Draft — under legal review. Nothing on this page is final legal advice; the enforcement described below is live as stated.
Trust & Safety
LAGOON is a channel the audience writes: one continuous AI broadcast, live around the clock, that airs whatever is legal to show. We don't run a taste filter in front of that. We do run a legal one, and this page is what that filter is, who's accountable for it, and how to report something that gets through anyway.
Who's accountable
LAGOON Media, the operator of this channel, is the named, accountable Trust & Safety owner for LAGOON. There is no separate Trust & Safety team — this is a small company, and the page says so rather than implying otherwise. Every report, every appeal, and every regulator inquiry reaches the same person. Contact: [email protected].
What we check, and how
Every prompt is checked before it airs. Sampled frames of the live broadcast and reference images are checked against the same rules too — the frame-sampling and hash-matching layers below are built, wired end to end, and tested against a real synthetic broadcast; each one activates for real production traffic only once its specific precondition is met (real-model validation on our own GPU, for frame sampling; a live vendor partnership, for hash matching). Until each precondition is met, that layer denies rather than waving anything through — the same fail-closed rule stated at the bottom of this section, not an exception to it. Three layers, in order:
- Pre-broadcast prompt check. Two classifiers we run ourselves, on our own hardware: Llama Guard 4 (12B) and ShieldGemma (2B), both from open weights (Meta and Google respectively). ShieldGemma is fed our actual published deny list as its instructions, not a paraphrase of it — the rule enforced and the rule published are the same document. We also run OpenAI's free moderation endpoint as a second opinion for non-CSAM categories. We chose to run the CSAM and non-consensual-imagery checks exclusively on our own hardware, never sending that content to any outside vendor, because every hosted moderation vendor's terms are ambiguous about whether you're even allowed to send them that content for classification in the first place. Self-hosting removes the question. This layer is live today, tested against 60+ scenarios including 13 legal-but-distasteful adversarial prompts.
- Frame sampling. A sidecar worker pulls one frame every ten seconds
(
FRAME_SAMPLE_INTERVAL_S, configurable) from the live broadcast and sends it through Llama Guard 4 — the only one of our two self-hosted models that can read an image at all; ShieldGemma is a text-only model and has never run this check (an earlier internal review caught it sitting in this layer regardless, which is exactly the kind of gap this sentence exists to rule out going forward — see "Code that keeps this honest" below). The sampler and worker are built and run end to end against a synthetic stream today. Llama Guard 4's image-understanding path itself is implemented against the vendor's documented multimodal format but has not yet been validated against real weights on real GPU hardware — we don't have a GPU in our current build environment. Until that validation happens, this layer is configured to deny by default rather than pass anything through unproven. - Hash matching. Reference images in our curated library and sampled output frames are built to run against PhotoDNA, StopNCII, and Google CSAI Match's abuse-image hash banks — the same tool used across the industry to catch re-uploads and redistribution, not to catch a wholly new image (nothing generated for the first time has a hash to match against yet; that's a pre-broadcast job, which is what step 1 does). This layer requires a live vendor partnership and credentials we don't have yet (see Named Partners below); our client code refuses to run against a real backend without a real perceptual-hash algorithm in place of the placeholder we ship today, so this layer also denies rather than silently no-op until a partnership and a real hash implementation are both in place.
If any of the above fails, times out, can't be reached, or hasn't been activated yet, the prompt or frame is refused. A broken or not-yet-live checker is not treated as a pass — including the frame and hash layers above, while they wait on GPU validation and vendor credentials respectively.
Code that keeps this honest: the frame check can no longer silently include a text-only model — the software itself refuses to start if a classifier that can't read images is registered for this layer (a configuration error, not a runtime guess). The same software refuses to treat "we couldn't check the image" as "the image is fine."
The deny list
Five categories, each naming the law that makes it illegal. The full list, every source
cited, and which parts are still pending a lawyer's sign-off, is public at
services/moderation/denylist.yaml and summarized on our Acceptable Use Policy.
Short version: child sexual abuse material in any form including AI-generated, non-consensual
intimate imagery of a real person including deepfakes, an undisclosed deepfake of a real
identifiable person, terrorism or violent-extremism support, and content that fails a
legally required age gate in a jurisdiction that has one. Nothing else is refused. Legal,
adult, properly age-gated content between consenting adults airs. Violence that's legal to
show, airs. Content that's merely embarrassing, in bad taste, or unflattering to a brand or
a politician airs. That's not an oversight — it's the entire premise of the product.
Named partners
- NCMEC (National Center for Missing & Exploited Children). We have built our reporting
client against NCMEC's own published test environment (
exttest.cybertip.org) and intend to register as a voluntary Electronic Service Provider. Registration: not yet submitted — this is a named launch-day step (PLAN.md §11, item L10), not a completed partnership. We are not a US company and have no statutory duty to report to NCMEC, but we intend to anyway, the same way non-US platforms in our category already do. - StopNCII.org (operated by the UK's Revenge Porn Helpline / SWGfL). Hash-based, privacy-preserving matching for non-consensual intimate imagery — the victim hashes their own image on-device, we never see the image itself, only the hash. Partner application: not yet submitted — their partner-onboarding flow is not self-serve and requires contacting them directly; this is also a named launch-day step. Confirmed current partners in our content category include Pornhub, OnlyFans, xVideos, and REDGIFS — we are adopting a control that is already standard among direct peers, not inventing one.
- PhotoDNA (Microsoft) and Google's Content Safety API / CSAI Match. Free for qualifying organizations, application-gated. Applications: not yet submitted. These are the hash-matching backstops that cover images (PhotoDNA) and video (CSAI Match) once we're approved.
- IWF (Internet Watch Foundation). We checked. We do not qualify — their membership terms require more than two full-time employees, and we're a one-person company. We are not applying, and we are not claiming a relationship we don't have.
We are naming every one of these accurately as "applied" or "not yet applied," not as an active partnership, because an underwriter checks, and because pretending otherwise is the kind of thing that gets a company's account terminated, not approved.
The classifiers, named
Llama Guard 4 (12B) and ShieldGemma (2B), both open-weight models we run on our own GPU, check every prompt before it airs. Llama Guard 4 alone checks sampled broadcast frames — it's the only one of the two that reads images; ShieldGemma is text-only. OpenAI's omni-moderation endpoint runs as a free secondary opinion for non-CSAM categories, on prompts only. No content in the CSAM or non-consensual-imagery categories, and no sampled broadcast frame, is ever sent to a third party for classification — see "What we check, and how" above.
Enforcement
A denied prompt never airs; the chat sees a plain-language reason naming the category, not a generic refusal. Something that gets through anyway can be taken down individually — an operator disabling that specific clip, recorded with who did it, when, and why — without cutting the whole channel. A confirmed violation can result in an account suspension; an account with a pattern of denied prompts or takedowns is suspended from directing automatically, not only on a human's individual review. Apparent CSAM is escalated through our NCMEC reporting client (once registration is complete) and, as a Swiss company, through the federal police's own reporting channel (fedpol.admin.ch/en/reporting-illegal-pornography). A kill switch exists that cuts the entire broadcast to a static off-air card in one call, reachable by the accountable owner from a phone, for anything the automated layers don't resolve fast enough.
Appeals
If you think a prompt was wrongly refused, or content should have been refused and wasn't, you can appeal. A person reads every appeal by hand — it is never routed back through the same automated check that made the original decision. Full process, including our response time commitment, is at Takedown & Appeals.
Report something
The fastest way: hit Report on the player, or go to /report — no account needed. We record what was actually airing at the moment you report it, so you don't have to describe it perfectly. You can also email [email protected] with what you saw and when. If you are the subject of non-consensual intimate imagery, you can also go directly to StopNCII.org (18 or older) or NCMEC's Take It Down tool (under 18, or concerned about content from when you were under 18) — both work independently of us and don't require us to act first.
A report that turns out to be a real violation can result in the clip being taken down immediately and, for a pattern of violations from the same account, suspension from directing — see "Enforcement" below.
What's still open
This page mirrors the shape of similar pages published by comparable platforms, adapted to our actual facts rather than copied. Two things are explicitly unresolved and this page says so rather than hiding it: the exact Swiss statutory wording behind the CSAM and personality-rights lines of our deny list is still pending a lawyer's direct reading (the government's own law portal is not machine-readable, and no shortcut around that is honest), and none of the partner applications above has been submitted yet — every one is a named launch-day step, not an existing relationship. Both are named, both have owners, and this page will be corrected the moment either changes.