ODFSEC
Reporting Policy

External Reporting & Referral Policy

This policy explains how Onetrak Digital Forensics LLC handles referrals to NCMEC, law enforcement, online service providers, and other third parties when a report concerns child exploitation or unlawfully distributed content.

Effective
August 9, 2026
Last updated
August 9, 2026

1. Scope and Priority

This policy applies when the BlackBox Computer Security Research & Development Team (BBCSR&D Team) receives information that may warrant a referral outside Onetrak. It describes Onetrak's operational process; it does not create a promise that every report will be referred or acted upon and does not replace legal advice for a particular matter.

Immediate danger

ZNRC4 AIRPORT and the USA Hotline are not emergency services. If a child or any person is in immediate danger, call 911 or the appropriate local emergency or law-enforcement agency. A CyberTipline report does not replace an emergency call.

2. Suspected CSAM and Child Exploitation

Do not upload, attach, email, download, copy, retransmit, or intentionally access suspected child sexual abuse material (CSAM) to make or support a ZNRC4 AIRPORT report. Do not ask another person to obtain it. Instead, provide only lawfully available indicators such as the exact URL, platform and account identifier, UTC observation time, incident description, existing report number, and a hash already obtained through lawful and authorized means.

Onetrak may restrict access, isolate relevant systems or records, preserve authorized evidence, and escalate the matter to appropriately trained personnel. Review is limited to material that is reported to us or otherwise lawfully obtained; this policy is not a promise to monitor or search third-party services for illegal content.

Members of the public may report suspected online child exploitation directly to the NCMEC CyberTipline. If you believe an image or video depicts you when you were under 18, NCMEC also offers victim and family support resources through its CyberTipline site.

3. NCMEC Reporting

NCMEC operates the CyberTipline as the United States' centralized reporting system for suspected online child exploitation. NCMEC reviews tips and may make them available to an appropriate law-enforcement agency for possible investigation.

When Onetrak is acting as a provider subject to 18 U.S.C. § 2258A, Onetrak will report covered facts or circumstances involving apparent child sexual exploitation to the CyberTipline as soon as reasonably possible after obtaining the actual knowledge required by that law. Onetrak may also make a voluntary CyberTipline report when permitted and appropriate. This policy does not determine whether Onetrak, a customer, or another participant is a statutory provider in every situation.

A report to Onetrak is not a substitute for a direct CyberTipline or law-enforcement report. Submitting information to Onetrak does not guarantee that NCMEC or law enforcement will open or complete an investigation.

4. Preservation and Restricted Access

For a qualifying provider report made under 18 U.S.C. § 2258A, Onetrak will preserve the reported contents and reasonably accessible associated material for the period required by applicable law. The current federal rule treats a completed CyberTipline submission as a request to preserve the contents provided in the report for one year after submission. A longer period may apply when lawful, voluntarily appropriate, contractually required, or subject to a preservation request, warrant, subpoena, court order, litigation hold, or other legal duty.

Preserved material must be secured against unauthorized access and handled only by employees, agents, counsel, service providers, NCMEC, or government personnel whose access is lawful and necessary. Onetrak will use an approved secure channel for any transfer and will not send suspected CSAM through ordinary email.

5. Referrals to Third-Party Companies

Depending on the content, infrastructure, and jurisdiction involved, the BBCSR&D Team may refer a matter to a platform's trust-and-safety or abuse team, hosting provider, content-delivery network, registrar, registry, internet or email service provider, payment provider, search provider, employer, affected organization, regulator, or law-enforcement agency.

Before a referral, the team should verify the recipient and its designated reporting channel, disclose only information reasonably necessary for the stated purpose, avoid alerting a suspected offender when that could endanger a person or investigation, and preserve a record of what was sent, when, by whom, and under what authority. Suspected CSAM must be sent only to a recipient legally authorized to receive it and through an approved secure method.

Each recipient controls its own review, preservation, disclosure, account action, takedown, and response timing. Onetrak cannot compel a private company, NCMEC, regulator, or law-enforcement agency to act.

7. Minimum Referral Package

When lawful and available, an external referral should contain:

  • the ZNRC4 AIRPORT case or tracking identifier;
  • a concise, factual allegation and the relevant content category;
  • exact URLs, hostnames, account identifiers, service names, and UTC timestamps;
  • lawfully obtained hashes, headers, logs, or screenshots that do not reproduce prohibited content;
  • the reporter's contact information, relationship to the matter, and authority to submit;
  • known risk to a child or other person, without speculation;
  • preservation or chain-of-custody information when relevant; and
  • the requested action, while recognizing that the recipient makes the final decision.

Do not collect additional unlawful content to make a package more complete. If a recipient requires material that cannot lawfully or securely be transmitted, the matter must be escalated to Onetrak counsel or the appropriate authority before transfer.

8. Confidentiality, Records, and Reporter Updates

Onetrak may limit details about a referral when disclosure could identify a victim, expose sensitive evidence, interfere with an investigation, violate law or contract, reveal protected security information, or create a safety risk. Reporter anonymity or confidentiality cannot be guaranteed when identifying information is required by law, legal process, provider procedure, or the needs of an authorized investigation.

The BBCSR&D Team should record the referral recipient, channel, date and time, submitting team member, data categories disclosed, legal or operational basis, acknowledgement or reference number, and any requested follow-up. Receipt of an external reference number confirms only that the recipient accepted the submission, not that it validated the allegation or will take action.

See the Report Outcome Notice for the factors that affect review, referral, and resolution.

9. Official Resources

10. Contact

Onetrak Digital Forensics LLC
5900 Balcones Dr., STE 23284
Austin, TX 78731
United States
administration@odfsec.org +1 918-297-8696 (USA Hotline)