A threat of violence in a children’s game and a threat of violence in an adult shooter may contain the same words. Treat them identically and you have a problem. Treat them differently and you need something more demanding than a list of forbidden phrases: context, a policy, and a way to make the distinction thousands of times without losing your nerve.
Glen Wise, Cinder’s chief executive, uses that gaming example to explain his business. The company sells software and expert services that connect detection, investigation, human review and enforcement. OpenAI, Spotify and Depop are among its customers. The proposition is wonderfully unromantic: make the rules work.
- One operation: agents, investigations, review queues and policy enforcement share a platform.
- Your standards: customers define violations and supply examples of correct decisions.
- People keep the hard calls: automation handles confident decisions; ambiguous cases move to human reviewers.
The missing machinery
Wise’s background includes government work and Facebook’s Threat Discovery team. His fellow founders brought complementary experience: Phil Brennan in government and Meta, Brian Fishman in counterterrorism at Meta and disaster relief at Palantir, and Declan Cummings in engineering. They had seen what serious adversaries could do, and what defenders needed to stop them.
In Accel’s account of Cinder’s origins, Wise spoke with teams in delivery, ride-sharing, gaming and AI while looking for better tools. The discovery was a shared shortage. Accel’s early investment note describes Google documents, PDFs, fragmented databases and static lists standing in for a coherent operation. The first weakness was organizational: evidence and decisions lived apart.
Cinder launched publicly in December 2022 with $14 million in combined seed and Series A financing. Its founding insight survives the arrival of generative AI. A detector can raise an alarm. Somebody still has to decide what happened, connect the relevant evidence, apply the right rule and carry out the response.

The rules are yours. The plumbing is Cinder’s.
Customers send data into Cinder through an API; many receive actions back through a webhook. Within the interface, staff can configure policies, queues and workflows. The data model can connect accounts, content and other entities, allowing an investigator to examine a conversation or related network rather than a lonely screenshot.
Cinder’s agents learn from a customer’s policies, content and validated decisions. They classify incoming material, explain their decisions and attach confidence scores. Clear cases can be resolved automatically. Uncertain ones reach a human with context and a recommended action. Reviewed decisions feed subsequent retraining; new versions can be shadow-tested before deployment.
- 01Define the policy
- 02Evaluate with context
- 03Act or escalate
- 04Check the decision
This is also an orchestration business. Customers can bring their own agents, classifiers or third-party models. Cinder supplies shared case management, policy versioning, audit trails and analytics around them. A company need not discard its existing detector to stop rebuilding the machinery surrounding every new one.
Shrink the haystack, then test the fire exits
Character.AI’s problem was a substantial volume of user reports, including a moderation backlog. Its deployment used Cinder agents to distinguish violations from false positives, with conservative confidence thresholds. The system worked on incoming reports and existing cases. Cinder’s case study reports reductions of more than half across all queues in the largest backlog while maintaining the decision-quality service level.
Reported queue reductions across Character.AI’s largest moderation backlog.Customer case study published April 2026; a deployment result, not a universal forecast.
Black Forest Labs needed a different service before releasing FLUX.2: adversarial testing of an image-generation model. Cinder ran four evaluation cycles covering text-to-image and image-to-image attacks, concentrating on child sexual abuse material and non-consensual intimate imagery. Findings went back to the research team for changes and further testing.
The published case study reports more than a 90% reduction in those targeted vulnerabilities and evaluation turnaround below 48 hours. Those figures describe the tested harms and attack sets. They cannot certify every future use of a model. What readers can copy is the sequence: attack, categorize, fix, repeat before launch.
“Cinder provided rigorous adversarial testing that matched our release velocity.”Ben Brooks / Head of Public Policy, Black Forest Labs
Who checks the checker?
Patreon’s example concerns quality assurance. It used Cinder’s QA tools to assess outsourced review teams, find process and policy gaps, and shift more work to vendors. Sampling and layered review let staff examine decisions inside the same system where they were made. Multiple reviewers can be required to agree before a label is finalized.
There is a useful discipline here for anyone building a platform: establish what a correct decision looks like before celebrating automation. Wise describes cost, latency and accuracy as competing priorities. A model that produces a fast answer to the wrong question is an impressively punctual nuisance.
The approach depends on usable policies, credible evaluation examples and a functioning escalation route. If reviewers disagree about the rule, their labels need scrutiny. If a platform removes human judgment from ambiguous cases, it loses a central part of Cinder’s operating loop. Better plumbing still needs somewhere sensible to send the water.
A business built between the model and the decision
Cinder competes with internal systems, standalone detection services, outsourced review operations and adapted CRM tools. Its enterprise sales process starts with a demo; its homepage also offers managed moderation priced on outcomes rather than hours. For buyers, the economic question includes integration, model usage and the difficult cases that remain.
In May 2026, Cinder announced a $41 million Series B led by Radical Ventures and a New York headquarters. Its August Internet Watch Foundation membership added access to known-abuse signals for customers who also hold IWF membership. A StopNCII integration similarly connects eligible platforms to shared hashes and enforcement workflows.
The transferable lesson is modest enough to be useful. Keep evidence, policy, action and quality checks close together. Test what your system misses. Feed good human decisions back into the next version. The internet’s rules have never lacked ambition. Cinder has chosen to work on their execution.
Follow the work
COMPANY / CONVERSATIONS / CUSTOMER STORIES