9 September 2026. Bounded acquisition complete. No harmful-content database was accessed, no underlying propaganda was downloaded, and no registration, outreach or payment was made. GIFCT's own rules and the comparative rights/evaluation literature are separate lanes.
The strongest new relationship is concrete corporate and financial dependence: Tech Against Terrorism (TAT) is implemented by Online Harms Foundation (OHF); OHF's filed controlling entity is QuantSpark Limited; OHF also reports receiving loans from, being invoiced by, and owing money to QuantSpark. A separate official Canadian award directly funds development of the Terrorist Content Analytics Platform (TCAP). Neither record gives a donor a demonstrated right to order an individual content classification.
Why this actor belongs in the case
The Australian DIS Standard2024 section6 definition of known pro-terror material, Note2, names TAT and GIFCT as examples of independent counterterrorism-expert organisations whose tools may be used to verify material. This supplies the observed legal connection. It is not a requirement to buy from TAT, a finding about every TCAP record, or incorporation of the entirety of TCAP's evolving taxonomy into Australian law. Retained ../esafety-service-wave-2026-09-09/legal-dis-standard.pdf, PDF13/printed9, text independently reread in this pass; original SHA256 afe30304b7094509de84a1845534b346a48c4fc2f2f07e163fd47fd040ce487d.
Legal identity and control
TAT's [About page](http[local research file] Governance and Funding sections, identifies OHF as implementer and describes TAT as independent and not-for-profit. Its privacy policy also names OHF and company11656320, although the page retains a QuantSpark label in its introductory wording. The legal-identity inference is therefore tied to the company number, not just a similar name.
[Companies House's OHF overview](http[local research file] lists an active private company limited by guarantee without share capital, using the Limited exemption; incorporation2November2018; previous name QuantSpark Foundation until11May2021. This pass establishes a company, not registered-charity status. The project website's earlier launch account is a different event from this legal entity's incorporation.
The [current PSC record](http[local research file] names QuantSpark Limited, company10304694, notified2November2018, with 75% or more of voting rights and the right to appoint or remove directors. This is voting/director-appointment control in a guarantee company; it is not ownership of75% of nonexistent share capital. The public filing is a company-reported legal record, and Companies House states it does not check the accuracy of filed information. No donor voting right or instruction about a particular TCAP item is established by it.
Money with distinct legal and accounting states
OHF's unaudited financial statements for the year ended31July2025 were approved and filed28July2026. All8 retained PDF pages were visually read. The directors elected not to file the income-and-expenditure account. Consequently, this filing does not provide total annual income or a donor-by-donor allocation against which to verify TAT's stated balance of government and industry funding.
| Relationship | Exact disclosed state | Limit |
|---|---|---|
| QuantSpark → OHF consultancy | FY2025 invoices GBP913,015; comparative FY2024 GBP2,160,943 | Invoiced services, not proved cash payment or a TCAP-only expense. |
| OHF → QuantSpark outstanding amount | GBP1,554,927 owed at31July2025; comparative GBP1,287,711 | Related-party balance. The note does not disaggregate consultancy payable versus loans; do not label the entire balance a loan. |
| QuantSpark → OHF finance | Going-concern note says OHF relies on loans received from QuantSpark, a related party. QuantSpark's director confirmed amounts would not be recalled in the next12months. | Dated support statement, not perpetual funding, an item-level veto or evidence that all liabilities were forgiven. |
| Public Safety Canada → TCAP Phase2 | 20September2022 announcement: commitment of up to CAD1.9million over three years, through the Community Resilience Fund. | Project-specific commitment ceiling; not proof all money was paid. |
| Public Safety Canada → TCAP creation | Same announcement retrospectively says approximately CAD1million was provided in June2019 through the fund to create TCAP. | Official reported provision, not independently obtained bank receipt or the underlying executed agreement. |
Accounts source: [filed FY2025 accounts](http[local research file] retained tat-accounts-2025.pdf. PDF3/printed1 identifies unaudited small-company treatment, omitted income/expenditure statement and approval date; PDF4/printed2 note1.2 gives going-concern support; PDF7/printed5 note7 gives related-party invoices and outstanding amounts. Note7 expressly calls QuantSpark a corporate director and related party through common control and a common director. It does not identify the particular services, underlying subcontract terms or project cost centre. These financial statements also use accrual accounting, not a cash-receipts presentation.
Canadian source: [Public Safety Canada20September2022 announcement](http[local research file] complete substantive news-release body read. Phase2 is described as expanding content types/platform coverage and helping develop a moderation tool for smaller companies. CAD reflects the Canadian public-programme currency context; no conversion is performed. The award names TAT, while the recipient legal-entity bridge comes from the separate TAT/Companies House records; the executed agreement naming its legal signatory was not acquired.
TAT's About page says bespoke services to technology companies generate funding and GIFCT contributes to its work. It also says funding comes equally from democratic governments and industry. This is an organisational self-description with no accounting period or reconciliation on the page, not an independently verified50:50 financial ratio. It does not establish that TCAP alerts themselves are paid, that a particular government funds a particular classification, or that the UN owns OHF.
What is verified, by whom, and under which published rules
The public [classification-and-verification page](http[local research file] says in-house experts assess both source and content against the inclusion policy, using source-channel assessment and an intelligence assessment of likely organisational production. The full policy requires a form supplying name, work email, organisation and position. This is an explicit access boundary. The form was not submitted, and no alternate access path was attempted.
The [tiered inclusion policy](http[local research file] is version-sensitive: it announces a July2023 expansion. It separates threat-to-life, crisis, designation and promotional tiers, with law-enforcement alerting confined to threat-to-life and live crisis content. Promotional content goes beyond officially produced material. A fifth tier for material not necessarily illegal remains labelled forthcoming on the page read; that is not proof it is operational now. Its references to an Oversight Board describe a safeguard prospectively, without a charter, appointment or adjudication record in this source. Footer2026 does not establish a2026 policy revision.
[Tier3's designation policy](http[local research file] follows selected UN/EU and national designation authorities, then applies TAT's consensus and offline/online threat assessments. It permits an expert assessment of splinter-group continuity when a designation effort fails, and includes supporter-produced material using official branding under an imitation rule. Thus the published process contains private judgement as well as legal-list inputs. The stated entity review interval is six months. Removal from all followed lists triggers removal from the inclusion policy; a major governmental-status change can also justify delisting. Historical material predating delisting continues to be alerted. This is an entity-level policy, not a demonstrated correction rule for a falsely labelled item. The displayed designation matrices were not visually audited and are not adopted here as current legal lists.
Provider choice and an actual reported correction
The [Year2 transparency report](http[local research file] covering December2021–November2022, describes human verification followed by automated alerts. Platforms retain exclusive moderation discretion and can decline further notifications. Registered companies can dispute classification; TAT says it responds within seven working days. It reports36 disputes, all concerning automated online/offline-status errors:35 URL statuses were manually changed and one remained active. These are not36 terrorist-label reversals. An Academic Advisory Board was still being established at report-writing. Locators: PDF28–33, especially29–32;31–32 visually checked.
The same report records18,995 submitted URLs,10,174 alerts to57 companies and82% subsequently offline (PDF5). Its monitor checks URL availability (PDF29). This is TAT's reported operational observation, not independently demonstrated causation, a measure of adjudicated illegality or proof that each disappearance was a provider removal caused by the alert.
The [legacy FAQ](http[local research file] describes vetted company, academic and civil-society access, free smaller-platform/academic use and no content downloading. It excludes government database access, while allowing threat-to-life escalation to police. However, its future references to2021/2022 development make it unsuitable as sole evidence of current access rights. Database access, receipt of an emergency alert and financial sponsorship remain different relationships.
The [current TAT product page](http[local research file] describes human analysts, automated email alerts and ongoing URL-status monitoring. Its marketing language about automated removal does not establish an independent power to delete another provider's content or override the narrower workflow evidence. No live service, API or customer configuration was inspected.
Limits and concrete next records
The evidence establishes corporate voting/appointment control, related-party financial reliance, a project-specific government commitment, private classification judgement and an operating provider-dispute process. It does not establish donor-to-item commands, paid inclusion incentives or proven arbitrary classification. Nor does the presence of appeals language demonstrate independent, implemented adjudication.
The decisive missing records are: OHF–QuantSpark consultancy and loan agreements plus project allocation ledgers; the executed Canadian contribution agreements and disbursement reports; the current TCAP verification policy and oversight charter/appointment decisions; a redacted item-classification appeal and its downstream correction notices, including hash withdrawal, recipient notification and provider reconsideration. OHF/QuantSpark hold the first family, Public Safety Canada and the grant recipient the second, and TAT plus participating providers the third. The filed balance cannot supply those terms. No further pursuit of these records starts before the root's forest review.
Capture and reading scope
All captures belong to this wave; tat-captures.json retains exactURLs, acquisition timestamps, byte sizes and SHA256. Website/company captures are original response HTML, not screenshots or reconstructions. The Companies House web-reader account link failed on a redirected cached URL; one ordinary public GET of the official filing link succeeded. Page2's web reader likewise missed cache; ordinary GET succeeded. These were transport/reader failures, not bypassed account gates.
Core original hashes: accounts2025 134815173e7eec20b1be9171b23da097d0db5b3eb9d5ffa7fe71e5b0c8c38ab9; PSC HTML 3ff455a4ac892cd12666f06583e52d9a7a5cc9e7c61075fa4055eeaeffbc5147; Canada announcement 4f830f539c2839ae245a4c04e29f2b8a41f072f58e2feee0a6b27faea4cfb619; Year2report 8e41db80e8a9619aa5fccf252b7a831508e34c82c02c924f58c68e79ee5c8d40. Other hashes are in the manifest.
Read scope: Companies House overview/PSC records complete substantive sections; filing-history entries identifying latest accounts/incorporation only. About page Governance/Funding and identity passages; privacy-page identity passage in indexed-primary excerpt only. Canada2022 announcement complete substantive body. FAQ substantive questions, with explicit legacy-date caveat. Inclusion policy substantive body; designation policy narrative criteria, imitation, splinter and delisting sections, excluding matrix accuracy. Verification public summary and form boundary only. Current TCAP product-page narrative. Accounts2025 all8pages visually inspected; its embedded text layer was empty. Year2report text PDF5–6,17,28–33; visual31–32 only; remaining40-page contents unreviewed. The incorporation bundle was captured as a58-page original but is image-only and not substantively read; no articles-of-association claim relies on it. Original capture does not imply content knowledge.
No private database or underlying extremist media was accessed, copied or tested. This packet is frozen at the funding/control-to-verification breakpoint for the combined forest.