Six months later, someone will ask what you knew.
An AI verdict that cannot be reconstructed is not a control, it is an opinion. Every decision Proveniro makes is sealed with its inputs, model versions, thresholds and timing — replayable by an auditor, an insurer, a regulator or a court.
- record
- tamper-evident
- standards
- C2PA · EU AI Act
- replay
- full inputs
- export
- signed bundle
- enrolmentvoice + face enrolled, consent capturedsha256:19919…fb5
- grantlicence issued · 12 months · 3 territoriessha256:1b808…fd4
- verificationcallback scored · human verified · 268 mssha256:1d6f7…ff3
- findingunlicensed use matched on ad networksha256:1f5e6…1012
- noticetakedown filed with evidence packagesha256:214d5…1031
What gets sealed
Not the raw media — hashes of it. The record proves what was analysed and what was concluded without becoming a second copy of the sensitive material it was built to protect.
- inputs
- Media hashes, duration, codec chain, capture path attestation
- decision
- Label, confidence, per-model reason codes, operating threshold
- versions
- AI model identifiers and versions in force at the moment of scoring
- context
- Control invoked, claimed identity reference, amount or case ID
- actors
- Which system asked, which human reviewed, what they did next
- timing
- Signed timestamps for request, verdict and any downstream action
AI provenance is the product platforms and insurers actually buy.
Detection is interesting to a security team. A defensible record is what a claims adjuster, a compliance officer and a platform's trust team can act on.
Insurers
Price and adjudicate synthetic-media risk with per-decision evidence rather than a post-incident narrative reconstructed from memory.
Regulated firms
Demonstrate that an AI control existed, operated, and produced a specific result on a specific transaction — the standard an examiner and the EU AI Act both apply.
Platforms
Attach content credentials at upload and resolve rights disputes against a registry record instead of duelling screenshots.
Counsel
Export a signed evidence bundle with chain of custody intact, suitable for a notice, a claim or a filing.
Standards-aligned
C2PA content credentials, verifiable credentials for grants and agent identity, and stable identifiers other systems can resolve.
Privacy-preserving
Hashes and manifests by default. Raw media is retained only where you explicitly require it for a case.
Tamper-evident, not theatrical.
There is no token and no public chain. Records are hash-linked and periodically anchored so that any modification to the history is detectable, and so that the anchor can be verified independently of us.
Each record commits to its predecessor. Periodic checkpoints are published and counter-signed, which means a customer can prove that a record existed at a point in time without trusting our word for it — and can detect if anything earlier in the chain has been altered since.
Export produces a self-contained bundle: the records, the verification keys, the checkpoint proofs and a verifier you can run yourself. If Proveniro disappeared tomorrow, your evidence would still verify.
- structure
- Append-only, hash-linked records with per-tenant isolation
- anchoring
- Periodic signed checkpoints, counter-signed and independently verifiable
- content credentials
- C2PA manifests with issuer assertions and grant references
- grants
- W3C Verifiable Credentials with Ed25519 proofs and revocation lists
- export
- Signed bundle with keys, checkpoints and a standalone verifier
- retention
- Records held on your schedule; media held only by explicit configuration
- access
- Scoped read tokens for auditors, insurers and counsel without account provisioning
Make the record before you need it.
Provenance is worth nothing retroactively. Teams that adopt it early are the ones with an answer when the question finally arrives.
soc 2 type ii in progress · eu & uk data residency · no ai training on your data