Self-harm dominates the portfolio. One site's severity mix is
worsening, three are improving, and one control gap needs an answer.
Signal Safety has read all 16,310 incidents across seven
establishments. The position is mixed: three sites genuinely improving, one
holding at an elevated level with a worsening severity composition, and a
recording inconsistency that changes how the numbers should be read.
16,310
Incidents analysed
7
Establishments
38
Months of history
509
SIRS 1 & 2 events
62Portfolio Signal
ELEVATED — ACTIVE SIGNALS
Portfolio Signal — what drives the score
The Portfolio Signal is a composite index across the four evidenced predictive
dimensions. It is an internal indicator, not a regulatory rating. A lower score
means more active adverse signals across the estate.
Trend?Trend. Whether incident rates are heading up or down, and how reliably we can forecast next month.Rate trajectory
58
Drift?Drift. Whether any site has genuinely shifted from its normal pattern — a real, sustained change, not a noisy month.Sustained shifts
54
Cluster?Cluster. How densely the most serious incidents are concentrated — which sites carry the heaviest serious-incident load.Serious-incident concentration
66
Control integrity?Control integrity. Whether the reporting itself can be trusted — consistent recording, no sign of incidents going unlogged.Recording & reporting
49
What changed
Severity worsening
2.0→4.7%
HMP Dovegate serious-incident share has more than doubled
(p<0.001). Volume stepped up in mid-2023 and has since held at that
elevated level.
Discontinued
−85%
HMP Lowdham Grange volume from April 2023. Coincides with the
contract transition out of Serco operation — a data discontinuity, not a
safety signal.
Improving
3 sites
Doncaster, Thameside and Kilmarnock all show sustained volume
decline. Doncaster's SIRS 1 count, however, remains the highest in the
estate.
Three things that merit a conversation
1
The Control & Restraint recording gap
HMP Thameside records C&R injuries at 12.1% of all incidents; HMP
Doncaster at 0.8%. A 15× difference is too large for population profile to
explain. Either Thameside over-records or Doncaster under-records — and the
answer changes Doncaster's true risk position.
CONTROL INTEGRITY
2
HMP Dovegate's worsening severity mix
Self-harm at Dovegate moved 981 → 938 → 1,298 across 2021–23. Volume has
since plateaued — but its serious-incident share has more than doubled
(2.0% → 4.7%, statistically significant). Stable volume is masking a
genuinely worsening composition.
SEVERITY MIGRATION
3
Serious-incident concentration at Thameside
Thameside carries 37.8 SIRS 1–2 events per 1,000 incidents — the highest in
the estate, and statistically clear of the lowest site. The middle five
sites overlap and should be treated as comparable, not ranked.
CLUSTER
Risk regime — the estate at a glance
?Risk regime. A single plain-English status for each site, derived from its trend, drift, volatility and data quality.
Each establishment is classified into one current regime from its own
trajectory, volatility and data quality — a fast read of where the estate
stands before drilling into any single number.
Establishment risk map
Feature 02
Safety Reality Lens
The facts of the portfolio, stated plainly. What the data
actually contains, how serious it is, and where the established quality issues
sit — before any forward-looking analysis.
16,310
Total incidents recorded
41
SIRS 1 — most serious
468
SIRS 2 events
94.6%
Recorded as SIRS 4 (minor)
Key finding
SIGNAL SAFETY LENS
49.1%
Deliberate self-harm is
the single largest incident category — by a wide margin.
8,011 of 16,310
recorded incidents are deliberate self-harm. Minor and serious assault combined
account for 24.0%. A safety conversation that opens with assault is addressing
the second-largest category first. The data does not support that order of
priority.
Incident category breakdown
Serious-incident concentration — with confidence intervals
Why intervals matter. SIRS 1–2 events are rare, so a raw per-site rate is
noisy. Each bar below shows the rate of serious incidents per 1,000 with its exact
95% Poisson confidence interval. Where two intervals overlap, the difference
between those sites is not statistically distinguishable — it should not be
read as a ranking.
Read: HMP Thameside (37.8) sits clearly above HMP Ashfield (16.2) — that
gap is real. The five sites in between have overlapping intervals and should be
treated as comparable. Confident site-by-site ranking of the middle group is
not supported by the data.
Establishment profile
Recording quality — the Control & Restraint anomaly
HMP Thameside records Control & Restraint injuries at 12.1% of all
incidents and HMP Kilmarnock at 10.5%, while HMP Doncaster records just
0.8% and HMP Dovegate 1.2%. A 10–15× spread cannot be explained by
population profile alone. This is a recording-consistency question that must be
resolved before the portfolio's C&R data can be compared across sites.
Predictive Intelligence · Feature 03
Predictive Lenses
Seven forward-looking lenses on the same data — Trend, Drift,
Cluster, Control Failure, Precursor, Severity Migration and the Cluster Model.
Every claim is tested against a baseline and reported with its limitations. The
combined per-site warning state is on the Signal Stack page.
In plain terms — what this page is telling youREAD ME FIRST
Most of the estate is stable, improving or analytically
explainable. HMP Dovegate is the site where the warning signals align.
What this page does
This page looks forward, not back. It takes the same incident data and asks
a sharper question: not simply "what happened?", but "where is each prison
heading, what is changing underneath the headline numbers, and where might
risk be building?"
The headline finding
The estate is not moving in one direction. Doncaster shows a sustained fall
in volume; Thameside has reduced volume but still carries the highest
serious-incident concentration; Lowdham Grange reflects a contract-transition
discontinuity, not a safety change. Dovegate is the exception — volume has
levelled off, but the seriousness of incidents is climbing. A simple
count would call Dovegate stable. It isn't.
How to read the page
The six lenses below each test one specific thing: trend, sudden drift,
serious-incident concentration, control integrity, possible precursor
patterns, and whether the severity mix is worsening. The Signal Stack then
combines them.
The honesty note
Signal Safety does not predict that a specific serious incident will
happen — the data cannot support that, and the product says so. It shows
where conditions are worsening early, with every claim tested, qualified and
shown with its confidence.
A single warning sign may be noise. Several warning signs lining up at one site
is different — and right now, only Dovegate does that, with five of six signals
active.
The seven lenses in detail
Trend?Trend. Guesses next month's incident count for a site, like a weather forecast. Works where there's volume and a clear direction.Rate forecastingEVIDENCED
Drift?Drift. Spots the exact month a site genuinely changed — a real shift, not a noisy month — and dates it.Change-point detectionEVIDENCED
Cluster?Cluster. Finds which site has the most serious incidents packed in — and is honest where sites are too close to rank.Serious concentrationEVIDENCED
Control Failure?Control Failure. Checks the reporting can be trusted — that a quiet site is genuinely safer, not just under-recording.Reporting integrityPARTIAL
Precursor?Precursor. Maps the portfolio against the recognised five-phase prison deterioration cascade — and shows which phases the data can see.Deterioration cascadePARTIAL — DATA
Severity Migration?Severity Migration. Spots when a site's total volume is steady but the mix is shifting toward more serious incidents.Composition shiftEVIDENCED
Cluster Model?Cluster-to-Outcome Model. Tests whether several warning signals occurring together predict a worse outcome the following period. A synthesis tool, not a single lens.Cluster-to-outcomeMETHOD
Method. A trend-aware forecasting model (Holt linear smoothing) projects
next-month self-harm volume per site. Each forecast is backtested with rolling
one-step-ahead prediction over the last 8 months and scored against a naïve
"same as last month" baseline. Skill % is how much the model beats that
baseline. A negative score means the naïve baseline wins — and we say so.
HMP Dovegate
SKILL +27%
76self-harm incidents forecast · next month
95% band 46–106. Model materially beats
naïve here — clear trend, high volume.
Model confidence
?Confidence. Based on data volume, history length, backtest skill and series stability — not a vague AI score.91 · High
HMP Doncaster
SKILL +23%
56self-harm incidents forecast · next month
95% band 24–88. Reliable forecast — the
model beats naïve across the backtest window.
Model confidence89 · High
HMP Thameside
SKILL −38%
48self-harm incidents forecast · next month
Shown for completeness only. The model does not beat naïve here —
the series is too irregular to forecast reliably.
Model confidence62 · Moderate
Dovegate self-harm — observed series & forecast
Honest scope. Rate forecasting works where there is volume and trend —
Dovegate and Doncaster. It does not work everywhere, and the prototype shows the
site where it fails rather than hiding it. This is forecasting of a rate, not
prediction of an individual serious event.
Method. Tabular CUSUM change-point detection runs on each site's monthly
incident count. It accumulates deviation from the site's own baseline and signals
when a shift is sustained — not a single noisy month. Every shift below is dated.
This is established statistical process control and is fully audit-defensible.
Detected change-points
What the detector can and cannot do. It identifies that a shift
happened and when — with statistical confidence. It cannot identify
why. HMP Lowdham Grange's downward shift from April 2023 coincides with
its contract transition out of Serco operation; that context comes from the
operator, not the algorithm. Signal Safety flags the shift and leaves the
explanation to people who know the estate.
Method. Serious incidents (SIRS 1 and 2) are counted per site and expressed
as a rate per 1,000 incidents, each with an exact 95% Poisson confidence interval.
Clustering is a present-state concentration measure — it identifies where serious
outcomes are densest, with honest uncertainty attached.
Highest concentration
HMP Thameside
37.8 serious incidents per 1,000 [32.1–44.2]. Statistically
clear of the lowest site.
SIRS 1 outlier
HMP Kilmarnock
12 SIRS 1 events on only 1,280 incidents — the highest SIRS 1
rate relative to volume in the estate.
Method. A negative-binomial baseline models each site's expected monthly
volume from its own history. Observed volume outside the 95% prediction interval
is flagged. Honest limitation: monthly incident counts are highly
overdispersed, so these intervals are wide — only a large, sharp departure breaks
them. A gradual reporting decline is better caught by the Drift detector than by
this interval check. We show both, and we show where the interval test stays
silent.
Reporting fidelity — last 6 months vs expected
Why this panel is marked "partial." On this dataset the interval test
flags no site in the last six months — the bands are too wide to catch
anything short of a total collapse. That is a genuine finding, not a failure to
look. The real control-integrity signals in this portfolio are the C&R
recording gap (Reality Lens) and the dated shifts (Drift). Control Failure
becomes a strong standalone feature only with site population/occupancy data,
which this export does not contain.
What this lens does. Prisons rarely deteriorate at random. Research across
developed-world custodial systems describes a recognised five-phase
deterioration cascade — a sequence that runs from staffing strain through to
systemic breakdown. Signal Safety maps a portfolio against this established
pathway, and is explicit about which phases the current data can observe and which
it cannot.
The five-phase deterioration cascade
Each phase tends to trigger the next. The earlier a phase is visible, the more
warning it gives — which is why the missing early-phase data matters.
PHASE 1
Staffing strain
Unplanned absences and vacancies rise; experienced
officers thin out.
NOT IN DATA
→
PHASE 2
Regime curtailment
Less time out of cell; activities and visits cancelled
to hold security.
Conditions worsen; assaults and disorder begin to
cluster.
OBSERVABLE
→
PHASE 5
Systemic breakdown
Illicit markets, drug harm and serious violence
take hold.
OBSERVABLE
Observable in the current dataset
— incident and severity records Not in the current dataset —
requires operational feeds
The honest position. Signal Safety can currently observe phases 3–5 — the
consequences of deterioration — through the incident record. It cannot yet
observe phases 1–2 — the causes — because this export contains no staffing
or regime data. That means the platform sees deterioration as it lands, not
before. Closing that gap is the single biggest upgrade available, and it needs
data, not a better algorithm.
What data would unlock true early warning
These five operational feeds are identified across the custodial research
literature as the proven leading indicators of phases 1–2. With them, Signal
Safety could detect deterioration before it reaches the incident record.
This is the priority data request to put to the operator.
1
Unplanned staff absence rate
Daily % from the HR system.
2
Officer experience mix
Ratio of new to experienced staff.
3
Time out of cell
Daily variance from scheduled hours.
4
ACCT open-case volume
Active self-harm monitoring plans.
5
Adjudication rate
Daily formal disciplinary charges.
Why this is framed honestly. An earlier version of this lens tested a
data-derived chain (minor assault preceding C&R injury). It showed a strong
raw correlation but failed a trend-corrected significance test — the categories
simply rise and fall together. Rather than present that as a precursor engine,
Signal Safety uses the recognised cascade above and states plainly which phases
it can and cannot yet see.
Method. For each site, the serious-incident share (SIRS 1–2 as a percentage
of all incidents) is compared between the first and second half of its active
period, and the difference is tested with a chi-square test. This catches a site
where total volume looks stable but the mix is getting worse — a leading
indicator that headline incident counts miss entirely.
HMP Dovegate — confirmed severity migration
p < 0.001
FIRST HALF
2.0% serious share
→
VOLUME
Plateaued — not rising
→
SECOND HALF
4.7% serious share
Dovegate's serious-incident share has more than doubled. Because total
volume has plateaued, a headline-count dashboard would show this site as stable.
It is not — the composition is genuinely worsening, and the shift is
statistically significant.
Serious-incident share — all establishments
Honest scope. Only Dovegate clears statistical significance. Doncaster and
Kilmarnock show upward movement that does not yet pass the test — they are
flagged "watch," not "migrating." The detector reports the one confirmed case
and does not inflate the borderline ones.
Cluster-to-Outcome Model — the synthesis engine
The idea. Real deterioration is rarely one signal moving — it is several
moving together. This model goes beyond single-lens analysis: it counts how many
of the six warning signals are active for a site in a given period, then tests
whether that cluster of signals predicts a worse outcome the following
period. It is a synthesis engine — it combines the lenses rather than adding
another one.
STEP 1 · INPUT
Count active signals
For each site, each quarter, count how many of the six
lenses are firing — self-harm, assault, C&R, volume, severity, drift.
→
STEP 2 · TEST
Compare next-period outcome
Group site-quarters by signal count, then test whether
high-cluster periods are followed by a higher serious-incident rate.
→
STEP 3 · VERDICT
Report — pass or fail
A Mann-Whitney significance test decides whether the
pattern is real. The result is shown either way.
Result on the current dataset
0–1 SIGNALS ACTIVE
26.8
Next-quarter serious-incident rate per 1,000
30 site-quarters
2 SIGNALS ACTIVE
35.0
Next-quarter serious-incident rate per 1,000
13 site-quarters
3+ SIGNALS ACTIVE
24.2
Next-quarter serious-incident rate per 1,000
15 site-quarters
NOT YET SIGNIFICANT
On the current 38-month export, signal clustering does not reliably
predict the next quarter's serious-incident rate (Mann-Whitney p = 0.55;
correlation r = 0.04). With only 58 site-quarter observations across
seven sites, the model does not yet have the data to confirm the pattern —
and Signal Safety reports that openly rather than presenting an unproven
result as a finding.
Why this is shown as a method, not a result. The engine is built, the test
runs, and the analysis is real — what is missing is data, not capability. A
cluster-to-outcome model needs many more site-quarters than 38 months of seven
prisons can provide. Shown here transparently: the method works, the current
data is too thin to confirm it, and that is stated plainly.
What makes this model go live
Two things move the Cluster-to-Outcome Model from method to confirmed
capability — and neither is a better algorithm.
1
More site-quarters
A larger estate and a longer history — more establishments,
24+ further months — give the significance test the observations it needs.
2
The operational data feeds
Adding staffing, regime and ACCT signals (see Precursor)
gives the model earlier, stronger inputs than incident counts alone.
Predictive Intelligence · Synthesis
Signal Stack
The six predictive lenses combined into one explainable
warning state per establishment. None of the signals is decisive alone — it is
the way they stack up together that matters.
How to read this. The six lenses are combined here into one warning state
per establishment. Signal Safety tracks six independent weak signals — none
decisive alone. When several activate together, the site moves into an
elevated warning state. Every signal is individually checkable against the
data: a transparent alert, not a black box.
What the Signal Stack is — and is not. It is a present-state synthesis: a
transparent count of which warning signals are active for each site right now. It
describes the current position. It is not, on its own, a forecast — for the
forward-looking test of whether stacked signals predict a worse outcome, see the
Cluster Model lens.
Predictive Intelligence · Roadmap
Signal Intake
How Signal Safety moves from describing incidents to
anticipating them — by taking in the operational data and written records that
sit upstream of harm. This page sets out what is live today and what is built
next.
In plain terms — what this page is telling youREAD ME FIRST
The predictive ceiling today is set by data, not
by the model. Signal Intake is the path to lifting it.
The honest position
Every lens in Signal Safety currently reads one source — the incident
record. That record is, by definition, a count of harm that has already
happened. No model, however advanced, turns a lagging source into an early
warning. The limit is the input.
What changes it
The genuinely predictive signal lives upstream of incidents — in
staffing, regime and the written records a prison already keeps. Signal
Intake is the structured way to bring that data in. It is an information
and integration build, not a new algorithm.
Where the AI fits
Much of the upstream data is messy free text — investigation narratives,
ACCT entries, wing logs. The language model's job is narrow and specific:
read that text and convert it into structured signals. It feeds the
existing statistical engine — it does not replace it.
What it is not
This page is a roadmap. Layer 1 is live. Layers 2 and 3 are
designed, not yet running on this dataset. The interactive panel below is
an illustration of the extraction step, not a live feature.
The prediction stays with calibrated statistics. The language model's only
job is to turn what a prison already writes down into signals those
statistics can use.
The three intake layers
How to read this. Signal Safety's predictive capability is built in three
layers. Each is useful in its own right, and each is a prerequisite for the next.
Only Layer 1 runs on the current dataset — Layers 2 and 3 are shown as designed.
● LIVE TODAY
Layer 1 — Incident data
System of record
The EHSQ incident export. Powers every lens running today — Trend, Drift,
Cluster, Severity Migration. Strong at describing what has happened; lagging
by nature.
IncidentsSeverity (SIRS)Categories
→
◷ NEXT — STRUCTURED INTAKE
Layer 2 — Operational feeds
Plumbing, not algorithm
A defined intake for the numeric feeds that sit upstream of incidents. Each
arrives on a known schema and cadence and joins straight into the existing
statistical engine — no model change needed.
Staff absenceOfficer mixTime out of cellACCT open casesAdjudications
→
◆ THE DIFFERENTIATOR
Layer 3 — Narrative extraction
Where the language model earns its place
The richest source a prison holds is written text. The model reads that
prose and emits structured early signals — converting unstructured records
into variables the statistical lenses can test.
Why the order matters. Layer 2 is sequenced before Layer 3 deliberately.
Adding staffing and regime feeds sharpens the lenses that already exist — it is
the larger, lower-risk gain. Layer 3 is the higher-value, higher-effort step,
and it is what finally lets the Precursor lens see the early phases of
deterioration rather than only the consequences.
Designed for messy, real-world input
The realistic assumption. Operational records are not tidy. Narratives are
written by different people, in different styles, with uneven detail and gaps.
Signal Intake is built on the assumption that input will be incomplete and
inconsistent — and to be honest about its own confidence when it is.
What it does with messy input
The model extracts what is present and ignores what is not — it never invents
a signal to fill a gap. A sparse or vague record yields fewer signals, not
fabricated ones. Structured feeds with missing months are flagged as
incomplete rather than silently zero-filled.
How it calibrates the output
Every extracted signal carries an extraction confidence — high when
the text is explicit, lower when it is implied or ambiguous. That confidence
is carried downstream: a low-confidence signal contributes less weight to a
lens, and the lens reports its own confidence accordingly. Thin input
produces a cautious, clearly-qualified output — not a false-precise one.
The principle, carried over from the rest of the platform. The same rule
that governs the lenses governs intake: the quality of the output is tied to the
quality of the input, and Signal Safety states that confidence openly rather
than presenting a thin signal as a firm one.
Illustrative — narrative to structured signal
This is an illustration, not a live feature. Select a sample record to see
the kind of structured signals the extraction layer is designed to produce — and
how a cleaner record yields more, and more confident, signals than a sparse one.
Sample text is synthetic.
INPUT · UNSTRUCTURED RECORD
Select a sample record above.
EXTRACT
OUTPUT · STRUCTURED SIGNALS
Awaiting a record.
Read across the samples. The detailed narrative produces several
high-confidence signals. The sparse one produces fewer, at lower confidence —
and Signal Safety says so. The extracted signals are what flow into Trend, Drift
and the Cluster Model; the forecast itself remains the statistical engine's job.
What Signal Intake unlocks
The intake layers do not add another lens — they give the existing lenses
earlier and stronger inputs. Three concrete gains:
1
Precursor sees the early phases
Staffing and regime feeds make Phases 1–2 of the
deterioration cascade observable — not just the consequences.
2
The Cluster Model gets data
Earlier, stronger inputs than incident counts alone give
the synthesis engine the signal it currently lacks.
3
Forecasts move from rate to condition
Trend and Drift gain leading indicators, shifting from
"where is the rate heading" toward "where are conditions degrading".
Feature 04
External Market Intelligence
The portfolio in context — and how Serco stays at the leading
edge of custodial safety practice. Regulatory direction, peer performance and
sector benchmarks, each translated into what it means for this estate.
Where the regulatory edge is moving
MOJ — SAFETY IN CUSTODYDec 2024
National self-harm reaches a record 910 incidents per 1,000 prisoners
The 12 months to December 2024 recorded 79,027 self-harm incidents nationally
— a 10% year-on-year rise and a new peak. The rate has climbed consistently
since 2021.
Edge for Serco: this portfolio's 49.1% self-harm
share tracks the national direction. Sites running well above national
patterns are where proactive investment now pre-empts the regulatory scrutiny
that high self-harm has triggered at peer establishments.
HMIP INSPECTION2024/25
Inspection framework increasingly weights leading indicators & data quality
Recent HMIP inspections place growing emphasis on whether a prison's own
safety data is reliable and acted upon — not only on incident counts. Sudden
unexplained shifts in recorded volume now attract direct questions.
Edge for Serco: dated, evidenced explanations for
every shift — exactly what Signal Safety's Drift detection produces — turn an
inspection liability into a demonstration of control.
MOJ — PERFORMANCE PENALTIES2024/25
Private operators incurred £6.1m in performance penalties in one year
Penalty frameworks are triggered by accrued points across safety, respect and
purposeful-activity measures — with safety the heaviest contributor at
under-performing sites.
Edge for Serco: the penalty-driving categories are
precisely those Signal Safety tracks. Identifying a deteriorating site two to
three quarters early is the difference between intervention and penalty.
SECTOR — POSITIVE PRACTICE2024/25
Performance varies sharply between sites under a single operator
Across the sector, the strongest and weakest establishments frequently sit
within the same operator — pointing to site-level management and reporting
culture, not operator identity, as the determining variable.
Edge for Serco: Signal Safety's site-level
resolution surfaces which establishments are diverging from the estate norm —
so good practice at strong sites can be identified and transferred.
Portfolio vs national benchmark
This portfolio — self-harm share
49.1%
HMP Doncaster — self-harm share
66.3%
HMP Dovegate — self-harm share
58.4%
HMP Kilmarnock — self-harm share
23.6%
Doncaster and Dovegate sit materially above the portfolio average and in the
range that has drawn regulatory attention at comparable peer sites. Kilmarnock's
profile is markedly different — assault and C&R weighted rather than
self-harm.
External Market Intelligence · Briefing
Research Briefing — Predictive Safety in Custodial Settings
A distilled view of current sector research on predictive
analytics and early-warning systems in developed-world prisons — and where Signal
Safety's approach already aligns with established best practice.
SECTOR RESEARCH SYNTHESIS
The custodial sector is moving from reactive monitoring to
condition-based predictive intelligence.
Across the UK, US, Australia and New Zealand, prison systems are shifting away
from simply recording incidents toward detecting when a facility is drifting into
a high-risk state. The research consensus is clear on one point: predict the
conditions, not the individual.
The shift in approach
THE OLD MODEL
Reactive incident monitoring
Count what already happened. Respond after harm. Safety data
used to report, not to anticipate.
→
THE EMERGING MODEL
Condition-based predictive intelligence
Detect when a site's operating conditions are degrading —
before the rise in violence and self-harm follows.
The five-phase deterioration cascade
Research describes a recognised sequence by which custodial environments
deteriorate. Each phase tends to trigger the next — which is why detecting the
earliest phases gives the most warning. This is the same cascade Signal Safety's
Precursor lens maps the portfolio against.
PHASE 1
Staffing strain
Unplanned absences and vacancies rise; experience thins.
→
PHASE 2
Regime curtailment
Less time out of cell; activities and visits cancelled.
Illicit markets, drug harm and serious violence take hold.
The proven leading indicators
Staff absence rate
Unplanned absences force regime restrictions — the primary
upstream driver of systemic risk.
HIGHLY EVIDENCED
Officer experience mix
Inexperienced staff misread tension, raising escalations and
use-of-force incidents.
HIGHLY EVIDENCED
Time out of cell
Prolonged lockdowns cause sensory deprivation and spike acute
self-harm rates.
HIGHLY EVIDENCED
ACCT open-case volume
Active self-harm monitoring plans show the baseline distress
load on a unit.
HIGHLY EVIDENCED
Adjudication rate
Rising disciplinary charges signal a shift from dynamic to
adversarial control.
HIGHLY EVIDENCED
Wing noise & temperature
High ambient noise and heat are physiological stressors that
lower aggression thresholds.
MODERATE EVIDENCE
What is safe to model — and what to avoid
Safe and defensible
Site-level risk states — flagging when a facility's conditions are
degrading.
Drift and trend detection — statistical process control on
incident counts.
Behavioural-deviation alerts — clinically framed, for support not
sanction.
Explainable, transparent models — every alert traceable to its
inputs.
Too risky — avoid
Individual rare-event prediction — claiming to predict a specific
suicide or assault.
Automated decisions — segregation or categorisation without human
review.
Demographic proxy weighting — inputs that replicate racial
disparities.
Black-box models — outputs that cannot be explained or
challenged.
The central ethical finding. Individual-level prediction in custody
carries real-world harm — unjustified segregation, entrenched bias, feedback
loops of over-surveillance. The research is consistent: keep prediction at the
site and condition level, keep a human in every decision.
How developed-world systems compare
🇬🇧
United Kingdom
Explainable models in operational use; growing inspectorate
focus on data quality and unexplained shifts.
🇺🇸
United States
Dashboard-driven alerting on housing and programme data;
staff-focused early-warning systems.
🇦🇺
Australia
Risk tools under scrutiny for uneven accuracy across
Indigenous cohorts — bias validation now mandated.
🇳🇴
Scandinavia / NL
Low-surveillance model — safety through design and dynamic
security rather than intensive monitoring.
Where Signal Safety already aligns with best practice
Site-level, not individual
Every lens analyses establishments and conditions — never
predicts a named person's behaviour.
Established statistical methods
CUSUM drift detection and Poisson concentration modelling
are the methods this research names as defensible.
No rare-event overclaiming
Signal Safety explicitly does not predict individual
serious incidents — exactly the research's core warning.
Transparent and explainable
Every signal is auditable and every claim shown with its
test result — no black box.
The takeaway. Signal Safety's design is not a bet — it tracks the
direction the custodial sector's own research is moving in. Site-level,
condition-based, explainable, and honest about its limits.
Source note. This briefing distils published sector research on predictive
analytics in developed-world custodial environments. Findings are summarised in
Signal Safety's own words; no figures are reproduced from source material.
Feature 05
Ask Signal AI
A natural-language interface over the full evidence base —
all 16,310 incidents, every analysis on this portfolio. Ask in plain English.
Ask anything about the Custodial Services portfolio.
Signal Safety answers from the full dataset and analysis.
SUGGESTED QUESTIONS
SERIOUS RISKWhich site has the highest serious-incident concentration?
TRENDIs self-harm rising at any establishment?
RECORDING QUALITYWhy is the C&R injury rate so different across sites?
PREDICTIVE LIMITSCan Signal Safety predict a serious incident?
Workspace
Upload Data
Add a new export to extend the portfolio's longitudinal
history. Any CSV or Excel export from an EHSQ system is accepted as-is.
Drop your safety data export here
CSV or Excel · Any EHSQ system · No reformatting required
What happens to your data
1
Pseudonymisation runs on your device
Identifiers are removed in the browser before anything is transmitted. The
raw export never leaves your environment.
2
Analysis runs in your Azure tenancy
Tokenised data is processed against your own Azure OpenAI resource. Signal
Safety never sees raw operational data.
3
Outputs stored longitudinally
Structured intelligence — not raw data — is held in your Azure Data Lake.
Each upload extends the portfolio's organisational memory.
Prototype note. This is a demonstration build. Upload is simulated — no file
is transmitted or processed. The intelligence shown throughout is derived from a
real custodial dataset of 16,310 incidents (Jan 2021 – Feb 2024).
How it works
Architecture
How Signal Safety works in practice — an executive
intelligence layer that sits above your existing safety system without replacing
it. Your data stays in your environment throughout.
The executive intelligence layer — without replacing your systems
Your EHSQ system was built to record and classify incidents. Signal Safety sits
above it and reads what it records — turning a system of record into executive
intelligence, inside your own secure environment.
Sits above your system
No rip-and-replace. Your EHSQ system stays in place.
Inside your environment
Runs in your Azure tenancy. Your data stays yours.
Pseudonymised by design
Identifiers removed on-device before anything moves.
Powered by Azure OpenAI
Current AI capability, your approved Microsoft estate.
A fraction of the cost
Intelligence layer, not an enterprise rebuild.
How your data moves — three layers
1
Your SystemsSYSTEM OF RECORD
Legacy EHSQ system
Incidents, hazards, near misses, corrective actions,
risk assessments.
Investigations & reports
Structured and narrative investigation records.
Audits & findings
Audit data, inspection findings, action logs.
CSV / EXPORT
2
Signal Processing LayerINSIDE YOUR SECURE AZURE ENVIRONMENT
Pseudonymisation cipher
Removes direct identifiers and protects sensitive fields
on-device, before any analysis.
Signal Safety engine
Normalises and structures the data, applies the
safety-specific taxonomy and analytical logic.
Azure OpenAI processing
Pattern recognition and analysis against your own Azure
OpenAI resource.
Longitudinal memory
Structured outputs stored over time — organisational
memory builds with every upload. No model training on your data.
STRUCTURED OUTPUT
3
Signal Safety IntelligenceEXECUTIVE INSIGHT & DECISION SUPPORT
Executive Read
The full position, a portfolio rating and the risks
that merit a conversation.
Safety Reality Lens
The facts of the portfolio — what the data actually
says, stated plainly.
Predictive Intelligence
Trend, Drift, Cluster, Control Failure, Precursor and
Severity Migration — combined into a warning state.
External Market Intelligence
Regulatory direction and peer benchmarks — staying at
the leading edge of safety practice.
Ask Signal AI
Natural-language interface over the full evidence base.
Signal never sees your raw data. It never leaves your secure environment. You maintain full control throughout.
Trust & security principles
Your data stays yours
Raw data never leaves your environment at any point.
Pseudonymised by design
Sensitive identifiers are removed at source, on-device.
Azure enterprise security
Runs in your Microsoft estate. Role-based access, full audit trails.
Compliant by architecture
Meets data-residency and governance standards by design.
Transparent & auditable
Every insight is evidenced, traceable and explainable.
What it delivers
See what's changing across the estate before it becomes an incident.
Make faster, evidence-based decisions with the position stated plainly.
Give safety leaders intelligence, not just another dashboard of counts.
Use current AI capability without enterprise disruption or system replacement.
Surface honest limits, with every claim tested and shown with its confidence.
Build organisational memory that compounds with every upload.
Prototype note. This page describes the intended production architecture.
The current prototype demonstrates the Intelligence layer (layer 3) using a real
custodial dataset; the processing and storage layers are shown as designed.
Reference
Methodology & Honest Limits
What Signal Safety does, how each analysis is produced, and —
importantly — what it does not claim.
What is evidenced
Trend — rate forecasting, backtested against a
naïve baseline. Works where there is volume and a clear trend.
Drift — CUSUM
change-point detection. Established statistical process control; every shift is
dated and audit-defensible.
Cluster — serious
incident concentration with exact Poisson confidence intervals. Overlapping
intervals are presented as ties, not rankings.
What Signal Safety does not claim
It does not predict individual serious
incidents. With 41 SIRS 1 events across the estate, no method can build a
reliable forward model of rare events. Predictive output is rate forecasting and
drift detection only.
It does not claim a
working precursor engine. The candidate chain is a monitored hypothesis that
failed the trend-corrected significance test.
It does not explain
why a shift happened — only that it did, and when. Interpretation stays
with the people who run the estate.
The narrative layer. The strongest version of precursor and root-cause
analysis needs the free-text investigation narratives. This export contains only
structured fields. Requesting an export with narrative fields is the single
highest-value next step for the product.