Responsible use
We are building AI and biometric infrastructure. That is a category of technology with a poor track record, and pretending otherwise would be dishonest. This page sets out what we will not build, who we will not sell to, and the limits we place on the models we do ship.
last updated · 7 September 2026
Pre-launch draft. Proveniro is in private beta. This document describes our intended practice and will be finalised, with counsel, before general availability. Design partners operate under a signed agreement that takes precedence over this page.
01What this technology can do badly
An AI model that can tell whether a voice is synthetic can also be pointed at people who never asked to be analysed. A registry of faces and voices is, structurally, a database of biometric identifiers. Both can be misused, and the misuse is usually not exotic — it is ordinary surveillance, applied to people with no way to object.
We would rather name that risk and constrain the product around it than discover it in a deployment.
02Where we will not deploy
We decline these use cases, and the restriction is contractual, not aspirational.
- Mass or indiscriminate surveillance of a population, whether by a state or a private operator.
- Covert identification of individuals in public spaces without a lawful, specific and disclosed basis.
- Emotion inference, deception detection, or any AI inference about an individual's state of mind from their voice or face — prohibited practices under the EU AI Act and ones we would decline regardless.
- Scoring or profiling of individuals on characteristics unrelated to the specific verification being performed.
- Any deployment intended to suppress journalism, dissent, or lawful political expression.
03Constraints we build in
Some limits are easier to keep when the product enforces them.
- A synthesis-only mode that determines whether media is AI-generated without performing any identity matching.
- Enrolment that is opt-in, scoped and revocable, with revocation deleting the underlying templates.
- Verdicts returned to customer systems rather than to callers, so the model cannot be probed conversationally.
- Model reason codes on every decision, so a human reviewer can evaluate the basis rather than defer to an AI score.
04Human review
An AI verdict is a signal, not a judgement. We require customers to keep a human in the loop for any decision that materially affects an individual — declining an account, blocking a transaction, or removing content — and we design our tooling to make that review fast enough that it actually happens. No agent, ours or yours, gets to make those calls alone.
05The rights side is not decoration
It would be commercially simpler to sell only enterprise defence. We build the registry because the alternative — AI detection infrastructure that serves institutions while individuals have no way to assert control over their own likeness — is a worse world, and one we would be helping to build.
06Reporting misuse
If you believe Proveniro is being used in a way this policy prohibits, write to abuse@proveniro.com. We investigate every report, and we will suspend access where a customer is in breach.
Security vulnerabilities go to security@proveniro.com. We do not pursue good-faith researchers.
Questions about any of this?
Write to legal@proveniro.com and a human will answer. Security disclosures go to security@proveniro.com.
soc 2 type ii in progress · eu & uk data residency · no ai training on your data