Which sources are asked
Not all of them. A source is asked only when it holds the kind of thing being looked for — asking a vessel register about a person wastes the publisher's capacity and yours.
Two separate authorities have to agree before anything is called, and they cannot override each other:
- The connector states what its publisher permits. That lives in code and cannot be changed from any web form. A source whose terms forbid automated access refuses to be called whatever the database says about it.
- The registry row carries the association's own decisions: whether the source is switched on, how far it has got through review, and in what order to try it. It has the final say on everything the connector has not already refused.
Where no registry row exists, the connector's own judgement stands — so a source can never become callable merely by having its row deleted.
How each one is asked
- 12 seconds to answer, 5 to connect. A search fans out to several sources at once, and one slow publisher must not hold the whole page.
- Two retries, and only for a fault — a dropped connection, a server error. Never for an answer: a 404 means the record is not there and a 403 means we are not allowed in, and asking again changes neither while doubling the load on publishers who hand us their data for nothing.
- A source that fails is recorded and stepped over. It never takes the search down with it, and it is never quietly dropped from what you are shown.
-
Every request says who is making it. The association does not disguise itself as a browser or as anybody else, and a publisher reading its own logs can match this exactly:
UnitedPoliceAssociation/1.0 (+https://upa-int.org; research platform)
What happens to the records that come back
A record is recognised as one already seen only when it is the same record from the same source. Two sources holding a record about the same name produce two results.
Records from different sources are never combined into one person. The association does not build a profile out of fragments; it shows you what each publisher published, separately, with its name on it.
Results are ordered by how well they match, strongest first. Order is not importance and it is not certainty.
What the match labels mean
Four levels, and here is exactly what separates them:
- Identifier match
- The source’s own unique identifier matched — a notice number, an IMO number, a registration number. Strong evidence about the record itself. Still not an identification of a person.
- Strong potential match
- Several attributes agree, and the connector scored the match at 90 or above out of 100 — typically a name together with a date of birth or a nationality.
- Potential match
- Some attributes agree, scoring at least 60. This is the default for anything matched on a name.
- Weak potential match
- Loose or fuzzy agreement only, below 60. Shown rather than hidden, and flagged as weak.
None of the four confirms that a record is the person you were looking for. That is not a matter of wording: the code that asks "is this confirmed?" returns no for every level there is, and there is no fifth level that returns yes.
What an empty result does not mean
It does not mean no record exists. It means the sources that were asked, and that answered, held nothing matching. Three separate things can be true at once and each is reported beside the result:
- Sources that were not asked, because they do not hold this kind of record.
- Sources that were asked and did not answer.
- Sources that hold relevant records and that the association may not query — because the publisher forbids automated access, because the terms have not been read yet, or because no connector has been written. These are named individually, with the reason.
An empty result read as "no such record exists" is the single most likely way this service could mislead somebody. That is why the account of what was not searched sits beside the result rather than in a footnote.
What the association will not do
These are boundaries in the code, not intentions:
- It does not reach private profiles, direct messages or closed groups.
- It does not use leaked or stolen databases, whatever is in them.
- It does not work around CAPTCHA, authentication, access limits or paywalls. Where a platform's public interface is closed, the answer is to say so and link to it — not to find a way in.
- It does not scrape a site that publishes on the open web without an interface for it. A person may read such a page; the association does not harvest it.
Where the association states that a platform is closed to it, the status that platform returned to an unauthenticated request is quoted with the date it was measured. "We cannot search X" is a claim about somebody else's service, and it should be checkable.
The photograph search, specifically
It fingerprints a picture and looks for the same picture among photographs published by the sources the association indexes. A rescaled, recompressed or reformatted copy still matches.
It does not recognise faces. Two different photographs of the same person will not match, and a match is never a statement about who is in the picture.
No match means the picture is not among those fingerprinted — which is a small part of what exists. It is not evidence that a photograph has not been published anywhere.
These pages are published in ten languages. Where a translation and the English text differ, the English text is the one that was reviewed.