9September2026. Root acquisition closed. Public administrative documentation separates NCMEC's access administration, submitting members' rights, clients' local datasets and platform actions. No live hash/media data, credentials, endpoint, application or account was used.
Software rights do not supply reference-data rights
The [NCMEC Hash Sharing v2 documentation](http[local research file] visibly last updated5November2025, requires NCMEC-issued credentials and separate read-only/read-write permissions in each environment. Its table distinguishes industry, nonprofit and law-enforcement services, with separate CSAM/exploitative and generative-AI entries; a label is not a legal finding about every entry. Submitting members can limit which other members see their entries. No explicit grants means access for all members; deleting the last grant restores that default. Self-only access is separately described. These are documented functions, not an observed denial or a public dataset.
Only the submitting member can retract its entries through the described API. Recipients' queries can return a deletion marker identifying submitter, entry and timestamp. Other members can provide affirmative/negative fingerprint feedback; example reason IDs are expressly synthetic. This is not an adjudicated appeal or a promise to remove an account restriction. Read scopes: sections2,4.6,7.5,7.9,7.10 completely; other sections were discovery/search context only. No operational examples were executed.
The [Usage Recommendations](http[local research file] make the client side consequential. Clients maintain their own datasets and choose polling frequency; the API supplies the latest state using update times, rather than a historical event log. Owners can withdraw visibility, and the guide expressly says the API has no explicit mechanism for detecting others' visibility changes. New grants can require historical backfill. This differs from a published retraction marker: loss of access is not automatically evidence an entry was judged wrong. The guide does not establish a particular client's cache deletion, duty to erase, or reversal of past moderation. Full substantive page read; date matches the main document footer.
Review and removal: a specific public record
NCMEC's [2025 CyberTipline data page](http[local research file] Hash Sharing and Removing Content, describes repeated staff review and reports12.1million-plus hashes shared with78 voluntary ESP participants as of31December2025. Its notice programme distinguishes CSAM, exploitative imagery of identified victims that may fall below the CSAM threshold, and predatory text. These notification categories must not all become criminal-content findings or be assigned to every reference environment. Removal/blocking is described as based on company terms. Counts and response times are NCMEC's reported outcomes; no individual notification or client log was acquired. Root read those sections and adjacent response context, not the entire page or downloadable outcome tables.
The [12April2024 Concentrix attestation](http[local research file] all3pages read, identifies an April2023 RFP and13July2023 audit contract. It covers538,922 unique files, with two reviews each against the stated federal definition, conducted16October–8December2023. It reports59 exceptions:50 judged not to meet that definition;5 cartoons/anime also not meeting it;2 unplayable videos;2 with uncertain depicted age. These are the auditor's classifications, not our inspection of content or59 identical kinds of error.
Page3 says Concentrix notified NCMEC and was told that NCMEC removed all59 in less than five business days. This is a concrete auditor-reported correction notification, not an independently observed deletion log or proof of recipient-wide correction. Reported99.99% agreement concerns that reviewed list/version; it is not all NCMEC environments or future datasets. The entire audit contract, workpapers and downstream acknowledgements remain unacquired.
NCMEC's [15April2024 announcement](http[local research file] full substantive body read, says the audit was donated, valued at$300,000. This is a reported in-kind contribution and recipient valuation, not a cash payment. The announcement also describes systems/training supplied by NCMEC and the auditor's independent content decisions; its own promotional conclusion is not additional independent assurance. No new corporate genealogy or moderator/subject identification was undertaken.
A named agreement trail, through reproduced judicial text
A [25November2025 Rosales opinion reproduced by FindLaw](http[local research file] cases01-23-00876-CR/00877-CR, describes separate Microsoft→NCMEC→Dropbox software sublicensing, database-access agreements and a signatures MOU. The reproduced text says the MOU grants restricted royalty-free access and an agreement to attempt detection; database clauses retain voluntary access and disclaim NCMEC direction over use and responsibility for other nonprofits' entries. The court rejected government-agency attribution on that record, while assuming NCMEC's status for argument. It also records that actual use of that software in the contested search was not proved. This is not a universal judgment that collaborations cannot exercise influence.
Custody matters: root read the reproduced analysis123–196, relevant footnotes and conclusion through the reader. It is not the official original, full contracts, or current Dropbox terms. The available official link was for a distinct July2025 opinion; reader failure followed by one GET403 closed that route. FindLaw GET likewise returned an error while its reader worked. No original or signed agreement is claimed. A later attempt to retain serialized reader output hit Windows command-length limits before creating a file; tool history/read locators, rather than a fabricated original, preserve this scope. No further recovery route was opened.
Synthesis and exact remaining gap
There are several administrators, not just one database owner: NCMEC grants environment access; a submitter controls the visibility/retraction of its entries; a recipient chooses its local subset, polling and effects. Review can produce a documented correction, yet feed withdrawal and a restored item remain different steps. The reproduced litigation shows why signed access rights, general detection commitments and case-specific direction need separate evidence. Main licence/TC sublicence findings are in the sibling lanes and are not inferred here.
ncmec-captures.json records five successful primary originals, the FindLaw error response and the closed official-opinion access observation. HTML derivatives/section extracts and PDF text are labelled. Root checked disk hashes after capture and after final scope edits. Source-provided examples are not real entries. Four focused NCMEC discovery queries and three court-identity queries were used; unhelpful same-name cases were discarded. No data endpoint, status check, application, private system, outreach or paid source was accessed. Acquisition is stopped for combined review and forest; the case and ZIP remain unchanged.