| Hosting provider | 12 | The file, the page, the site or the account, on the machine actually serving it. This is the only layer at which content stops existing. | The live URL, timestamped captures of the abusive page, and the authorisation letter naming the mark or the data being misused. |
| Where it fails: an abuse-tolerant host reads the notice and does nothing, and its own process has no appeal above itself. Bulletproof hosting is the extreme of that, and it is the reason the ladder further down this page exists at all. |
| Social platform | 10 | The impersonating profile, page, group, post or paid advert — and, on repeat abuse, the account publishing them. | Proof of identity or registered rights, filed through the platform’s own impersonation or brand channel rather than a general abuse address. |
| Where it fails: platform policy is the operative law here, not trademark law. An account that parodies rather than impersonates, or that copies a tone without copying a mark, is regularly held to be within policy — and the reviewer applying that policy is not a lawyer. |
| Registrar | 9 | Nothing on the page. It suspends, locks or places the domain registration on hold, which takes the name out of service and leaves the content where it is. | Proof of the mark, the current WHOIS or RDAP record, and evidence of abusive use — resemblance on its own is not a ground. |
| Where it fails: a parked lookalike serving nothing yet is the hardest class of case in this table, because the registrar is being asked to act on intent rather than on conduct. We say so when the request is raised, not once the case has stalled. |
| Cloud storage | 7 | The exposed object or bucket, or the public access to it. | The address of the exposed object, and evidence that the data sitting inside it belongs to you. |
| Where it does not apply at all: when the bucket is yours. That is a configuration change you can make immediately, and a notice would only tell you about something you already control — so the finding says so instead of opening a case against your own provider. |
| App store | 7 | The store listing. Where one publisher does it repeatedly, the developer account itself. | An attestation from the rights holder, the identifier of the offending listing, and a pointer to the real application being copied. |
| Where it fails: a cloned application distributed as a sideloaded package never enters a store, so no store notice reaches it. Those cases belong to whichever host is serving the file, one row up. |
| CDN and reverse proxy | 6 | Rarely the content. It can terminate the route, and in some processes it identifies the origin its network is fronting. | The proxied hostname and evidence that the abuse is being served through that network. |
| Where it fails as a destination: it was never one. The usual value of a notice here is the origin it discloses, which means a successful case at this layer ends by opening another at the layer that can actually delete something. |
| Paste and forum site | 6 | The paste, the thread, the post or the attachment. | The identifier of the paste or thread, and evidence that what it holds originated with you. |
| Where removal is not remediation: this content is routinely mirrored before it comes down. Taking it down narrows the audience, it does not un-publish anything — so the revocation or rotation is the work, and the notice is the tidying up afterwards. |
| Developer tooling and registries | 6 | Packages, container images and build artefacts uploaded under a namespace built to be mistaken for yours. | Enough to locate the artefact exactly — registry, namespace, name, version — together with the namespace claim or the mark it trades on. |
| Where it fails: a package that is merely a near-miss of your name and does nothing malicious. Registries generally act on demonstrated harm or on a namespace claim, and similarity alone is neither. |
| Marketplace | 6 | Listings that counterfeit or infringe, and the seller account behind them once the pattern repeats. | A registration number, the identifier of the listing complained of, and the genuine product it is passing itself off as. |
| Where it fails: an unregistered mark. Most marketplace rights programmes are built around a registration number and have no intake path for a brand that has never filed one, however well known it is. |
| Code platform | 6 | The repository, file, gist or fork holding source, configuration or secrets that were never meant to be public. | Ownership of the material and, where a secret is involved, an indication of what that secret unlocks. |
| Where removal is not the remedy: a secret that has been public is compromised whether or not the repository ever comes down, and a fork can outlive the parent it was taken from. Rotation is the remediation. The notice only limits who else stumbles across it. |
| Search engine | 5 | Nothing. It deindexes the URL, so the content stops being found through search. | The address, the search that returns it, and the reference of the abuse case opened against whoever is actually serving it. |
| Deindexing is routinely reported upward as a takedown. It is not one: the page is untouched at its own address and stays reachable by anyone holding the link — which is exactly how a phishing page distributed by email is reached in the first place. |
| Other | 6 | Varies. Browser and phishing blocklists sit here: nothing comes down, but an interstitial stands between the reader and the page for as long as the removal itself is unresolved. | Varies by provider. |
| The twelfth type collects the counterparties that will not sit in any of the eleven above. It is labelled a remainder rather than given a name of its own, because the alternative is a directory that reads tidier than the internet actually is. |