TAKE IT DOWN Act compliance software for small platforms: what actually exists in 2026

Search for TAKE IT DOWN Act compliance software and you will get law-firm client alerts. Not products — alerts, telling you that you need a live takedown workflow on a 48-hour clock, and stopping there. There is no software category behind that phrase. There are five separate things that exist, only one of them is a takedown workflow, and one of the other four is free and covers the hardest part of the duty. Here is the honest inventory.

What the tooling has to deliverRemoval of the depiction and known identical copies within 48 hours of a valid requestFTC guidance
Exposure if it does not$53,088 per violationFTC guidance
Hash-matching bank available freeStopNCII.org — PDQ/PhotoDNA for photos, MD5 for videosStopNCII.org FAQ
Platforms already matching against it20 named industry partners, including Meta's apps, Microsoft, TikTok, Reddit, Snap, X and BlueskyStopNCII.org partners
What hash-matching does not supplyAn intake form, a 48-hour clock, or a record that you actedStopNCII.org, how it works
Notice requirement the tooling sits behindPlain-language notice of the process, clear and conspicuousFTC guidance

The Federal Trade Commission enforces Section 3 of the TAKE IT DOWN Act, effective 19 May 2026. Its business guidance states the operational requirement in one sentence: “TIDA requires covered platforms that receive a valid request to remove the content and known identical copies within 48 hours.” The same page states the consequence: platforms that violate the law “may face FTC enforcement that could result in civil penalties of $53,088 per violation.”

That sentence contains two different engineering problems. Receiving and acting on a valid request within 48 hours is a workflow problem. Finding known identical copies is a detection problem. Almost everything written about the Act addresses the first and skips the second, and the tools that exist tend to solve one or the other but not both. Sorting them by which problem they solve is the only way this inventory makes sense.

Is there such a thing as TAKE IT DOWN Act compliance software?

Not as a product category, no. A search for that exact phrase run on 3 August 2026 returned nine results: eight law-firm client alerts and one survivor-support press release. No vendor markets a product under that name, and no comparison of such products exists to be found, because there is nothing yet to compare. What exists instead is five things that each cover part of the duty:

  1. Law-firm client alerts — an accurate description of the obligation, and no implementation.
  2. StopNCII.org hash-matching — free, real, widely adopted, and aimed at the identical-copies problem rather than the intake problem.
  3. General trust and safety platforms — broad content-moderation suites, priced through a sales conversation.
  4. Building the desk yourself — a form, a timer, a log and a published policy.
  5. A hosted takedown desk — the category TrustDesk is in.

Only items 4 and 5 produce a notice-and-removal process. Item 2 is the one most operators have never heard of and the one that costs nothing.

What does the software actually have to do?

Four things, all four named in the FTC’s own business guidance rather than inferred. The platform must publish plain-language information about its notice and removal process, including how someone can submit a removal request — and per the guidance, “That notice must be clear and conspicuous.” It must accept removal requests. It must remove the reported depiction and known identical copies inside 48 hours of a valid request. And the scope is wider than photographs of real events: TIDA covers “nonconsensual intimate real photos and videos as well as ‘digital forgeries,’ such as images that were digitally created or altered using software, an app, or artificial intelligence.” A detection approach that only recognises previously-seen real photographs is not, on its own, an answer to that scope. The full list of duties, including the two most operators miss, is in the compliance checklist.

What is StopNCII.org, and does it cost anything?

StopNCII.org is a hash-sharing bank that lets a person protect their own intimate images across participating platforms without ever uploading the images anywhere. Its own description of the mechanism: “StopNCII.org will generate a hash (also known as a digital fingerprint) of the image(s)/video(s) on your device. A hash will be sent from your device, but not the image/video itself.” The bank then distributes that hash to partner platforms, which compare it against uploads. The FAQ names the algorithms outright: “Algorithms we use are PDQ/PhotoDNA for photos and MD5 for videos. They are open-sourced and are industry standard for applications like ours.” Its FAQ directs questions to an address at swgfl.org.uk.

Its industry partners page lists twenty platforms already matching against the bank, among them Facebook, Instagram, Threads, Microsoft, TikTok, Reddit, OnlyFans, Pornhub, Snap Inc., Patreon, X, Bluesky, FetLife and Depop. The same page states that Microsoft “uses validated StopNCII hashes in its Bing search engine and (as of May 2026) its hosted consumer services, including GroupMe, Teams Free, OneDrive, and Xbox.” The page carries a “Want to become a partner? Contact us” call to action and publishes no fee, no eligibility floor and no size threshold for joining. It also does not publish a price — so treat “free” as “no published cost” until you have asked them, which is a question worth an email either way.

Does joining StopNCII.org satisfy the “known identical copies” duty?

Partly, on one axis, and it does not touch the rest of the statute. Hash-matching is the right shape of tool for the identical-copies half of the sentence: identical copies are exactly what a hash finds, and the alternative for a small platform is manual search. But three limits matter, and all three are in StopNCII.org’s own material rather than in a critic’s.

First, it is survivor-initiated and forward-looking. A case starts when a person hashes their images, and step 4 is that “Participating platforms will look for matches to the hash and remove any matching images within their system(s) if it violates their intimate image abuse policy.” The removal is conditioned on the platform’s own policy; the platform is still the one deciding. TIDA’s clock, by contrast, starts on the platform’s receipt of a valid removal request and does not ask whether the platform’s policy agrees.

Second, its reach is bounded by its membership: “StopNCII.org cannot remove images from the whole internet, only the participating platforms listed on our partners page.” That is a statement about the bank’s scope, and it cuts the right way for an operator — it means joining helps you police your own service, not that it discharges an obligation somewhere else.

Third, and decisively for compliance: nothing in it is a notice-and-removal process. There is no intake form on your platform, no 48-hour timer running against a specific request, no identifying number issued to a requester, no notice back to them, and no record that you acted — and a hash bank cannot produce one, because the request never went through you. A platform that joins StopNCII.org and does nothing else has better detection and no compliance artifacts. One useful operational detail from the same FAQ: it routes anyone under 18 elsewhere — “If the image is of someone under the age of 18 – even if it is of yourself and you are now over 18 – please submit to TakeItDown” — which means your own intake form will still receive those reports and needs a route for them.

What about general trust and safety platforms?

Enterprise content-moderation suites do exist, several of them have added NCII handling, and some integrate hash banks directly. This page does not name or rank them, for one reason: their marketing pages did not serve to us when we tried to read them on 3 August 2026, and a comparison table of vendors whose own claims we could not open would be invention rather than research. What is safe to say about the category from its shape is that these are moderation platforms rather than statutory-compliance products, that pricing runs through a sales conversation rather than a page, and that a platform small enough to be reading this guide is unlikely to be the customer they are built for. If one of them is already under contract, the question to put to them is narrow: does it issue an identifying number per request and produce a per-request audit record, or only a moderation queue?

What does building it yourself involve?

A public form that anyone can file on without an account, capture of the four elements the statute requires of a valid request, an identifying number per request, a timer that starts on receipt and is visible before it expires, a removal step, notice back to the requester, and an append-only record of all of it that still exists when someone asks a year later. The four elements are not a design choice — they are enumerated in Public Law 119-12 §3(a)(1)(B) and set out field by field in the valid-request guide. The build is genuinely small. The part that is not small is the log: an evidence trail is only worth anything if it cannot be edited after the fact, which is a different storage decision from the one most teams reach for.

Which option covers which duty?

OptionPublic intake48-hour clockIdentical copiesEvidence logPublished price
Law-firm client alertNoNoNoNoHourly, on request
StopNCII.org hash-matchingNoNoYes, for hashed content on your own serviceNoNone published
Trust and safety suiteVariesVariesVariesVariesContact sales
Build it yourselfYesYesOnly what you buildOnly if append-onlyEngineering time
TrustDesk hosted deskYesYesManual, loggedYes, append-only$49/month, or $249 once

Read the table as two columns of work rather than five products. Nothing in the middle rows makes the bottom rows unnecessary, and the top two rows are not competitors at all — an alert tells you the duty exists and a hash bank helps you find copies. Neither receives a request.

What should a small platform with no budget do first?

Publish the notice, then stand up intake, then improve detection — in that order, because that is the order the FTC’s guidance puts them in and the order in which a missing piece is visible from outside. A platform with no removal notice on it is failing the requirement that is checkable by anyone with a browser, including the person about to file a complaint at the FTC’s portal. The notice text is free here, with no account, from the generator on the pricing page. Intake and the clock are the part that has to run continuously, which is what a hosted desk is for. Detection is where StopNCII.org belongs, and it costs an email.

Where TrustDesk fits

TrustDesk is item 5: a hosted NCII report intake form, a 48-hour clock on every report, and an append-only evidence log of every action the platform took. It is $249 once for the kit or $49 a month hosted, and the policy generator is free. It does not do hash-matching and this page is not the place to pretend otherwise — a platform serious about the identical-copies duty should join StopNCII.org as well, and the two sit on different halves of the same sentence in the statute. Whether to host the desk, build it, or hand the question to counsel is compared in counsel, build, or hosted desk. Whether any of this applies to your platform at all is settled in the covered-platform test, and what the FTC has done since enforcement began is in the enforcement guide.

The 48-hour requirement, the $53,088 penalty, the clear-and-conspicuous notice requirement and the digital-forgeries scope on this page are quoted from the FTC’s business guidance on complying with the Take It Down Act, read on 3 August 2026. The four elements of a valid request are in the enrolled text of Public Law 119-12 at the Government Publishing Office. Everything about hash-matching is quoted from StopNCII.org’s own how-it-works page, FAQ and industry partners list, all read the same day. TrustDesk is not affiliated with StopNCII.org, SWGfL or any platform named on this page. This is a description of what the tools do and is not legal advice about a particular platform.