Courtesan Finder Interview

CourtesanFinder
Author:
theoz
Published:
August 27, 2026
Categories

CourtesanFinder was founded by two senior developers based in the Netherlands with backgrounds in building high-traffic digital platforms serving millions of monthly visitors.

The devs for CourtesanFinder got the idea whilst working on an escort agency website and looking into the broader landscape of existing escort directories. They were surprised to find out what sex workers are all too aware of = All the top directories look outdated, have awful UI, atrocious customer service and are incompetent when it comes to securing our data with seemingly no motivation to improve any of these aspects of their businesses.

It’s high time somebody who knows what they’re doing came along and built a platform.

Why not take pride in building something that looks good, works properly, isn’t full of fake profiles, deposit scammers and Onlyfans models posing as in person providers, and doesn’t leak our data like a sieve? Maybe even recruit staff as necessary to keep up with customer service such that turnaround times stay within a day or two rather than keep people waiting up to 6 months for a reply to an email (Tryst).

 

1) The thing I like best about CourtesanFinder is that you’ve prioritised privacy and data minimisation from the beginning. When we discussed age verification you were already looking towards third-party verification rather than collecting and storing sex workers’ identity documents yourselves. How did you decide to take this approach, and what would your ideal privacy-preserving age verification system look like if regulation eventually makes age checks necessary? Would you still like to get as close as technically possible to a double-blind system where neither CourtesanFinder nor the verification company holds enough information to connect someone’s legal identity with their sex work profile?

ie. As we discussed = age verification can be achieved without the directory ever seeing or storing government ID documents.

A trusted third-party age verification provider can simply return a token confirming that a person is over 18, without revealing any other identity information. Likewise, the third-party age verification provider need not know which platform the token will ultimately be used on.

Directories may also wish to verify that an account is controlled by the person depicted in the advert and guard against impersonation or account takeovers.

Ok, fine, but that objective can be achieved in ways that are less privacy-invasive than requiring and retaining biometric face selfies.

eg providers could be asked to submit a short video showing the outfits and backgrounds used in their advert photos, show distinctive tattoos or other identifying features, provide original RAW image files (of the images without face showing that escort is using in their ad) or photographer references where available, enable two-factor authentication, or obtain references from other verified providers.

A combination of these measures can provide a high degree of confidence in account ownership while significantly reducing the collection and long-term storage of sensitive biometric data.

I’ve written a more detailed proposal here.

 

The reason we wanted to minimise the amount of data we store from the very beginning is actually quite simple: if we don’t have it, it can’t be leaked.

Data breaches are unfortunately a daily occurrence. We believe no system can ever be 100% secure, and handling this kind of sensitive information therefore comes with a huge responsibility, a responsibility we think is too large for a small team like us where the risk is simply too high. Even large companies with huge security budgets and dedicated security teams regularly get this wrong, so we don’t have the illusion that we could do better with just the two of us.

For us, good security therefore starts not only with securing the data we actually need as well as possible, but also by asking ourselves whether we actually need that data in the first place. If certain information isn’t necessary for CourtesanFinder to function, we see no reason to collect it anyway and unnecessarily increase the risk.

That applies not only to our advertisers, but also to our visitors, who should be able to use the website with privacy and discretion in mind. We don’t need to know who someone is, exactly what they are looking for, what their preferences are, or what two parties discuss between themselves in order to fulfil our role.

Both agencies and independent advertisers are perfectly capable of carrying out their own screening and deciding which clients they want to work with. That is ultimately their own responsibility, and we see no reason for the platform to unnecessarily get involved in that process.

For clients, we try to act as a filter between fake listings, people who are primarily using the platform to promote their OnlyFans accounts, and genuine sex workers. CourtesanFinder deliberately focuses on a specific niche: high-end companions.

Our role is essentially very simple: we bring two parties into contact. We don’t need copies of ID documents or other unnecessarily sensitive information to do that. Because CourtesanFinder is also invite-only and thereby curated, we can carry out our own due diligence without unnecessarily collecting large amounts of personal data.

As for age verification, we currently carry out our own due diligence and will continue to do so while this remains legally possible. If a legal requirement for formal age verification is eventually introduced, we would outsource this to a specialized third party. Since we currently operate exclusively within the EU, we would strongly prefer an EU-based solution that allows the verification to happen without CourtesanFinder ever receiving or storing the underlying identity documents.

Ideally, we would take this one step further and use a genuinely double-blind approach. The verification provider should be able to establish that someone is over 18 without needing to know which specific platform or profile the verification will ultimately be used for, while CourtesanFinder would receive nothing more than a verifiable confirmation that the person has passed the age requirement. That would give us the benefit of formal age verification without creating a link between someone’s legal identity and their activity on CourtesanFinder.

For account ownership, we are still investigating the best approach and found the alternatives you outlined in your proposal particularly interesting. Things such as original image files, photographer references, references from other verified providers and two-factor authentication can all provide useful evidence without requiring us to permanently store biometric information. We see these as useful options to consider alongside simpler, more direct verification methods rather than necessarily choosing one approach over the other.

At the same time, we don’t necessarily see a selfie or a short video call as a problem in itself, provided that the information is only retained for as long as necessary and is then deleted. A simple, well-designed verification step may ultimately be more practical than building a complicated verification process around multiple forms of evidence.

Editors note: The problem is sex workers then need to take your word for it that you’re deleting it.

If we use a selfie, it would be used only as evidence during the verification process, not stored as biometric data or processed through facial recognition. Selfies would be deleted immediately after verification, and video calls would never be recorded. The goal is to obtain sufficient confidence about account ownership without creating a permanent biometric record.

We also see account verification as part of a broader due diligence process rather than something that has to be solved through a single technical check. We already look at things such as whether someone has their own website, how established that website appears to be, and how well represented they are elsewhere online and on social media. For the type of high-end companions we are targeting, having an established online presence and often their own business and website is relatively common.

This also means that someone with none of those signals may simply not be a good fit for CourtesanFinder in the first place. We are building for a particular segment of the market, rather than trying to accommodate every possible type of advertiser.

Ultimately, double-blind verification is a very attractive principle to us, but it also needs to be practical. We want verification to be as quick and frictionless as possible, both for the advertiser and for ourselves. We will therefore have to find the approach that provides the right balance between privacy, confidence and usability over the long term. We haven’t decided on one single method yet and may ultimately use a combination of different signals.

 

2) CourtesanFinder is run by two developers based in the Netherlands and operates under Dutch law. Was the Netherlands simply the natural choice because you are based there, or did its legal environment and approach to sex work, privacy and technology businesses make it particularly attractive? At the moment CourtesanFinder is self-funded and free, although I noticed your terms mention “paid advertising credits”. Is the eventual plan a subscription or premium-listing model? Once you monetise, you’ll potentially have to deal with banks, payment processors, KYC requirements and a public company register eg KVK Handelsregister. Have you thought about how you’ll structure the business so you can accept recurring payments while protecting both the founders’ privacy and advertisers’ financial privacy? Could that mean alternatives to Visa/Mastercard, such as cryptocurrency, or incorporating somewhere other than the Netherlands, such as Cyprus or Malta, to provide greater privacy for the people behind the platform?

 

The Netherlands was simply the most logical choice for us. To be honest, we never seriously considered setting up CourtesanFinder somewhere else. It started as a project that we are building alongside our regular work (and still is) as developers, so from that perspective the Netherlands was the natural choice.

That said, it does help that sex work is legal and regulated in the Netherlands. It means we can build and run this as an ordinary business, without the legal grey area that operators in some other countries have to work around.

We also have no intention of moving elsewhere because the regulations there are less strict or certain things would be easier. European regulation can sometimes feel restrictive, but we believe we can operate perfectly well within those frameworks. We therefore see no reason to set up a structure somewhere like Cyprus or Malta purely for regulatory or privacy reasons.

The same applies to our own privacy. We are aware that the KVK Handelsregister is public, and we recognize that this is something we will need to take into account when we formalize the business structure. We don’t feel any particular need to hide who we are or construct an offshore structure purely to remain anonymous. We aren’t doing anything illegal, and we would rather operate as a legitimate, properly registered business within the Netherlands.

There will eventually be premium options. The simple reason we aren’t charging for anything yet is that we have only just started, and we don’t think we deliver enough value yet to justify asking people to pay for it. We want to build and deliver that value first, and only then introduce premium options. There will always be a free option available for using the platform.

To avoid confusion about the wording in our terms: “advertising credits” refers to the advertising space we sell to agencies and independents on our own platform. It does not mean third-party advertising. We have no intention of placing external ads or ad networks on CourtesanFinder, for reasons of both user experience and privacy. Premium listings are the only thing we currently intend to monetize.

As for payments, KYC and invoicing, there will obviously be situations where we do need certain information. If someone wants a proper invoice for their own accounting, we will need to request business details, simply to keep our administration and invoicing accurate. But that is only for people who actually want an invoice; it isn’t something we intend to require from everyone who buys credits.

Advertisers’ financial privacy is something we take just as seriously as the rest of our data minimization. Card details would be handled entirely by the payment provider and never stored on our own infrastructure. Where possible, we would also want the billing descriptor on someone’s bank or card statement to be neutral, so that a payment to us doesn’t unnecessarily identify the platform or the nature of the service to anyone who happens to see the statement.

Cryptocurrency is not something we currently plan to offer. It doesn’t solve a problem we actually have, and it isn’t what our advertisers or visitors are asking for. If that changes, we will look at it again, but it isn’t on the roadmap.

We also haven’t decided exactly what the payment infrastructure will look like. That is something we will need to look at critically when the time comes, particularly given the specific challenges around payment providers for this type of platform. At the moment, we don’t see an immediate need for recurring payments either. We would rather have advertisers return regularly, keep their profiles up to date and potentially purchase credits again when they do, rather than introduce recurring payments purely for convenience.

Ultimately, we only provide advertising space. We are not involved in the relationship between an agency or independent and their clients, or in the agreements they make with each other.

 

3) You’re developing an AI matchfinder to help clients find suitable companions. I love this as a concept and AFAIK none of the big directories are doing this yet but it does seem like a natural, if not inevitable, progression for the platforms we use to start using LLMs. What will actually power it, what information will it be allowed to analyse, and what information will leave CourtesanFinder’s own infrastructure? Will conversations be stored or used to build a profile of a visitor’s preferences over time, or are you aiming for something that forgets the user after each session? Given the potentially very sensitive sexual and personal information people could give such an assistant, how are you approaching privacy from the design stage?

 

The AI matchfinder is indeed on our roadmap. We may have got slightly ahead of ourselves by mentioning it, because the feature hasn’t been built yet, but we already have the technical outlines in place and see real value in it.

Our preferred approach is to run an open-weight LLM ourselves, on infrastructure we control. That would mean that neither visitor queries nor profile data would leave our own infrastructure for inference. We are a self-funded project, however, so we also have to be realistic about the cost of running the necessary hardware ourselves. If self-hosting doesn’t make sense from a technical or financial perspective, we would rather use a specialized EU-based provider running open-weight models on EU infrastructure, with strict no-training and no-retention terms, than simply send data to a large general-purpose
AI provider.

One example we are currently looking at is Solheim, which provides EU-hosted inference on open-weight models. It isn’t necessarily the final choice, but it is much closer to the model we are looking for than sending profile data to OpenAI, Anthropic or a similar general-purpose API.

Running an AI model of this kind costs significant money, whichever route we take. For that reason, the matchfinder will surface premium listings. It is one of the features that premium advertising pays for, and we would rather be upfront about that than pretend otherwise. Ordinary search will continue to cover the whole directory as it does now.

As far as profiles are concerned, the matchfinder will only use information that is publicly visible on CourtesanFinder. For example, if an independent has provided business details that were needed to generate a proper invoice that information would never be passed to the model.

We also don’t want advertisers to unexpectedly find their profiles being used for something completely unrelated to the service they signed up for. The matchfinder will therefore only analyse the information that is already publicly available as part of the profile, and the purpose is strictly to make that information easier for visitors to search and understand.

For visitors, the matchfinder is intended to be session-based. Someone can tell it what they are looking for and what their preferences are, and it can use that information during that session to find suitable profiles. That information would not be attached to their account, used to build a persistent preference profile or carried over into future sessions. Once the session ends, the conversation and the preferences provided during it are discarded.

This also fits with our general approach to data minimization: as a platform, we don’t need to know what someone is looking for. If a visitor chooses to use the matchfinder, however, they can provide that information voluntarily in order to get a useful result. We can process it for that specific purpose without turning it into a permanent profile of that person.

Since conversations aren’t retained, anything we learn from usage would have to be limited to aggregate signals, such as whether searches produced useful results or whether visitors found relevant profiles, rather than the conversations themselves.

The principle is quite simple: the matchfinder should help someone find what they are looking for, not learn who that person is.

 

4) I’m constantly trying to encourage clients to do more research when looking for providers and avoid ads where one low effort ad is the providers entire web presence (AKA likely to be a deposit scam) and instead choose someone who has their own personal website, an extensive web presence they’ve clearly put a lot of time and effort into and socials with a lot of followers and engagement. A well-established independent personal website is, IMO, the best indicator that a provider is genuine, invested in their own business and likely to take pride in their work and want to build a good reputation and attract and retain regulars. You already distinguish independent companions from agencies. Would you consider adding a “has own personal website” filter, or otherwise making independently owned websites more prominent in search and matching?

 

We already have most of this in place, although there isn’t a dedicated filter for it yet. Independents can add their own website to their profile, and having a personal website has recently become one of the most important signals we take into account when selecting profiles.

We agree that an independent website is a valuable signal. It usually shows that someone is serious about their own business and isn’t solely dependent on an advert on a single directory. We also look at whether the website is genuinely established and actually belongs to the person behind the profile, rather than being a page put together last week. That is exactly the difference you’re describing between a real business and a low-effort listing.

We will definitely implement a dedicated filter for this, so thank you for the suggestion 😉.

There is one condition attached to how the link is displayed. Advertising with us is currently free, and for free profiles we ask for a link back to CourtesanFinder in return for displaying a link to their own website. We are a new directory and that kind of reciprocity is part of how we get discovered. If someone would rather not do that, that’s entirely their choice, but the website link isn’t displayed on the profile in that case and they won’t show up when filtered on it also.

Once premium listings are introduced, that requirement disappears. Premium advertisers can display their website regardless, and a link back to us is appreciated but never required. That seems fairer to us than asking people who are already paying to also provide a link.

Either way, a known website still counts in our own assessment. If someone has a well-established site, that weighs in their favor when we decide whether to invite or accept a profile, whether or not the link ends up being displayed publicly.

 

5) The established escort directories were all designed years, or decades, ago and have accumulated advertising, trackers, outdated interfaces, invasive verification requirements and layers of outdated features that have been added over time. Honestly, most of them look like garbage. Their designs are ugly and old fashioned. Their UIs are non intuitive and awkward. Based on how incapable most of them are of even responding to an email in a timely manner, I’m very sceptical about their ability to install security updates, renew certificates, update firewall rules, react to intrusion notifications, rotate credentials, pen test, security scan and respond to incidents. If there’s a critical zero day vulnerability that requires attention immediately, they might get around to looking at it next year. CourtesanFinder is being built from scratch by two experienced developers and from what I’ve seen is already a lot better looking and nicer to use than any of the big directories. What do you think escort directories have historically got wrong from a technical or product-design perspective, and what are you deliberately doing differently?

 

We are developers first and foremost, rather than a marketing or sales organization. Technology has been our profession for many years, and we have also worked extensively with SEO, regularly taking responsibility for the technical side of things. That gives us a different starting point when building CourtesanFinder. We mainly use AI as a tool to improve and validate our own work, rather than as a replacement for our own knowledge and experience.

From a technical perspective, one of our main priorities from the beginning has been to keep the architecture as decoupled as possible, for reasons of maintainability, performance and security. We have experience building and maintaining high-traffic platforms, so we know that tightly coupled systems become increasingly difficult to maintain as they grow.

Our public-facing website, for example, operates independently from the underlying platform. Different components can therefore be developed, changed and updated without every change immediately affecting the entire system. The same applies to the management interfaces for agencies and independents.

In practice, that means server patches are applied nightly and dependency updates are checked on every deploy. We deliberately use managed services where it makes sense, for example for our databases, so that security updates and patches can be applied as quickly as possible without us having to be the bottleneck. We manage the rest of the infrastructure ourselves and keep it up to date daily. We also try to minimise the number of third-party dependencies wherever practical, particularly on the public-facing side of the platform.

The same principle applies to the frontend. If we wanted to completely change the visual style of CourtesanFinder tomorrow, it wouldn’t require changes to our data model or underlying systems. We try to keep presentation, functionality and data as decoupled as possible. That makes it much easier to evolve the product without accumulating unnecessary technical debt.

Security is something we consider part of the architecture rather than something added afterwards. We take the view that no system can ever be completely secure, so incident response matters just as much as prevention. We maintain and monitor the infrastructure ourselves, and keeping the patch cycle short means we can respond quickly when something needs fixing urgently.

We also intend to provide a clear channel for responsible disclosure, so that security researchers can report issues directly to us rather than having to guess who to contact. If an incident ever does affect user data, we believe in dealing with it promptly and transparently rather than trying to hide it.

There is also a product-design side to this. We think many older platforms have accumulated years of features, integrations and interface decisions without ever having the opportunity to properly rethink the underlying product. Technical debt is ultimately something every platform has to deal with, particularly as a product gets older. Our focus is mainly on avoiding creating the same problems for ourselves.

That said, I don’t want to be overly critical of existing directories. There is another reason why there are relatively many outdated or lower-quality platforms in this market. Many larger agencies and companies prefer to stay away from the industry because of the stigma and preconceptions surrounding it. As a result, a number of smaller operators have stepped into that gap, and some have managed to capture a significant part of the market with fairly mediocre products, simply because there weren’t many alternatives.

Say what you like about them, but even the mediocre ones have survived for years and presumably generate enough revenue to make a proper living. People sometimes assume that building a platform like this is easy. AI has made it much easier to build something quickly, but building something that is genuinely good, performs well and remains maintainable in the long term is still difficult to do properly.

If we can make one critical observation in the other direction as well: this isn’t only a matter of what the platforms do. Nothing changes while the money keeps arriving regardless of quality. We regularly hear from providers that they aren’t happy with the directories they advertise on, while they continue paying a substantial amount every month to exactly those platforms. As long as that remains the case, there is very little incentive for anyone to improve.

We don’t expect anyone to advertise with us out of principle, and we understand perfectly well that a new directory with fewer listings is a risk. We expect to have to earn it by being demonstrably better. But someone does have to be willing to try something new at some point, because otherwise the situation simply stays as it is.

We also have no illusions that we will do everything better or that we won’t make mistakes. Things will go wrong for us too, and you will undoubtedly be able to catch us taking too long to answer an email at some point. Where people are involved, mistakes happen. What we consider much more important is how effectively you respond to those mistakes and how you prevent them from having disastrous consequences.

Something else we’ve run into is that we have been accused of scraping data and publishing profiles without permission, when in reality we had simply sent someone an invitation to join the platform. To be completely clear about this: we do not scrape websites or profiles, and we never will. Everything on CourtesanFinder is there because someone chose to put it there. Given how much of this interview is about privacy and data minimization, it would be fairly absurd for us to build the platform on data we took without asking.

Ultimately, our approach is fairly simple: keep the architecture maintainable, minimise unnecessary complexity and data, keep the infrastructure properly maintained, and build the product in a way that allows us to change it without having to rebuild everything underneath it.