The problem it solves
Youth platforms face the inverse threat: adults seeking access to spaces built for young people. The standard industry answer — trust the birthday field — is the same failed checkbox in reverse. Guardian Shield Inverted applies the full gateway discipline to keeping the wrong adults out.
How it works
Access to the youth platform passes through the inverted gateway before any profile or contact is possible. Signals that suggest an adult attempting entry accumulate across layers, and the gateway’s bias runs protective: uncertainty escalates, it never waves through.
Both directions, one discipline
Together with Guardian Shield, this forms a matched pair unique to the Candor architecture: minors kept off the adult platform, adults kept out of the youth platform — one verification discipline, two doors, both guarded.
Verified behaviors
Every claim below maps to a dated behavioral proof against the live production service.
A real grooming-pattern message submitted to the live screening service is detected, held, and sealed into an encrypted, tamper-evident evidence record — and the record independently verifies.
method: a grooming-class message (secrecy request, move-off-platform, image request) submitted through the live production API against a provisioned customer tenant · observed: verdict ADULT_DETECTED score 0.95 with named signals; encrypted evidence sealed to the tenant’s vault with a receipt returned; the independent verification endpoint confirmed the record intact — digest match, hash chain unbroken · VERIFIED August 3, 2026
A grooming message is caught even when the account was screened clear minutes earlier — message-level detection does not hide behind the account-level cache.
method: a benign account screened and cached CLEAR, then a grooming-pattern message sent inside the cache window · observed: the message was held despite the fresh CLEAR cache entry, evidence encrypted and hash-chained, and a review case opened · VERIFIED August 3, 2026
Each customer’s evidence lives in its own separately encrypted vault database — one tenant cannot read, or even verify the existence of, another tenant’s records.
method: two tenants provisioned on the live service, each with its own vault database and key; tenant B attempted to verify tenant A’s evidence record through the API; red-team suite run against auth bypass, injection, and cross-tenant access · observed: A verifies its own record; B’s attempt is refused; red-team suite passed 6 of 6 · VERIFIED August 3, 2026
Honest limitations
- No screening system replaces safeguarding practice — the gateway reduces exposure; platform design and human oversight complete the protection.
- Detection mechanics are deliberately not published, for the same reason as Guardian Shield’s.
Download the white paper (PDF)