Detailed research note

Provider disclosure and an attributed Australian lead

Part of the research through 9 September 2026. This dated note preserves its original findings; later developments are discussed in the synthesis and linked profiles.

9 September 2026. Root provider lane closed. [Tilak declaration, filed 13 June 2025](http[local research file] republished by Ars Technica. Original custody and hash: tilak-capture.json. Retained PDF is 61 pages, 6,815,888 bytes, SHA256 bbd7cfa2059c35fd203ce7202b1bb6072d7bbfe6412ea061ffdf7aa58d2183a5.

Findings and locators

The sworn declaration supports a motion for alternative service on Sol Ecom, not a Briver compliance certification. Paragraphs18–23 report subpoenas and responsive contact records from Cloudflare, Namecheap and former registrar Name.com. Paragraph29 reports Google's June6,2025 production. Paragraphs24–30 describe subsequent notices and correspondence. These are counsel's sworn accounts; actual subpoena and production instruments are not attached in this read scope. They establish a reported disclosure route, not provider shutdown instructions.

Exhibit6 reproduces December2024–January2025 correspondence. A respondent associated by counsel with drawnudes.io claims eSafety requirements and compliance, including alleged January2025 legislation (PDF19,21). The respondent seeks written SF requirements and discusses territorial restrictions (PDF19,22). This is a respondent's account and offer, not independent verification of Australian law, successful compliance, eSafety approval, or regulator-to-regulator coordination. No specific technical restriction or issuing provider is demonstrated by that exchange.

The complete declaration and exhibit do not supply Briver's required report or a named provider's takedown command. The city-announced cooperation and this separate subpoena route must retain separate source ancestry.

Read scope

Root read the complete six-page declaration through the web reader, including the filed stamp, allegations about service attempts and signature, and complete Exhibit6 (PDF18–23) through retained extraction. Root visually checked PDF1,4,6,21,22. PDF21's visually underlined eSafety reference has no URI annotation on that page in the retained PDF. That is not a finding about external links everywhere in the bundle. All61 pages were extracted for search; corporate-registration/profile/site exhibits outside those twelve pages were not substantively reviewed, and no whole-bundle-read claim is made. Residential addresses, private contact identifiers and unrelated personal profile details are not reproduced here.

Bounded acquisition log

Root searched seven queries: "Briver" "registrar"; "Sol Ecom" "registry"; site.sfcityattorney.org "deepfake" "registrars"; site.sf.gov "deepfake" "registrars"; "San Francisco" "registries" "June 2, 2025"; "Chiu" "Briver" "cooperate"; "San Francisco" "registrars" "Namecheap" deepfake. Most results were unrelated, including different Briver entities. They were not identity evidence. The named-company query was a probe, not prior proof of involvement.

The complete main body of Ars Technica's16August2024 article was read. It supplies a lead concerning the complaint's requested provider relief; root did not acquire the linked complaint or promote a report of requested relief into an order. The worker independently found the actual Tilak declaration; root's web reader and one ordinary originalGET succeeded. Search and retained-record read only. No provider takedown record was recovered in this bounded lane; that is not proof no provider acted. The separate worker filings.md records the court-gateway limitation and Briver-record search. No further acquisition branch was opened before the forest review.