0

Evaluation criteria, per VPN

0

Third-party ad trackers

§ 06 — Exhibit

From the casebook.

An excerpt from our litigation-grade response to the Home Office consultation on facial recognition (DEP2025-0828).

ExhibitA
Filed · 11 Feb 2026Folio · 01 / 01

── Submission · executive summary

Mass biometric surveillance of public spaces without judicial pre-authorisation, statutory basis, or adequate equality protections is incompatible with ECHR Articles 8, 10, 11, and 14, Data Protection Act 2018 Part 3, and the Public Sector Equality Duty under the Equality Act 2010 s.149.

Home Office DEP2025-0828 · response of record · 11 February 2026

Read the full submission

How we help

Consulting for UK organisations.

Technical privacy, AI agent assurance, data protection, and governance for UK organisations. We connect policy claims to architecture, tests, controls, and evidence.

  • AI agent evaluation
  • Privacy engineering reviews
  • PET suitability assessments
  • DPIA & AI impact assessments
  • AI governance frameworks
  • Online Safety Act assessments
  • Privacy-by-design reviews
  • Advisory retainers · workshops

Technical foundation

Privacy-enhancing technologies

The primitives we research, apply, and build with.

Lead

Cryptographic privacy

Maths you can verify, not policies you have to trust.

  • ·Homomorphic Encryption (FHE)
  • ·Zero-Knowledge Proofs
  • ·Secure Multi-Party Computation
  • ·Post-Quantum Cryptography

Confidential computing

Compute on data without seeing it.

  • ·Trusted Execution Environments
  • ·On-Device AI / Edge Inference
  • ·Federated Learning
  • ·Differential Privacy

Identity & sovereignty

Prove things about yourself without giving up everything.

  • ·Self-Sovereign Identity
  • ·Verifiable Credentials
  • ·Selective Disclosure (BBS+)
  • ·Age Assurance Mechanisms

Emerging

What we are watching, testing, and contributing to.

  • ·FHE Hardware Acceleration
  • ·Confidential AI
  • ·Machine Unlearning
  • ·Post-Quantum ZKPs