Legal · ReguNow Surveillance
ReguNow Surveillance
For an authority that oversees a market: the questions the engine is built to answer, the instruction it works under, the evidence it keeps, the right of reply — and what is built today, in plain words.
Last updated · 2026-09-11
The questions an authority brings
ReguNow Surveillance is built for an authority that oversees a market, and it is shaped around the questions such an authority brings. This page says which questions, under what instruction the engine works, what its evidence is, how a right of reply fits, and how much of it is built today.
The questions below are the design: the frame the engine is built in, fixed in its plan so that a new kind of check is a versioned addition and never a redesign. They say what the engine is for, not what it does today. What it does today is narrower than the frame, and the evidence section below says exactly what.
Dark patterns in a checkout or a subscription flow — a false countdown, a basket that grows on its own, a subscription that cannot be cancelled — sit in the same frame, to be found by scripted flows in a browser we run ourselves, each step captured as evidence. That door is coming.
The questions:
- which brands are putting misleading communication into the market — ads, posts, pages and mails that could deceive a consumer.
- which listings are wrong — on a marketplace, a storefront or a social channel — an item that may not be sold at all; wrong information in the listing, such as a claim, a specification, the stated cost, the origin, a certification or a warranty that is false or unsubstantiated; an element in or on the product that is not allowed, even when the seller states it openly; or a mandatory element missing, such as a licence number, a country of origin, a warning, a standard mark or a disclaimer.
- what each brand is actually saying, everywhere — website, social, e-mail, marketplaces and partner sites, read as one picture.
Instructed only
We sweep only under a written instruction from the authority that names its scope. We never sweep on our own initiative, and we never bring an authority findings it did not ask for. That is the rule we work to, ruled and written down; nothing in the engine enforces it yet, and the rest of this section says what the engine does instead and what is still to come.
What the engine does today that bears on it: every sweep is declared before it runs — a frame that names the source and what a complete run must observe, stored with its own fingerprint and version — and a run that saw less than it expected is marked partial and records why. When runs are compared, an operator's tool refuses a partial or failed run as the baseline, and where the frame's version changed between the runs the comparison says so.
The written instruction itself is not yet a record inside the engine: a sweep does not yet carry the instruction it runs under. That record, and a seat from which an authority reads its own sweeps, are coming with the lane that keeps an authority's rows apart from a brand's.
Today, on every table the engine writes, a row belongs to a single workspace and is visible only inside it, and an authority seat is refused every row of those tables, even when that seat also belongs to the workspace. The database enforces both rules row by row, and both are tested.
A lane written on every row, with a test that a row on each side is invisible to the other, is coming. How the authority's work and a brand's are designed to sit apart is written on the method page.
See also: Method & trust
Evidence bundles, as they are built today
A capture begins with the site's own robots file. It is read first, for every host a redirect leads to, and where it says no the page is never fetched: the target is recorded as blinded, with the rule that said so, and shown as blinded rather than hidden. A robots file we could not read counts as a no.
Where the fetch is allowed, the engine keeps the exact bytes served, computes their fingerprint, asks an independent public timestamping authority for a token over that fingerprint, and seals those with a capture manifest, a custody record and a draft certificate into one archive. The parts are listed at the end of this section.
A bundle with any part missing — the timestamp, when that authority cannot be reached, is the usual one — is sealed as incomplete, names the missing part and why, and cannot be exported; a part that is present but describes other bytes is refused as well. Sealing is repeatable: the same parts sealed at the same instant give the same archive bytes on any machine, so the fingerprint an officer quotes is the fingerprint of exactly that archive. A fetch that fails outright, or a store that will not take the bytes, yields no bundle at all: the run is recorded as failed, with the reason, and nothing is sealed.
One bundle belongs to one capture. A second capture of the same page — the page unchanged — is a second run on the same declared frame, a second capture record, and a second bundle with its own fingerprint and its own door; the page's bytes are stored once and every capture of them points at that one object.
The bundle is built to be checked without trusting us: a standard timestamp tool can verify the token against the bytes, and a single changed byte fails. Which timestamping authority was used is written inside the sealed bundle, where a court can read it, and nowhere on a screen: the one screen that starts a capture today shows the address field, a state, a fingerprint, a door, the parts a bundle is missing and a reason code, never a host or a tool. The tools we fetch through are handled the same way: a path is described only as primary, secondary or tertiary, and the true tool is recorded inside the sealed bundle alone.
From an operator's command line, a capture is joined to the prior orders on record against the same seller, and the tool prints one sentence: the date of the latest prior action, whether that action is known from a press release rather than from the order itself, the date of the capture, the field it checked, and the state the operator supplies from the comparison of runs. The field is read against a rulebook a named person has reviewed; where the rulebook is unreviewed, the sentence says so and reports no finding.
Today one of the rulebooks a sweep reads is signed, by a named reviewer recorded as interim until a specialist is retained; the others are unsigned, and from those no sweep reports a finding. From the signed one, the sentence says of one required field whether the page is outside the rulebook's scope, whether the field's string is absent, or whether it is present and not yet confirmed against a register — a sentence about one field, not the end of a check.
Today a sealed bundle can be fetched only by our own administrators. The door that serves a bundle and the door that starts a capture both answer not found to everyone else — an authority seat included. The one screen that starts a capture sits inside our administrators' area, which sends anyone else to their own place first — a signed-out visitor to the sign-in page, a signed-in seat to its own console — and the screen itself refuses on the same tests the doors apply, save that one of our own administrators who belongs to no workspace classified for our internal work is told so in plain words rather than turned away. An authority's own door to the bundles made under its instruction is coming.
Every sealed bundle carries its own retention date in its custody record: three years after the case it belongs to closes, counted provisionally from the capture until the case closes. A capture under a sealed bundle cannot be deleted while the bundle stands.
This is what is built today: one page at a time, from an operator's command line or from one button on our own administrators' screen; sealed; stored, one archive for each sealing; recorded, so that a second capture of the same page is a second run on the same declared frame; and, from the command line, joined to the prior orders on record. The comparison of one run with another is a command-line tool over rows an operator writes out by hand; no capture the engine records is fed to it yet. The captures made today are our own proofs of the engine, made under no authority's instruction. The doors that take an authority's declared scope and sweep a marketplace, an ad library or a set of channels in bulk, and the queue that ranks what they find by how serious it is, are coming, in that order.
The parts:
- the page bytes — exactly what was served, kept as served.
- a hash record — the fingerprint of those bytes and the algorithm that made it.
- a capture manifest — the tool, its version, the time, the address asked for, every redirect followed and every robots decision taken on the way.
- an independent timestamp — the token, issued over the fingerprint, with the certificate chain the authority sent — so the time is not our word.
- a custody record — who ran the capture, where the bytes are stored, and the date until which they are retained.
- a draft certificate — the s.63 certificate text, pre-filled from the parts above, for the person who will sign it.
See also: Method & trust
Right of reply
The design is that a finding is not acted on until the party it concerns has been told and has had the chance to answer, and that the notice, the answer and the clock travel with the finding. Whether we give that notice before a finding is delivered, or the authority gives it after receipt, is a ruling still open; its default is that the authority gives it.
Less of that exists today than the design describes. The comparison library, given the date a notice was given, reports a listing removed after that date and before any enforcement as removed after notice, never as the effect of enforcement; but no tool of ours takes that date yet, and no record holds it, so no run has been read that way outside our own tests. A tool that takes the date is coming with the record below.
The record that holds the notice, the channel, the answer and the reply window is coming. Until it exists, the engine exports sealed bundles and no findings.
Talk to us
There is no self-serve sign-up for ReguNow Surveillance and no form to fill. An authority that wants to see the engine, or to put a written instruction to us, writes to us at the address our About page publishes.
Say which market you oversee and which of the questions above you want answered first. We will show the evidence bundle as it is built today and say plainly what is not built yet.