What AiProof proves — and what it doesn’t.

How verification works, how it is secured, and what evidence exists today.

Provenance model

AiProof never decides whether unknown content is fake. It keeps evidence about registered origins and evaluates a copy against them with a decision profile. Evidence and decision are separate; an origin stored under an unsupported canonicalization profile fails closed.

ProfileUsed forVocabulary
origin-matchA copy checked against one known origin (/v1/origins/{id}/verify)ExactNearChanged
lookupUnscoped registry lookup (/v1/verify)Exact match · Near match · No registered origin found

“No registered origin found” means no registered origin met the match profile within AiProof’s search bounds. It is never evidence that no origin exists anywhere or that the content is fake.

AiProof verifies provenance evidence against known registered origins. Registration establishes a known reference; it does not by itself establish authorship, ownership, first publication, factual truth, or whether content was created by a person or by AI.

Security

ItemCurrent state
Response signingEd25519 (kty OKP); the key ID is in the Signature-Input header of every signed answer and in the JWKS
Public keysGET /.well-known/aiproof-jwks.json on the API host
CoverageResponse body bytes. Full RFC 9421 HTTP message signing is not implemented.
InputsPNG, JPEG, WEBP · uploads capped at 10 MB
Abuse controlsRegistration rate-limited; the public trial has per-visitor and site-wide quotas
LoggingSite analytics keeps page addresses without query strings, the referring site and a random session ID; no IP addresses or form contents. No secrets in logs.
Supply chainCycloneDX SBOM generated in CI
Open the public keys →

Privacy & data

Media submitted for registration or verification is processed to compute strict and perceptual fingerprints. Only cryptographic commitments may ever be written to a public chain — never media, emails, names or confidential metadata.

Read the Privacy Policy →

Subprocessors

The confirmed list of subprocessors is published here before the first paid pilot; changes are announced in advance. Ask us at hello@aiproof.one if you need it for a review today.

Reliability & status

Controlled pilot operation

Verification paths fail safely rather than return a misleading success.

No contractual SLA is published yet. Uptime history and an incident timeline appear here once production telemetry can support them.

Standards

StandardStatus
Ed25519 signatures + JWKSIn use
C2PA / Content Credentials verificationRoadmap
RFC 3161 trusted timestampsRoadmap
Public-chain anchoring (commitments only)Roadmap

Vulnerability disclosure

Report a suspected vulnerability to hello@aiproof.one. Include steps to reproduce; do not access other customers’ data or degrade the service. We acknowledge every report and credit researchers who ask to be credited.

Compliance evidence

EvidenceStatus
SOC 2 Type I / IINot yet
ISO 27001Not yet
Independent penetration testPlanned
Data Processing AgreementIn preparation

We list only evidence that exists. New reports are added here without changing this page’s structure.