CarrySafe
Get early accessPortal access

How the law gets reviewed

A carry-law app is a machine for turning somebody's reading of a statute into a decision another person makes at a doorway. That is a serious thing to build, so the interesting part of CarrySafe is not what it publishes — it is what it structurally cannot publish.

Five rules the product is built around

  1. Never author a determination from memory or from an aggregator

    Every published row cites an official government source: the statute, the agency's own page, the attorney general's published policy. We have found cases where widely-copied reciprocity lists disagree with the destination authority's own page. When they disagree we take the authority's page, and the pair stays Not reviewed until a reviewer has read that page in full.

  2. Absence of data renders as Not reviewed, never as permission

    A missing row is unknown. A category with no rule falls back to a default that is never “permitted”. Silence is not a yes, in the database as well as on the screen.

  3. News is never law

    No ingestion path — press, bills, community posts, nothing — can write a rule. Reporting is rendered as reporting, with the outlet named. Only a reviewed determination changes what the map says.

  4. A badge must mean something

    A verified publisher badge is set by a human reviewer. The database pins that field on self-update, so no account can award itself the seal it wants readers to trust.

  5. The permit card is a reference copy, never a credential

    It carries a non-removable NOT VALID FOR CARRY watermark and deliberately does not reproduce a state seal. Holders type their own values, so a pixel-exact clone would be a forgery generator.

What a determination has to survive before it is shown

Publishing is not a reviewer pressing a button. A reviewer's finding becomes a controlled legal object, and the app re-checks that object every time it draws a card. Any single failure below produces “Not reviewed” rather than a weaker answer.

  • A source, not a citation-shaped string. A determination with no direct official source cannot be saved at all — the write is rejected, not warned about.
  • Scope. The evidence has to attest to the exact question being asked: this jurisdiction, this category, this permit context, this date. Evidence that answers a neighbouring question does not answer this one.
  • Completeness. A selective policy is only usable when the actual list it turns on is present. A source that says “see the list” without exposing the list is not evidence for anything on that list.
  • Currency. A source that has expired on its own terms cannot support a decision today, however recently a reviewer copied it.
  • Monitoring. The source has to be watched. An unwatched source is a determination that will silently become false.
  • Fingerprint match. Every legal input — issuer set, residency gates, permit types, conditions, age, source, effective dates — is fingerprinted. If the underlying policy changes, everything derived from it fails the comparison and closes.

Reviewers are not anonymous, and they are not unaudited

  • Review happens on a staff desk with role checks enforced in the database, not in the app.
  • Writing a determination requires a fresh re-authentication, not just an open session.
  • Every write is audited with who, what and when.
  • “Unknown” is not a saveable verdict. A reviewer who cannot support an answer retires the row instead of publishing a guess dressed as a finding.

Why one destination page can support many answers

Recognition is usually published by the destination: one state's own complete, current policy about which permits it recognizes, and under what conditions. One such policy legitimately supports many directional answers, so we do not pretend to hold thousands of independent sources.

The honest consequence is that the controlled object is the destination policy, and the individual pair answers are derived from it and re-checked against it. A pair is only publishable while its policy is complete, current, monitored and fingerprint-matched. What that means for the recognition matrix today.

When a source changes

  • Sources are monitored. A source that moves, changes or expires demotes what depends on it rather than leaving the old answer on screen.
  • Demotion is not a deletion of the underlying record — it is the answer being withdrawn until a reviewer has read the new page.
  • Geometry and inventory are versioned separately from legal review, so redrawing a boundary can never look like reviewing a law.

If you think we are wrong

Tell us, and include the official page you are reading. A correction backed by an authority's own URL is the fastest thing in our queue, and a determination we cannot re-derive from a live source gets withdrawn to “Not reviewed” while it is checked.

Report a legal-data error

Contact support

Please do not send anything you would not want stored: we do not need your permit number, your address, or where you were standing.