pdPurpledecks
Book a review
Safeguarding engineering · Peer support and community platforms

Peer-support and community platforms with safeguarding built in.

A policy does not enforce itself.

You have a safeguarding policy and a platform where people disclose things. Purpledecks is a senior software engineering firm in Ireland. We design and build the systems that make the policy real: joining rules, moderation, reporting, escalation, access control, retention. We built the peer-support platform and moderation system for Someone Like Me, with data protection designed in.

See the review See the twelve questions →
PURPLEDECKS · EST. 2012 · 53.7°N 7.8°W · IRELAND · EU
§ 01 · Honest fit

Who this is for, and who it is not.

In product circles this work is often called trust and safety. We call it safeguarding, because that is the word in the policy your board signed.

A fit

You are a founder, product owner or operations lead at a charity, a peer-support community or a health-adjacent service. You are building or fixing a platform where vulnerable people interact and disclose. You hold a safeguarding policy and duties, and you need them to exist as working software rather than as a document.

The shape matters more than the sector. If your product has user-to-user contact, a foreseeable risk to someone's welfare, sensitive interpersonal data and a real moderation duty, you are in the same place.

Not us

You want safeguarding policy consultancy. You want someone to moderate your community for you. You are shopping for a case-recording or case-management product. Nobody in your organisation owns safeguarding by name. Or your product is a medical device, which is a different regime and a different page.

Operators, recorders and builders

Togetherall, Kooth and Side by Side are operated services. You refer people to them and somebody else runs the service. Case-recording and case-management products are a different purchase again: they hold the record of concerns your staff enter. We are neither. We build and fix the platform you run yourself, and we build the safeguarding into it.

§ 02 · The checklist · Twelve questions

Does the software actually do what my safeguarding policy says?

Twelve questions a board asks, and the safeguarding software we build for each one. Every row has its own link, so you can send one question to the person who has to answer it.

SG-01

Who can join, and how do we know?

Registration and identity rules, an age gate where under-18s are in scope, and the smallest set of fields a person must give before anything opens to them.

SG-02

Who can contact whom?

Who can see and message whom is decided once and enforced by the system itself, not just hidden on the screen. Two people get a private conversation only when both have agreed to it.

SG-03

What can a member do to protect themselves?

Block someone, mute a thread, leave a group, decline a connection, or take a break. Each one is a real setting the system remembers and applies everywhere, not a preference that quietly lapses.

SG-04

How does someone report a concern?

A report route in every place people talk, and a record of the report that cannot be edited away.

SG-05

How do we tell urgent from ordinary?

A triage queue with severity, ordering and an owner, so the urgent case is not sitting behind forty ordinary ones.

SG-06

Who is on duty, and what happens at two in the morning?

Rotas and cover in the tool, and the out-of-hours message a person actually sees, so nobody is left waiting in silence.

SG-07

Who can read a disclosure?

Role-based access, with the read itself logged. You decide access once and the software enforces it every time.

SG-08

What can a moderator actually do?

A permission matrix for each role, every action written to an audit log, and no action taken by software on its own.

SG-09

What data do we actually need to hold?

We go through the data one field at a time and keep only what a feature genuinely needs, so nothing sensitive is collected on the chance it might be useful later.

SG-10

How long do we keep it?

Retention periods per class of data, a deletion window, export on request, and the deletion running rather than being promised.

SG-11

What do we let the software decide?

This is human-in-the-loop content moderation. The software spots something and puts it in front of a person, and the person decides what happens next. Nothing is removed and nobody is suspended on the software's word alone.

SG-12

How do we show it works, and keep it working?

The safeguarding rules are written down as tests the software has to pass, and they run again every time anything changes. If a rule breaks, the build tells us before your members do, and the reports come in language a trustee can read.

In Ireland, safeguarding guidance names a Designated Liaison Person. In the UK the same role is called a Designated Safeguarding Lead. The software does not care what you call it. It needs one named person, with cover.

Where the data sits

We name the region your data is stored in, and we hand you the list of every third party the platform sends data to and what each one receives. Trustees ask this. The answer should exist before they ask.

Tests we write

The safeguarding rules are tested as rules, at the backend, on every change. A general administrator cannot open private messages. A report cannot vanish without history.

Checklist version 1.0 · Maintained by Barry Gough, Chief Technology Officer
See the review
§ 03 · Proof

One platform, live, with four of these built in.

Someone Like Me is a founder-led cancer peer-support platform. Four facts, and then the page that carries them.

Built

We built the peer-support platform for people with cancer, and the moderation system that runs in it.

Kept apart

A person joins one of two communities, patients and survivors, or family and friends. The two do not appear to one another anywhere, and the rule runs through the product rather than sitting on the screens.

Moderation

Moderation works on intent rather than a banned-word list, and every flag goes to a moderator on the client's team. Software does not act on an account on its own.

Records

Consent is recorded with the exact wording shown at the time. A person can export their data. Retention runs to the periods the client sets, and every change made in the admin portal is written to an audit log.

Read the case →
§ 04 · The way in

The Safeguarding Systems Review.

A fixed-price, fixed-length review of your platform against your own policy. It is a new engagement and it stands on its own. You get deliverables, not activities, and the report is yours.

The Safeguarding Systems Review
Euro · €7,500
Sterling · £6,500
Dollars · $8,500

Each price is fixed, plus VAT where it applies.
Ten working days from complete access.

What you get
A policy to system matrix. Every clause of your policy against what the software does today.
A roles and permissions matrix. Who can do what, and who can see what, per role.
An escalation workflow. How a concern travels, who holds it, and what happens out of hours.
A data and retention map. What is held, where it sits, who else touches it, and for how long.
A risk register. What is wrong, how bad it is, and what it takes to fix.
A prioritised build backlog. The work, in the order we would do it.
A written report a trustee can read.
Yours to keep

The report is yours and you can take it to any builder. Findings do not change based on who does the fix.

What it is not
No legal opinion.
No policy authorship.
No vetting.
No live moderation.
No accessibility conformance audit.
What we need from you
Your safeguarding policy, as it stands.
Your roles, and who holds each one.
The name of your designated person, and who covers them.
Whether under-18s are in scope.
Where your organisation is established, and where your users are.

This is a systems and permissions review, not a line by line read of your code. If what you need is a deep source-code review, that is the Readiness Audit, a different engagement with a different price.

There is no safeguarding sample report yet. The sample below is from the Readiness Audit, and it is the standard our reports are written to.

Email to book a review See the standard our reports are written to →

Or write to hello@purpledecks.com. A senior engineer replies. Same day if you catch us in the morning, next working day at the latest. No hand-offs.

§ 05 · Limits

What software cannot decide, and who we will not take.

Software can carry a decision. It cannot make one. Whether a case is urgent, whether a person should be removed, what your threshold for harm is, who your designated person is: those are yours, and they belong in your policy before they belong in a product. We build what carries them, and we say so on the page rather than in the small print.

Moderation is labour

Moderation is labour, not a feature. Somebody reads the queue, and what is in the queue is the worst of what your community produces. So moderator wellbeing and supervision are design inputs here, not afterthoughts: how long a shift runs, how much a moderator sees before they choose to open something, whether the same person carries the hardest material every day, and who they escalate to when it lands badly. A tool that ignores that burns out the people your policy depends on.

Who we will not take
An organisation with nobody who owns safeguarding by name. We would be inventing the decisions the software has to enforce.

A buyer who wants the report to say the platform is fine. We write what we find.

A build where safeguarding is a phase two. It runs through the data layer, so it is not something you add later without opening the whole thing again.
What we find when we open other people's code →

Accessibility is a delivery requirement. We agree the standard, testing method and evidence for each build before work starts.

§ 07 · Common questions

The questions a board asks.

Is this safeguarding policy consultancy?

No. Your policy is yours, and it should be written with people who do that work. We take the policy you have and build the software that carries it. If the two disagree, we tell you which clauses have nothing behind them.

Do you moderate our community for us?

No. We build the tools your moderators work in: the queue, the triage, the permissions, the audit trail. The people are yours, and so are the decisions.

We are a company, not a charity. Does this still apply?

Yes. The duties follow what your service does and who uses it, not what kind of organisation you are. A commercial platform with user-to-user contact and sensitive data is in the same position.

Is this trust and safety?

Same work, different word. Trust and safety is the product term, and safeguarding is the word in the policy your board signed. We answer to the policy.

What about the Digital Services Act?

The Digital Services Act is EU law for online platforms, and whether it reaches your service is a question for your own advice. What it asks of software is the same shape as the rest of this page: notice and action routes, records, and reasons a person can be told.

Can we take the report to another builder?

Yes. The report is yours. We would rather you had an accurate one you can act on than a captive one you cannot.

What do you need from us to start?

Your policy, your roles, the name of your designated person, whether under-18s are in scope, and where you are established. Ten working days from the point where we have complete access.

Start here

Book a Safeguarding Systems Review.

A short call first, with a senior engineer rather than a sales layer. What your platform is, who uses it, what your policy says, and where you already know the gaps are. If the review is not what you need, we will say so on the call.

Email to book a review

Written by Barry Gough, Chief Technology Officer.

Published: 14 August 2026 · Last reviewed: 14 August 2026
Changelog
14 August 2026 · Published. Twelve checklist questions, the four legal frameworks described, and the Safeguarding Systems Review.
PURPLEDECKS · 53.7°N 7.8°W · IRELAND · EST. 2012 · EU · hello@purpledecks.com