Permissioned information environments with contributor-level control over visibility and retraction

NCMEC reference-sharing environments

NCMEC's reference-sharing environments are separately permissioned services for industry, nonprofit and law-enforcement participants. Their public API describes credentials, submission rights, visibility controls, feedback and retraction. A licence to fingerprinting software does not itself provide access to these collections.

Latest-state sharing and its limits

The API distinguishes read-only and read-write permissions. A submitter can restrict visibility; with no explicit grants, the default is visibility to all members, and removing the last grant restores that default. Only the submitter can retract its entries, with deletion markers available to queries; others can send positive or negative feedback. Usage guidance says there is no explicit mechanism to detect another party's visibility changes and newly gained access may require historical backfill. These are documented functions, not observed cache deletion or a universal user-appeal process.

What the records show

NCMEC reference-sharing environmentsReference recipient / local dataset — role

supplies latest-state updates for locally maintained datasets

Clients choose polling and subsets. Guide says no explicit mechanism detects others’ visibility changes; new access may need historical backfill. Visibility loss is not necessarily error correction, and no cache deletion/restoration was observed.

Reference submitter — member roleNCMEC reference-sharing environments

can restrict visibility of its own entries

No explicit grants means all members; deleting last grant restores that default. Self-only visibility is separately described. Functions are not observed decisions.

National Center for Missing & Exploited ChildrenNCMEC reference-sharing environments

issues environment-specific credentials and permissions

Published API separates read-only/read-write permissions and industry/nonprofit/law-enforcement environments; no software licence alone supplies these credentials.

Reference submitter — member roleNCMEC reference-sharing environments

alone can retract its entries through the described API

Queries can return deletion markers with submitter/entry/time. Other members can send positive/negative feedback, not adjudicate a universal appeal.

NCMEC reference-sharing environmentsReference recipient / local dataset — role

is described as informing company-policy action

NCMEC notice categories distinguish CSAM, some exploitative imagery below that threshold and predatory text. Provider removal/blocking follows company terms; not all categories are criminal findings or every environment’s contents.

Further reading

Reference hashes: permissions, retraction and an actual audit response

Read the original sources 3

What the connections say

5 relationships