Supplier Safeguarding Statement

Last updated: 2 August 2026

Chapter is a careers-education platform and game for UK secondary-age students (11-18), used in school and at home. This statement sets out how we keep children safe in and around our products and how we support schools' statutory safeguarding duties. It is written to answer school due-diligence against Keeping Children Safe in Education (KCSIE), the DfE's Generative AI product safety standards, the ICO Children's Code and the Online Safety Act 2023.

1. Our commitment and named safeguarding lead

The best interests of the child are the primary consideration in how we design and run the service. We operate a zero-tolerance approach to child sexual abuse and exploitation and to content that could seriously harm a child.

  • Company Safeguarding Lead: Luke Samson (luke@chapterapp.co.uk) - the single point of contact for any safeguarding concern, holding a current Enhanced DBS certificate.
  • Staff whose roles involve contact with children, moderation tooling or children's data are subject to appropriate vetting, including DBS checks at the level required by their role. Access to children's data is role-based and least-privilege.

2. Content moderation

Chat, user-generated content, usernames and AI inputs and outputs are moderated through a layered pipeline: a local denylist and word filter, then AI moderation, configured fail-closed - if moderation is unavailable, content is rejected rather than allowed through. A database-level safeguarding trigger independently detects defined harm categories (for example self-harm indicators, threats of violence, grooming patterns) and records blocked attempts for human review by trained staff.

Every user can report a message, user or AI response and can block and mute. Clear, age-appropriate community rules are enforced consistently.

3. Generative AI guardrails

Chappy (our AI assistant) exists for careers exploration, guidance and skills development - a clearly educational purpose, aligned to the DfE's Generative AI: product safety standards:

  • Input and output moderation prevents harmful or inappropriate content.
  • Anti-jailbreak system prompts, robust authentication, rate limiting and prompt-injection defences.
  • Children's data is never used to train AI models - excluded under our AI providers' commercial API terms.
  • No anthropomorphic deception: Chappy is clearly presented as an AI assistant, not a person, and AI responses are labelled as machine-generated. A human professional remains responsible for any careers decision.
  • No personalised advertising to children, no dark patterns, no engagement-prolonging design.

4. Escalation to your Designated Safeguarding Lead

Where a concern involves a specific, identifiable child in the school context, we escalate to the school's DSL without delay, sharing what is necessary for the school to fulfil its KCSIE duties - the DSL decides on referrals to children's social care or the police. Following the DfE's Sharing nudes and semi-nudes guidance, if an indecent image of a child surfaces our staff will not view, copy, share, store or delete it; we preserve the report and escalate to the DSL immediately.

Serious illegal content is reported to the appropriate authorities, including the National Crime Agency and the Internet Watch Foundation, with content and account information preserved for investigation.

5. Designed against the KCSIE four areas of risk

  • Content - layered AI and human moderation of all content surfaces (Section 2).
  • Contact - no real-name exposure in public spaces, report and block tools, moderated usernames.
  • Conduct - enforced community rules, anti-bullying moderation, and the nudes-handling protocol above.
  • Commerce - no personalised advertising to children.

In line with the ICO Children's Code we apply high-privacy defaults, data minimisation, geolocation off by default and age-appropriate transparency.

6. Filtering, monitoring and your network

Chapter runs inside the school's filtered and monitored environment and never requires schools to weaken or bypass their filters. Because a network filter cannot inspect dynamic AI-generated chat, that safety burden sits with our in-product moderation (Sections 2-3). A network requirements list is available for school IT on request.

7. Incidents and breaches

We operate a combined safeguarding and security incident-response process. As your data processor we notify the affected school without undue delay - target within 24-48 hours of becoming aware of a personal-data breach - with the information your school needs to meet its 72-hour ICO deadline. See the Data Processing Agreement and Security overview.

8. Contact

Safeguarding concerns: luke@chapterapp.co.uk. General and data protection: hello@chapterschools.com. For anything urgent involving immediate risk to a child, contact the police on 999.