Our methodology

Back to statistics

How we collect, analyze, and publish alerts to better protect citizens.

Updated: September 12, 2025

Scope

The ICU6 methodology covers citizen reports, public monitoring, and verified open-source sources.

  • Fraud, identity impersonation, phishing, fake news
  • Channels: email, SMS, social networks, web, messaging apps
  • Areas: worldwide, with a focus on FR/EU and local extensions

Data sources

Data comes from a public form, partner tools, and compliant OSINT collections.

  • Reports via ICU6.org (explicit consent)
  • Browser extensions and plugins (opt-in)
  • Open sources (institutional sites, CERT, trusted press)
  • Partner feeds compliant with GDPR / contracts

Processing pipeline

Each alert follows a standardized, traceable, versioned pipeline.

  • Ingestion & timestamping
  • Cleaning, anonymization, and normalization
  • AI analysis (categorization, risk signals, summary)
  • Consecutive human reviews (2 levels)
  • Publication to the public database / withdrawal if sensitive

AI analysis

We use audited AI models. The displayed scores are decision aids, not verdicts.

>= 90% Target precision
>= 85% Target recall
≤ €0.03 per analysis Cost ceiling (indicative)

Values are internal targets, reviewed through quality audits.

Human validation

Two volunteers review the AI analysis: an analyst, then an independent validator.

  • Fixing classification errors
  • Adding sources/evidence and risk indicators
  • Decision to publish, strengthen anonymization, or withdraw

Privacy & compliance

Data minimization, strict anonymization, and limited retention are applied by default.

  • No data sales; access is restricted and logged
  • Deletion on request and short retention periods
  • Compliance with GDPR / ePrivacy; DPIA for sensitive processing

Limits & biases

Despite our controls, some errors or biases may persist.

  • Variable quality of reports (noise, duplicates)
  • Fast-evolving threats (obsolescence)
  • Uneven coverage by country and channel

Spotted an error?

Contact us to correct a record or request a takedown.

Versioning & traceability

Each alert keeps the history of analyses, decisions, and updates.

  • Timestamps, authors, comments
  • Version numbers and diffs
  • Log of removals/re-activations

Contact us

For methodological questions, write to us via the contact form.

Response subject to volunteer availability.