Executive Read
Signal Safety / Intelligence
Jan 2021 – Feb 2024
Analysed today
Executive Safety Read · Custodial Services
Self-harm dominates the portfolio. One site's severity mix is worsening, three are improving, and one control gap needs an answer.
Signal Safety has read all 16,310 incidents across seven establishments. The position is mixed: three sites genuinely improving, one holding at an elevated level with a worsening severity composition, and a recording inconsistency that changes how the numbers should be read.
16,310
Incidents analysed
7
Establishments
38
Months of history
509
SIRS 1 & 2 events
62Portfolio Signal
ELEVATED — ACTIVE SIGNALS
Portfolio Signal — what drives the score

The Portfolio Signal is a composite index across the four evidenced predictive dimensions. It is an internal indicator, not a regulatory rating. A lower score means more active adverse signals across the estate.

Trend?Trend. Whether incident rates are heading up or down, and how reliably we can forecast next month.Rate trajectory
58
Drift?Drift. Whether any site has genuinely shifted from its normal pattern — a real, sustained change, not a noisy month.Sustained shifts
54
Cluster?Cluster. How densely the most serious incidents are concentrated — which sites carry the heaviest serious-incident load.Serious-incident concentration
66
Control integrity?Control integrity. Whether the reporting itself can be trusted — consistent recording, no sign of incidents going unlogged.Recording & reporting
49
What changed
Severity worsening
2.0→4.7%
HMP Dovegate serious-incident share has more than doubled (p<0.001). Volume stepped up in mid-2023 and has since held at that elevated level.
Discontinued
−85%
HMP Lowdham Grange volume from April 2023. Coincides with the contract transition out of Serco operation — a data discontinuity, not a safety signal.
Improving
3 sites
Doncaster, Thameside and Kilmarnock all show sustained volume decline. Doncaster's SIRS 1 count, however, remains the highest in the estate.
Three things that merit a conversation
1

The Control & Restraint recording gap

HMP Thameside records C&R injuries at 12.1% of all incidents; HMP Doncaster at 0.8%. A 15× difference is too large for population profile to explain. Either Thameside over-records or Doncaster under-records — and the answer changes Doncaster's true risk position.

CONTROL INTEGRITY
2

HMP Dovegate's worsening severity mix

Self-harm at Dovegate moved 981 → 938 → 1,298 across 2021–23. Volume has since plateaued — but its serious-incident share has more than doubled (2.0% → 4.7%, statistically significant). Stable volume is masking a genuinely worsening composition.

SEVERITY MIGRATION
3

Serious-incident concentration at Thameside

Thameside carries 37.8 SIRS 1–2 events per 1,000 incidents — the highest in the estate, and statistically clear of the lowest site. The middle five sites overlap and should be treated as comparable, not ranked.

CLUSTER
Risk regime — the estate at a glance ?Risk regime. A single plain-English status for each site, derived from its trend, drift, volatility and data quality.

Each establishment is classified into one current regime from its own trajectory, volatility and data quality — a fast read of where the estate stands before drilling into any single number.

Establishment risk map
Feature 02
Safety Reality Lens
The facts of the portfolio, stated plainly. What the data actually contains, how serious it is, and where the established quality issues sit — before any forward-looking analysis.
16,310
Total incidents recorded
41
SIRS 1 — most serious
468
SIRS 2 events
94.6%
Recorded as SIRS 4 (minor)
Key finding
SIGNAL SAFETY LENS
49.1%

Deliberate self-harm is the single largest incident category — by a wide margin.

8,011 of 16,310 recorded incidents are deliberate self-harm. Minor and serious assault combined account for 24.0%. A safety conversation that opens with assault is addressing the second-largest category first. The data does not support that order of priority.

Incident category breakdown
Serious-incident concentration — with confidence intervals
Why intervals matter. SIRS 1–2 events are rare, so a raw per-site rate is noisy. Each bar below shows the rate of serious incidents per 1,000 with its exact 95% Poisson confidence interval. Where two intervals overlap, the difference between those sites is not statistically distinguishable — it should not be read as a ranking.

Read: HMP Thameside (37.8) sits clearly above HMP Ashfield (16.2) — that gap is real. The five sites in between have overlapping intervals and should be treated as comparable. Confident site-by-site ranking of the middle group is not supported by the data.

Establishment profile
Recording quality — the Control & Restraint anomaly

HMP Thameside records Control & Restraint injuries at 12.1% of all incidents and HMP Kilmarnock at 10.5%, while HMP Doncaster records just 0.8% and HMP Dovegate 1.2%. A 10–15× spread cannot be explained by population profile alone. This is a recording-consistency question that must be resolved before the portfolio's C&R data can be compared across sites.

Predictive Intelligence · Feature 03
Predictive Lenses
Seven forward-looking lenses on the same data — Trend, Drift, Cluster, Control Failure, Precursor, Severity Migration and the Cluster Model. Every claim is tested against a baseline and reported with its limitations. The combined per-site warning state is on the Signal Stack page.
In plain terms — what this page is telling you READ ME FIRST
Most of the estate is stable, improving or analytically explainable. HMP Dovegate is the site where the warning signals align.
What this page does

This page looks forward, not back. It takes the same incident data and asks a sharper question: not simply "what happened?", but "where is each prison heading, what is changing underneath the headline numbers, and where might risk be building?"

The headline finding

The estate is not moving in one direction. Doncaster shows a sustained fall in volume; Thameside has reduced volume but still carries the highest serious-incident concentration; Lowdham Grange reflects a contract-transition discontinuity, not a safety change. Dovegate is the exception — volume has levelled off, but the seriousness of incidents is climbing. A simple count would call Dovegate stable. It isn't.

How to read the page

The six lenses below each test one specific thing: trend, sudden drift, serious-incident concentration, control integrity, possible precursor patterns, and whether the severity mix is worsening. The Signal Stack then combines them.

The honesty note

Signal Safety does not predict that a specific serious incident will happen — the data cannot support that, and the product says so. It shows where conditions are worsening early, with every claim tested, qualified and shown with its confidence.

A single warning sign may be noise. Several warning signs lining up at one site is different — and right now, only Dovegate does that, with five of six signals active.
The seven lenses in detail
Trend?Trend. Guesses next month's incident count for a site, like a weather forecast. Works where there's volume and a clear direction.Rate forecasting EVIDENCED
Drift?Drift. Spots the exact month a site genuinely changed — a real shift, not a noisy month — and dates it.Change-point detection EVIDENCED
Cluster?Cluster. Finds which site has the most serious incidents packed in — and is honest where sites are too close to rank.Serious concentration EVIDENCED
Control Failure?Control Failure. Checks the reporting can be trusted — that a quiet site is genuinely safer, not just under-recording.Reporting integrity PARTIAL
Precursor?Precursor. Maps the portfolio against the recognised five-phase prison deterioration cascade — and shows which phases the data can see.Deterioration cascade PARTIAL — DATA
Severity Migration?Severity Migration. Spots when a site's total volume is steady but the mix is shifting toward more serious incidents.Composition shift EVIDENCED
Cluster Model?Cluster-to-Outcome Model. Tests whether several warning signals occurring together predict a worse outcome the following period. A synthesis tool, not a single lens.Cluster-to-outcome METHOD
Method. A trend-aware forecasting model (Holt linear smoothing) projects next-month self-harm volume per site. Each forecast is backtested with rolling one-step-ahead prediction over the last 8 months and scored against a naïve "same as last month" baseline. Skill % is how much the model beats that baseline. A negative score means the naïve baseline wins — and we say so.

HMP Dovegate

SKILL +27%
76self-harm incidents forecast · next month
95% band 46–106. Model materially beats naïve here — clear trend, high volume.
Model confidence ?Confidence. Based on data volume, history length, backtest skill and series stability — not a vague AI score. 91 · High

HMP Doncaster

SKILL +23%
56self-harm incidents forecast · next month
95% band 24–88. Reliable forecast — the model beats naïve across the backtest window.
Model confidence 89 · High

HMP Thameside

SKILL −38%
48self-harm incidents forecast · next month
Shown for completeness only. The model does not beat naïve here — the series is too irregular to forecast reliably.
Model confidence 62 · Moderate
Dovegate self-harm — observed series & forecast

Honest scope. Rate forecasting works where there is volume and trend — Dovegate and Doncaster. It does not work everywhere, and the prototype shows the site where it fails rather than hiding it. This is forecasting of a rate, not prediction of an individual serious event.

Method. Tabular CUSUM change-point detection runs on each site's monthly incident count. It accumulates deviation from the site's own baseline and signals when a shift is sustained — not a single noisy month. Every shift below is dated. This is established statistical process control and is fully audit-defensible.
Detected change-points

What the detector can and cannot do. It identifies that a shift happened and when — with statistical confidence. It cannot identify why. HMP Lowdham Grange's downward shift from April 2023 coincides with its contract transition out of Serco operation; that context comes from the operator, not the algorithm. Signal Safety flags the shift and leaves the explanation to people who know the estate.

Method. Serious incidents (SIRS 1 and 2) are counted per site and expressed as a rate per 1,000 incidents, each with an exact 95% Poisson confidence interval. Clustering is a present-state concentration measure — it identifies where serious outcomes are densest, with honest uncertainty attached.
Highest concentration
HMP Thameside
37.8 serious incidents per 1,000 [32.1–44.2]. Statistically clear of the lowest site.
SIRS 1 outlier
HMP Kilmarnock
12 SIRS 1 events on only 1,280 incidents — the highest SIRS 1 rate relative to volume in the estate.
Method. A negative-binomial baseline models each site's expected monthly volume from its own history. Observed volume outside the 95% prediction interval is flagged. Honest limitation: monthly incident counts are highly overdispersed, so these intervals are wide — only a large, sharp departure breaks them. A gradual reporting decline is better caught by the Drift detector than by this interval check. We show both, and we show where the interval test stays silent.
Reporting fidelity — last 6 months vs expected

Why this panel is marked "partial." On this dataset the interval test flags no site in the last six months — the bands are too wide to catch anything short of a total collapse. That is a genuine finding, not a failure to look. The real control-integrity signals in this portfolio are the C&R recording gap (Reality Lens) and the dated shifts (Drift). Control Failure becomes a strong standalone feature only with site population/occupancy data, which this export does not contain.

What this lens does. Prisons rarely deteriorate at random. Research across developed-world custodial systems describes a recognised five-phase deterioration cascade — a sequence that runs from staffing strain through to systemic breakdown. Signal Safety maps a portfolio against this established pathway, and is explicit about which phases the current data can observe and which it cannot.
The five-phase deterioration cascade

Each phase tends to trigger the next. The earlier a phase is visible, the more warning it gives — which is why the missing early-phase data matters.

PHASE 1
Staffing strain
Unplanned absences and vacancies rise; experienced officers thin out.
NOT IN DATA
PHASE 2
Regime curtailment
Less time out of cell; activities and visits cancelled to hold security.
NOT IN DATA
PHASE 3
Isolation & distress
Confinement drives mental-health decline; self-harm rises.
OBSERVABLE
PHASE 4
Environmental decay
Conditions worsen; assaults and disorder begin to cluster.
OBSERVABLE
PHASE 5
Systemic breakdown
Illicit markets, drug harm and serious violence take hold.
OBSERVABLE
Observable in the current dataset — incident and severity records Not in the current dataset — requires operational feeds

The honest position. Signal Safety can currently observe phases 3–5 — the consequences of deterioration — through the incident record. It cannot yet observe phases 1–2 — the causes — because this export contains no staffing or regime data. That means the platform sees deterioration as it lands, not before. Closing that gap is the single biggest upgrade available, and it needs data, not a better algorithm.

What data would unlock true early warning

These five operational feeds are identified across the custodial research literature as the proven leading indicators of phases 1–2. With them, Signal Safety could detect deterioration before it reaches the incident record. This is the priority data request to put to the operator.

1
Unplanned staff absence rate
Daily % from the HR system.
2
Officer experience mix
Ratio of new to experienced staff.
3
Time out of cell
Daily variance from scheduled hours.
4
ACCT open-case volume
Active self-harm monitoring plans.
5
Adjudication rate
Daily formal disciplinary charges.

Why this is framed honestly. An earlier version of this lens tested a data-derived chain (minor assault preceding C&R injury). It showed a strong raw correlation but failed a trend-corrected significance test — the categories simply rise and fall together. Rather than present that as a precursor engine, Signal Safety uses the recognised cascade above and states plainly which phases it can and cannot yet see.

Method. For each site, the serious-incident share (SIRS 1–2 as a percentage of all incidents) is compared between the first and second half of its active period, and the difference is tested with a chi-square test. This catches a site where total volume looks stable but the mix is getting worse — a leading indicator that headline incident counts miss entirely.

HMP Dovegate — confirmed severity migration

p < 0.001
FIRST HALF
2.0% serious share
VOLUME
Plateaued — not rising
SECOND HALF
4.7% serious share

Dovegate's serious-incident share has more than doubled. Because total volume has plateaued, a headline-count dashboard would show this site as stable. It is not — the composition is genuinely worsening, and the shift is statistically significant.

Serious-incident share — all establishments

Honest scope. Only Dovegate clears statistical significance. Doncaster and Kilmarnock show upward movement that does not yet pass the test — they are flagged "watch," not "migrating." The detector reports the one confirmed case and does not inflate the borderline ones.

Cluster-to-Outcome Model — the synthesis engine
The idea. Real deterioration is rarely one signal moving — it is several moving together. This model goes beyond single-lens analysis: it counts how many of the six warning signals are active for a site in a given period, then tests whether that cluster of signals predicts a worse outcome the following period. It is a synthesis engine — it combines the lenses rather than adding another one.
STEP 1 · INPUT
Count active signals
For each site, each quarter, count how many of the six lenses are firing — self-harm, assault, C&R, volume, severity, drift.
STEP 2 · TEST
Compare next-period outcome
Group site-quarters by signal count, then test whether high-cluster periods are followed by a higher serious-incident rate.
STEP 3 · VERDICT
Report — pass or fail
A Mann-Whitney significance test decides whether the pattern is real. The result is shown either way.
Result on the current dataset
0–1 SIGNALS ACTIVE
26.8
Next-quarter serious-incident rate per 1,000
30 site-quarters
2 SIGNALS ACTIVE
35.0
Next-quarter serious-incident rate per 1,000
13 site-quarters
3+ SIGNALS ACTIVE
24.2
Next-quarter serious-incident rate per 1,000
15 site-quarters
NOT YET
SIGNIFICANT

On the current 38-month export, signal clustering does not reliably predict the next quarter's serious-incident rate (Mann-Whitney p = 0.55; correlation r = 0.04). With only 58 site-quarter observations across seven sites, the model does not yet have the data to confirm the pattern — and Signal Safety reports that openly rather than presenting an unproven result as a finding.

Why this is shown as a method, not a result. The engine is built, the test runs, and the analysis is real — what is missing is data, not capability. A cluster-to-outcome model needs many more site-quarters than 38 months of seven prisons can provide. Shown here transparently: the method works, the current data is too thin to confirm it, and that is stated plainly.

What makes this model go live

Two things move the Cluster-to-Outcome Model from method to confirmed capability — and neither is a better algorithm.

1
More site-quarters
A larger estate and a longer history — more establishments, 24+ further months — give the significance test the observations it needs.
2
The operational data feeds
Adding staffing, regime and ACCT signals (see Precursor) gives the model earlier, stronger inputs than incident counts alone.
Predictive Intelligence · Synthesis
Signal Stack
The six predictive lenses combined into one explainable warning state per establishment. None of the signals is decisive alone — it is the way they stack up together that matters.
How to read this. The six lenses are combined here into one warning state per establishment. Signal Safety tracks six independent weak signals — none decisive alone. When several activate together, the site moves into an elevated warning state. Every signal is individually checkable against the data: a transparent alert, not a black box.

What the Signal Stack is — and is not. It is a present-state synthesis: a transparent count of which warning signals are active for each site right now. It describes the current position. It is not, on its own, a forecast — for the forward-looking test of whether stacked signals predict a worse outcome, see the Cluster Model lens.

Predictive Intelligence · Roadmap
Signal Intake
How Signal Safety moves from describing incidents to anticipating them — by taking in the operational data and written records that sit upstream of harm. This page sets out what is live today and what is built next.
In plain terms — what this page is telling you READ ME FIRST
The predictive ceiling today is set by data, not by the model. Signal Intake is the path to lifting it.
The honest position

Every lens in Signal Safety currently reads one source — the incident record. That record is, by definition, a count of harm that has already happened. No model, however advanced, turns a lagging source into an early warning. The limit is the input.

What changes it

The genuinely predictive signal lives upstream of incidents — in staffing, regime and the written records a prison already keeps. Signal Intake is the structured way to bring that data in. It is an information and integration build, not a new algorithm.

Where the AI fits

Much of the upstream data is messy free text — investigation narratives, ACCT entries, wing logs. The language model's job is narrow and specific: read that text and convert it into structured signals. It feeds the existing statistical engine — it does not replace it.

What it is not

This page is a roadmap. Layer 1 is live. Layers 2 and 3 are designed, not yet running on this dataset. The interactive panel below is an illustration of the extraction step, not a live feature.

The prediction stays with calibrated statistics. The language model's only job is to turn what a prison already writes down into signals those statistics can use.
The three intake layers
How to read this. Signal Safety's predictive capability is built in three layers. Each is useful in its own right, and each is a prerequisite for the next. Only Layer 1 runs on the current dataset — Layers 2 and 3 are shown as designed.
● LIVE TODAY

Layer 1 — Incident data

System of record

The EHSQ incident export. Powers every lens running today — Trend, Drift, Cluster, Severity Migration. Strong at describing what has happened; lagging by nature.

Incidents Severity (SIRS) Categories
◆ THE DIFFERENTIATOR

Layer 3 — Narrative extraction

Where the language model earns its place

The richest source a prison holds is written text. The model reads that prose and emits structured early signals — converting unstructured records into variables the statistical lenses can test.

Investigation narratives ACCT entries Wing & handover logs

Why the order matters. Layer 2 is sequenced before Layer 3 deliberately. Adding staffing and regime feeds sharpens the lenses that already exist — it is the larger, lower-risk gain. Layer 3 is the higher-value, higher-effort step, and it is what finally lets the Precursor lens see the early phases of deterioration rather than only the consequences.

Designed for messy, real-world input
The realistic assumption. Operational records are not tidy. Narratives are written by different people, in different styles, with uneven detail and gaps. Signal Intake is built on the assumption that input will be incomplete and inconsistent — and to be honest about its own confidence when it is.
What it does with messy input

The model extracts what is present and ignores what is not — it never invents a signal to fill a gap. A sparse or vague record yields fewer signals, not fabricated ones. Structured feeds with missing months are flagged as incomplete rather than silently zero-filled.

How it calibrates the output

Every extracted signal carries an extraction confidence — high when the text is explicit, lower when it is implied or ambiguous. That confidence is carried downstream: a low-confidence signal contributes less weight to a lens, and the lens reports its own confidence accordingly. Thin input produces a cautious, clearly-qualified output — not a false-precise one.

The principle, carried over from the rest of the platform. The same rule that governs the lenses governs intake: the quality of the output is tied to the quality of the input, and Signal Safety states that confidence openly rather than presenting a thin signal as a firm one.

Illustrative — narrative to structured signal
This is an illustration, not a live feature. Select a sample record to see the kind of structured signals the extraction layer is designed to produce — and how a cleaner record yields more, and more confident, signals than a sparse one. Sample text is synthetic.
INPUT · UNSTRUCTURED RECORD
Select a sample record above.
EXTRACT
OUTPUT · STRUCTURED SIGNALS
Awaiting a record.

Read across the samples. The detailed narrative produces several high-confidence signals. The sparse one produces fewer, at lower confidence — and Signal Safety says so. The extracted signals are what flow into Trend, Drift and the Cluster Model; the forecast itself remains the statistical engine's job.

What Signal Intake unlocks

The intake layers do not add another lens — they give the existing lenses earlier and stronger inputs. Three concrete gains:

1
Precursor sees the early phases
Staffing and regime feeds make Phases 1–2 of the deterioration cascade observable — not just the consequences.
2
The Cluster Model gets data
Earlier, stronger inputs than incident counts alone give the synthesis engine the signal it currently lacks.
3
Forecasts move from rate to condition
Trend and Drift gain leading indicators, shifting from "where is the rate heading" toward "where are conditions degrading".
Feature 04
External Market Intelligence
The portfolio in context — and how Serco stays at the leading edge of custodial safety practice. Regulatory direction, peer performance and sector benchmarks, each translated into what it means for this estate.
Where the regulatory edge is moving
MOJ — SAFETY IN CUSTODY Dec 2024

National self-harm reaches a record 910 incidents per 1,000 prisoners

The 12 months to December 2024 recorded 79,027 self-harm incidents nationally — a 10% year-on-year rise and a new peak. The rate has climbed consistently since 2021.

Edge for Serco: this portfolio's 49.1% self-harm share tracks the national direction. Sites running well above national patterns are where proactive investment now pre-empts the regulatory scrutiny that high self-harm has triggered at peer establishments.
HMIP INSPECTION 2024/25

Inspection framework increasingly weights leading indicators & data quality

Recent HMIP inspections place growing emphasis on whether a prison's own safety data is reliable and acted upon — not only on incident counts. Sudden unexplained shifts in recorded volume now attract direct questions.

Edge for Serco: dated, evidenced explanations for every shift — exactly what Signal Safety's Drift detection produces — turn an inspection liability into a demonstration of control.
MOJ — PERFORMANCE PENALTIES 2024/25

Private operators incurred £6.1m in performance penalties in one year

Penalty frameworks are triggered by accrued points across safety, respect and purposeful-activity measures — with safety the heaviest contributor at under-performing sites.

Edge for Serco: the penalty-driving categories are precisely those Signal Safety tracks. Identifying a deteriorating site two to three quarters early is the difference between intervention and penalty.
SECTOR — POSITIVE PRACTICE 2024/25

Performance varies sharply between sites under a single operator

Across the sector, the strongest and weakest establishments frequently sit within the same operator — pointing to site-level management and reporting culture, not operator identity, as the determining variable.

Edge for Serco: Signal Safety's site-level resolution surfaces which establishments are diverging from the estate norm — so good practice at strong sites can be identified and transferred.
Portfolio vs national benchmark
This portfolio — self-harm share
49.1%
HMP Doncaster — self-harm share
66.3%
HMP Dovegate — self-harm share
58.4%
HMP Kilmarnock — self-harm share
23.6%

Doncaster and Dovegate sit materially above the portfolio average and in the range that has drawn regulatory attention at comparable peer sites. Kilmarnock's profile is markedly different — assault and C&R weighted rather than self-harm.

External Market Intelligence · Briefing
Research Briefing — Predictive Safety in Custodial Settings
A distilled view of current sector research on predictive analytics and early-warning systems in developed-world prisons — and where Signal Safety's approach already aligns with established best practice.
SECTOR RESEARCH SYNTHESIS

The custodial sector is moving from reactive monitoring to condition-based predictive intelligence.

Across the UK, US, Australia and New Zealand, prison systems are shifting away from simply recording incidents toward detecting when a facility is drifting into a high-risk state. The research consensus is clear on one point: predict the conditions, not the individual.

The shift in approach
THE OLD MODEL
Reactive incident monitoring
Count what already happened. Respond after harm. Safety data used to report, not to anticipate.
THE EMERGING MODEL
Condition-based predictive intelligence
Detect when a site's operating conditions are degrading — before the rise in violence and self-harm follows.
The five-phase deterioration cascade
Research describes a recognised sequence by which custodial environments deteriorate. Each phase tends to trigger the next — which is why detecting the earliest phases gives the most warning. This is the same cascade Signal Safety's Precursor lens maps the portfolio against.
PHASE 1
Staffing strain
Unplanned absences and vacancies rise; experience thins.
PHASE 2
Regime curtailment
Less time out of cell; activities and visits cancelled.
PHASE 3
Isolation & distress
Confinement drives mental-health decline; self-harm rises.
PHASE 4
Environmental decay
Conditions worsen; assaults and disorder cluster.
PHASE 5
Systemic breakdown
Illicit markets, drug harm and serious violence take hold.
The proven leading indicators
Staff absence rate
Unplanned absences force regime restrictions — the primary upstream driver of systemic risk.
HIGHLY EVIDENCED
Officer experience mix
Inexperienced staff misread tension, raising escalations and use-of-force incidents.
HIGHLY EVIDENCED
Time out of cell
Prolonged lockdowns cause sensory deprivation and spike acute self-harm rates.
HIGHLY EVIDENCED
ACCT open-case volume
Active self-harm monitoring plans show the baseline distress load on a unit.
HIGHLY EVIDENCED
Adjudication rate
Rising disciplinary charges signal a shift from dynamic to adversarial control.
HIGHLY EVIDENCED
Wing noise & temperature
High ambient noise and heat are physiological stressors that lower aggression thresholds.
MODERATE EVIDENCE
What is safe to model — and what to avoid

Safe and defensible

  • Site-level risk states — flagging when a facility's conditions are degrading.
  • Drift and trend detection — statistical process control on incident counts.
  • Behavioural-deviation alerts — clinically framed, for support not sanction.
  • Explainable, transparent models — every alert traceable to its inputs.

Too risky — avoid

  • Individual rare-event prediction — claiming to predict a specific suicide or assault.
  • Automated decisions — segregation or categorisation without human review.
  • Demographic proxy weighting — inputs that replicate racial disparities.
  • Black-box models — outputs that cannot be explained or challenged.

The central ethical finding. Individual-level prediction in custody carries real-world harm — unjustified segregation, entrenched bias, feedback loops of over-surveillance. The research is consistent: keep prediction at the site and condition level, keep a human in every decision.

How developed-world systems compare
🇬🇧
United Kingdom
Explainable models in operational use; growing inspectorate focus on data quality and unexplained shifts.
🇺🇸
United States
Dashboard-driven alerting on housing and programme data; staff-focused early-warning systems.
🇦🇺
Australia
Risk tools under scrutiny for uneven accuracy across Indigenous cohorts — bias validation now mandated.
🇳🇴
Scandinavia / NL
Low-surveillance model — safety through design and dynamic security rather than intensive monitoring.
Where Signal Safety already aligns with best practice
Site-level, not individual
Every lens analyses establishments and conditions — never predicts a named person's behaviour.
Established statistical methods
CUSUM drift detection and Poisson concentration modelling are the methods this research names as defensible.
No rare-event overclaiming
Signal Safety explicitly does not predict individual serious incidents — exactly the research's core warning.
Transparent and explainable
Every signal is auditable and every claim shown with its test result — no black box.

The takeaway. Signal Safety's design is not a bet — it tracks the direction the custodial sector's own research is moving in. Site-level, condition-based, explainable, and honest about its limits.

Source note. This briefing distils published sector research on predictive analytics in developed-world custodial environments. Findings are summarised in Signal Safety's own words; no figures are reproduced from source material.
Feature 05
Ask Signal AI
A natural-language interface over the full evidence base — all 16,310 incidents, every analysis on this portfolio. Ask in plain English.

Ask anything about the Custodial Services portfolio.
Signal Safety answers from the full dataset and analysis.

SUGGESTED QUESTIONS
SERIOUS RISK Which site has the highest serious-incident concentration?
TREND Is self-harm rising at any establishment?
RECORDING QUALITY Why is the C&R injury rate so different across sites?
PREDICTIVE LIMITS Can Signal Safety predict a serious incident?
Workspace
Upload Data
Add a new export to extend the portfolio's longitudinal history. Any CSV or Excel export from an EHSQ system is accepted as-is.

Drop your safety data export here

CSV or Excel · Any EHSQ system · No reformatting required

What happens to your data
1

Pseudonymisation runs on your device

Identifiers are removed in the browser before anything is transmitted. The raw export never leaves your environment.

2

Analysis runs in your Azure tenancy

Tokenised data is processed against your own Azure OpenAI resource. Signal Safety never sees raw operational data.

3

Outputs stored longitudinally

Structured intelligence — not raw data — is held in your Azure Data Lake. Each upload extends the portfolio's organisational memory.

Prototype note. This is a demonstration build. Upload is simulated — no file is transmitted or processed. The intelligence shown throughout is derived from a real custodial dataset of 16,310 incidents (Jan 2021 – Feb 2024).
How it works
Architecture
How Signal Safety works in practice — an executive intelligence layer that sits above your existing safety system without replacing it. Your data stays in your environment throughout.

The executive intelligence layer — without replacing your systems

Your EHSQ system was built to record and classify incidents. Signal Safety sits above it and reads what it records — turning a system of record into executive intelligence, inside your own secure environment.

Sits above your system
No rip-and-replace. Your EHSQ system stays in place.
Inside your environment
Runs in your Azure tenancy. Your data stays yours.
Pseudonymised by design
Identifiers removed on-device before anything moves.
Powered by Azure OpenAI
Current AI capability, your approved Microsoft estate.
A fraction of the cost
Intelligence layer, not an enterprise rebuild.
How your data moves — three layers
1
Your SystemsSYSTEM OF RECORD
Legacy EHSQ system
Incidents, hazards, near misses, corrective actions, risk assessments.
Investigations & reports
Structured and narrative investigation records.
Audits & findings
Audit data, inspection findings, action logs.
CSV / EXPORT
2
Signal Processing LayerINSIDE YOUR SECURE AZURE ENVIRONMENT
Pseudonymisation cipher
Removes direct identifiers and protects sensitive fields on-device, before any analysis.
Signal Safety engine
Normalises and structures the data, applies the safety-specific taxonomy and analytical logic.
Azure OpenAI processing
Pattern recognition and analysis against your own Azure OpenAI resource.
Longitudinal memory
Structured outputs stored over time — organisational memory builds with every upload. No model training on your data.
STRUCTURED OUTPUT
3
Signal Safety IntelligenceEXECUTIVE INSIGHT & DECISION SUPPORT
Executive Read
The full position, a portfolio rating and the risks that merit a conversation.
Safety Reality Lens
The facts of the portfolio — what the data actually says, stated plainly.
Predictive Intelligence
Trend, Drift, Cluster, Control Failure, Precursor and Severity Migration — combined into a warning state.
External Market Intelligence
Regulatory direction and peer benchmarks — staying at the leading edge of safety practice.
Ask Signal AI
Natural-language interface over the full evidence base.
Signal never sees your raw data.   It never leaves your secure environment. You maintain full control throughout.
Trust & security principles

Your data stays yours

Raw data never leaves your environment at any point.

Pseudonymised by design

Sensitive identifiers are removed at source, on-device.

Azure enterprise security

Runs in your Microsoft estate. Role-based access, full audit trails.

Compliant by architecture

Meets data-residency and governance standards by design.

Transparent & auditable

Every insight is evidenced, traceable and explainable.

What it delivers
See what's changing across the estate before it becomes an incident.
Make faster, evidence-based decisions with the position stated plainly.
Give safety leaders intelligence, not just another dashboard of counts.
Use current AI capability without enterprise disruption or system replacement.
Surface honest limits, with every claim tested and shown with its confidence.
Build organisational memory that compounds with every upload.

Prototype note. This page describes the intended production architecture. The current prototype demonstrates the Intelligence layer (layer 3) using a real custodial dataset; the processing and storage layers are shown as designed.

Reference
Methodology & Honest Limits
What Signal Safety does, how each analysis is produced, and — importantly — what it does not claim.

What is evidenced

Trend — rate forecasting, backtested against a naïve baseline. Works where there is volume and a clear trend.

Drift — CUSUM change-point detection. Established statistical process control; every shift is dated and audit-defensible.

Cluster — serious incident concentration with exact Poisson confidence intervals. Overlapping intervals are presented as ties, not rankings.

What Signal Safety does not claim

It does not predict individual serious incidents. With 41 SIRS 1 events across the estate, no method can build a reliable forward model of rare events. Predictive output is rate forecasting and drift detection only.

It does not claim a working precursor engine. The candidate chain is a monitored hypothesis that failed the trend-corrected significance test.

It does not explain why a shift happened — only that it did, and when. Interpretation stays with the people who run the estate.

The narrative layer. The strongest version of precursor and root-cause analysis needs the free-text investigation narratives. This export contains only structured fields. Requesting an export with narrative fields is the single highest-value next step for the product.