These documents are template-level information for transparency. They are not certified legal translations or lawyer-approved equivalents in every language. For binding advice, consult qualified counsel. Enterprise customers receive executed MSA, Order Form, and counter-signed DPA — see Enterprise contracting.
Policy version: 2026-07-13 · EN
Technical Documentation — EU AI Act Annex IV Style
Product: TrustOriginality.ai multimodal detection & compliance platform
Version: 1.0 · Date: 2026-06-16
Role: General-purpose B2B detection / documentation tool (limited-risk transparency support)
Public URL:https://trustoriginality.ai/technical-documentation
This document follows the structure of EU AI Act Annex IV for high-risk AI systems. TrustOriginality as a detection tool is generally not a standalone high-risk system under Annex III; this documentation supports customer due diligence, ISO 42001, and enterprise procurement.
1. General description
| Item | Description |
|---|---|
| Intended purpose | Probabilistic detection of AI-generated or manipulated text, image, audio, and video; provenance verification (C2PA); compliance labeling and audit trails |
| Provider | Soluzyn OÜ, Ahtri tn 12, 15551 Tallinn, Estonia |
| Version / build | SaaS — continuous deployment; API version in OpenAPI at /swagger |
| Hardware / software | Cloud: .NET 10, QuestPDF reports, ONNX/CNN detectors, optional blockchain attestation |
| Foreseeable misuse | Sole automated hiring/grading/law-enforcement decisions — prohibited per AUP |
2. Detailed description — logic and data
2.1 Detection pipeline
- Input ingestion — file upload, URL, or text; optional text hashing (GDPR minimization)
- Preprocessing — modality-specific normalization (resize, spectrogram, tokenization)
- Detector ensemble — weighted scores from CNN classifiers, FFT/heuristic cues, watermark readers, C2PA manifest parser
- Verify Suite — cross-check declared provenance vs forensic score (
consistency_audit) - Output — score 0–1,
isAIGeneratedLikelyflag, evidence array, signed PDF + certificate key
2.2 Training data (summary)
| Modality | Approach |
|---|---|
| Image | CNN ensembles trained on public synthetic/human image datasets; periodic retraining |
| Audio | Spectral + classifier models on voice clone / TTS vs human speech corpora |
| Video | Frame sampling + image/audio sub-pipelines |
| Text | Statistical and transformer-based AI-text detectors |
We do not claim training on all possible generators. Novel models may score outside calibration.
2.3 Model sources
- In-house ensemble weights deployed via
TrustOriginality_ai_Detect_Infrastructure - Optional Box offline bundles with signed
manifest.json(ECDSA) - Third-party ONNX where licensed — listed in SBOM (
docs/KAMU-IHALE.mdreference)
3. Monitoring, functioning, control
| Control | Implementation |
|---|---|
| Human oversight | Customer-configured thresholds; publish gate blocks pending review |
| Logging | Activity log, compliance CSV/PDF, evidence ZIP per analysis |
| Accuracy monitoring | Internal eval sets; public benchmark disclosure: docs/MODEL-BENCHMARK-TRANSPARENCY.md |
| Incident response | SECURITY-ROTATION.md; customer notification per DPA |
4. Risk management (Art. 9 alignment)
| Risk | Mitigation |
|---|---|
| False positive | Documented in reports; human review recommended |
| False negative | Multi-detector ensemble; C2PA contradiction flags |
| High-risk misuse | AUP prohibits Annex III sole automated decisions |
| Data protection | DPA, hashing, retention, deletion API |
| Misleading marketing | FTC-safe disclaimers on all PDFs and Terms |
5. Known limitations
- Probabilistic only — not legal proof or court-expert certification
- Adversarial compression, cropping, novel generators reduce accuracy
- C2PA: unsigned or stripped manifests limit provenance claims
- Text: short snippets less reliable than longer samples
- Watermark detection depends on generator implementing standards
6. Changes and versioning
- Model updates deployed without customer downtime where possible
- Material accuracy changes documented in release notes and benchmark page
- Certificate keys and verify URLs remain valid for issued reports
7. Standards & compliance mapping
| Standard / regulation | Support |
|---|---|
| EU AI Act Art. 50 | JSON-LD labels, detection API, compliance dashboard |
| Code of Practice (Jun 2026) | C2PA, audit exports, publish gate |
| GDPR / KVKK | DPA, DPIA template, minimization |
| DSA | Transparency JSON export (/Compliance/ExportDsaTransparency) |
| C2PA | Manifest read/write, Verify Suite |
| eIDAS 2 / QEAA | Attestation JSON (roadmap: qualified trust service) |
8. Contact
- Security:
security@trustoriginality.ai - DPA / privacy: see Privacy Policy
- API docs:
/developers·docs/API.md