The new evidence identifies a funded research route and a real toolkit consultation process. It does not identify the person or organisation that supplied eSafety's encrypted-environment recommendations. This lane made no canonical case edits, outreach or public submissions.
The toolkit labelled v 4 March 2026's printed24/PDF13 places footnote29 immediately after its homomorphic-encryption item. The full list has seven items: client-side scanning, homomorphic encryption, risk-based E2EE deployment, conditional encryption limits, interventions, signal-based detection and limiting viral spread. All are framed as approaches industry should consider. Footnote34 elsewhere supports SaferAI-related investigative triage and cannot provide ancestry for this list.
The footnote29 URL points to the 61-page December2024 report Guiding principles for addressing technology-facilitated child sexual exploitation and abuse, by Anri van der Spuy, Sabine Witting, Patrick Burton, Emma Day, Sonia Livingstone and Kim R. Sylwander. The report cover and p61 citation identify a Digital Futures for Children centre publication; the LSE repository calls it a technical report. The toolkit citation instead includes Security and Safety, vol.4. That is a bibliographic discrepancy, not yet proof of an incorrectly linked document.
The report's actual relevant content is more discriminating than a keyword absence. P34 discusses offenders moving to end-to-end encrypted messaging. The toolkit accurately points to that page separately in footnote26, printed22/PDF12. P28 warns that protective interventions can enable surveillance harmful to children's rights; pp50-51 call for proportionate assessment across rights, including privacy, and consultation with technologists and other experts. No homomorphic-encryption recommendation or technical support was identified in the scoped reading or exact-phrase search. This establishes an unresolved support gap for that specific technical claim. It does not establish that the report never discusses encryption, that eSafety's claim is technically false, or that the whole list originates with the report.
The first prefix search for encrypt returned no hits, but full-word encryption found a bibliography entry and reading p34 found encrypted messaging. Prefix absence was therefore not used as evidence. The UNICEF2020 encryption paper cited at reportp57 was not read or promoted into a new origin claim.
Reportp5 identifies the research as part of Toolbox for Measuring Online Child Sexual Exploitation and Abuse, funded through REPHRAIN's fourth Strategic Funding Call. It identifies UKRI as REPHRAIN's funder. P8 says Amy Orben of Cambridge led the project and this report is work package3. The current DFC project page independently documents the publisher's account of project funding and participating institutions; it shares project ancestry with the report and is not an independent audit of the money.
The report's back cover separately acknowledges 5Rights Foundation funding of the DFC centre, describing DFC as a joint LSE/5Rights research centre. Centre support is not evidence of a report-specific earmark. No amount, disbursement, grant conditions, manuscript-approval right or publication veto was acquired.
P5 names Mariesa Nicholas, Australian e-Safety Commissioner's Office, among four independent peer reviewers, alongside Hazel Bitaña, Michael Salter and Fabio Senne. This establishes named review participation and contemporaneous institutional affiliation. It does not establish current employment, the substance of her comments, corporate endorsement, or authorship of the toolkit's encryption sentences. The six cover authors remain named authors without allocating particular passages to individuals.
The official eSafety FOI25139 / LOG118 document set contains a May2025 industry consultation chain. The consequential readable record is Document19, PDF29-31, which preserves the 5May invitation and a 16May response from an @x.com correspondent. The invitation says the toolkit had been developed since the December2024 Safety by Design CSEA workshop, using workshop insights. Its draft core-content list already includes end-to-end encryption and AI. That establishes the subject's presence in a May2025 draft outline, not the four particular recommendations or a December2024 version of those sentences.
The email identifies AttachmentA, draft core content, and AttachmentB, practical tools, seeks feedback with particular attention to B, offers marked-up written edits or a 20May online discussion, and announces another opportunity for final-draft redlines before a then-anticipated September launch. These are offered process steps, not proof every step occurred. The sender signs as eSafety's Industry Insights and Enablement Team.
X's 16May reply says it has no additional feedback and looks forward to publication. This establishes draft review access and that particular response. It does not show X supplied wording, approved the final2026 text or had no other communications. The draft attachment bodies and any comment-disposition records were not acquired. Doc13's first page was incompletely exposed by the reader, so this result relies on the repeated invitation in Doc19 rather than pretending the whole original email was read there. Redacted names were not reconstructed.
The best next record is now concrete: May2025 AttachmentA and AttachmentB, the final-draft redlines, comment dispositions, footnote29 source entry and publication clearance, held by eSafety's toolkit team. These would identify when the encrypted-environment language entered the draft, which participant suggested or amended it, and whether footnote29 was an editing error, indirect principle citation, or intended to point somewhere else. A participant-specific insertion and accepted comment would establish textual influence; a pre-existing paragraph with an editorial citation error would support ordinary drafting/citation failure instead.
For the money route, the complementary record is the REPHRAIN fourth-call award and work-package budget. That can distinguish ordinary research funding from deliverable-specific approval rights. For the reviewer route, DFC's invitation, comments and author response can distinguish access from substantive changes. Neither inquiry can be replaced by general biographies or shared affiliations.
Read/capture occurred 8September2026 America/Chicago, after midnight9SeptemberUTC. The original researchonline PDF GET returned403; no retry. The public eprints cached reader supplied scoped report text. The original FOI PDF GET timed out after20seconds; no retry. Two publisher pages were retained as original HTTP200 bodies. The three PDF reading extracts have derivative hashes in encryption-capture-manifest.json and are not represented as original PDFs.
The 5Rights launch is dated4December2024 and links a /126219/1/ file; eSafety links /126219/3/. The /1/ reader failed and was not retried. The numeric path components are recorded as different file locators, not authenticated version numbers; no byte or revision comparison is claimed. Repository metadata records deposit3December2024 and published-version status. Screenshot calls did not yield an image available for inspection here, so footnote placement and the title comparison are grounded in parsed original-page text plus repository metadata, with no visual-verification claim.
The candidate is structurally separate from case-r8. Context nodes retain existing IDs. New records use w5-enc. The toolkit label is retained literally; the exact publication day is not independently established. The fresh toolkit source is another scoped observation of the same official document, not independent corroboration of its technical assertions.
Source URLs: [Report](http[local research file] [LSE metadata](http[local research file] [DFC project](http[local research file] [5Rights launch](http[local research file] [eSafety toolkit](http[local research file] [released FOI correspondence](http[local research file]