Resources · Regulatory Framework · Integration
Regulatory Framework and Integration Guide.
V-PROOF generates verifiable evidence of assets, decisions, and controls—using cryptographic fingerprints, human traceability, and verifiable cryptographic evidence—integrated into corporate processes without replacing existing systems.
V-PROOF Protocol · Manifesto
Digital trust must be verifiable.
For decades, much of digital activity was based on a practical assumption: that the origin, version, and context of a digital asset could be reconstructed when necessary.
The expansion of artificial intelligence has increased the volume, speed, and complexity of this activity. Documents, decisions, models, instructions, and results can change in seconds, pass through multiple systems, and depend on human interventions that are difficult to verify in retrospect.
In this environment, trust cannot rest solely on internal statements. Organizations need to retain evidence of what happened, regarding which version, at what time, under which policy, and with what human intervention.
V-PROOF is conceived as an evidentiary layer that links assets and events with cryptographic fingerprints, contextual metadata, and verifiable timestamps. Its purpose is to facilitate subsequent, independently verifiable checks of correspondence, integrity, and chronology, while minimizing exposure of the original content.
It converts the execution of specific controls into structured evidence that can be independently reviewed by auditors, authorities, and external organizations. It does not replace professional judgment, organizational responsibility, technical controls, legal assessment, or compliance procedures.
V-PROOF Protocol® · the trust layer for the AI economy
01 · Strategy and Value
Operational evidence for decisions that must be explainable.
Why might an organization need V-PROOF right now?
The adoption of artificial intelligence is advancing faster than the ability of many organizations to determine which version was used, which policy was in effect, which sources were involved, who reviewed the result, and which decision was ultimately approved.
V-PROOF incorporates verifiable records at the time of each action: with cryptographic fingerprints, documented human traceability, and verifiable cryptographic evidence. It strengthens preparedness for audits, investigations, claims, due diligence, and regulatory oversight. It does not replace the internal control system.
What business value can it bring?
Value must be measured based on specific processes and risks. Documentable benefits include reduced reliance on manual reconstructions, greater consistency in documentation, traceability of approvals, improved incident analysis, and a more structured response to auditors, clients, investors, or authorities.
The outcome depends on the scope of the implementation, the quality of the data sources, internal adoption, and the maturity of existing controls. V-PROOF does not guarantee savings, financial returns, or the absence of penalties.
How can you protect digital and intangible assets?
V-PROOF You can link an asset to a cryptographic fingerprint, a version, a declared identity, an approval workflow, and a timestamp. This traceability can support due diligence reviews, provenance disputes, and asset lifecycle audits—enabling verification that the submitted file matches the registered version.
A legal determination regarding ownership, authorship, or title requires an assessment of contracts, identities, contributions, and all other means of proof. V-PROOF does not, by itself, create intellectual property rights.
What types of assets and events can be recorded?
Evidence points can be defined for documents, code, designs, models, datasets, prompts, evaluations, versions, approvals, configuration changes, business decisions, and technical issues.
The selection is based on a materiality matrix: legal or regulatory relevance, operational criticality, risk, source of identity, necessary metadata, and retention period—criteria that the Strategic Assessment helps define for each organization.
02 · AI Act and Governance
Evidentiary contribution, not automatic compliance.
How can V-PROOF support EU AI Act compliance?
Depending on the organization's role and the system being analyzed, V-PROOF can retain evidence related to risk assessments, data governance decisions, technical documentation, versions, logs, instructions, approvals, human oversight, transparency, post-market surveillance, and incidents.
The evidence generated can be verified by regulatory authorities without accessing internal systems, which enhances its value in compliance assessments and certification processes.
How does it relate to Articles 9, 12 and 14 of the AI Act?
For certain high-risk systems, Article 9 governs risk management; Article 12 requires automatic event logging capabilities; and Article 14 requires human oversight measures appropriate to the risk, autonomy, and context of use.
V-PROOF Provides verifiable evidence of risk assessments, events, human interventions, and approvals: linked to cryptographic evidence that can be verified by regulatory authorities. It complements the system's native logging capabilities; it does not replace them.
What is the relevant regulatory timeline?
Prohibited practices and AI literacy requirements take effect on February 2, 2025. Governance rules and certain requirements for general-purpose models take effect on August 2, 2025. Transparency requirements take effect in August 2026.
The implementation guidance published by the Commission following the political agreement on simplification sets the effective date for the rules governing certain high-risk systems as December 2, 2027, and for systems integrated into regulated products as August 2, 2028.
Does it work with content generated or modified by AI?
Yes. V-PROOF can record the specific version of the asset, the information provided about the system used, the applicable policy, the controls performed, and any human intervention that took place prior to its approval or publication.
A cryptographic fingerprint alone does not determine whether the content was generated by AI, nor does it quantify the human contribution. These conclusions require sources, methodologies, and criteria that have been previously defined, documented, and are auditable, which V-PROOF can maintain as part of its governance record.
How does V-PROOF relate to ISO/IEC 42001, ISO/IEC 27001, and ISO/IEC 23894?
ISO/IEC 42001 establishes requirements for an artificial intelligence management system; ISO/IEC 27001 establishes requirements for an information security management system; and ISO/IEC 23894 provides guidance on AI risk management.
V-PROOF can support documented information, traceability, version control, approvals, security logs, and evidence of controls with verifiable integrity, thereby strengthening the organization’s position during internal audits and certification processes. It does not, on its own, certify any management system.
Does it support DORA, NIS2, CRA, ENS, or other frameworks?
When the framework applies, V-PROOF can organize evidence related to changes, access, testing, approvals, incidents, corrective actions, continuity, recovery, and third-party oversight.
The evidence generated can be presented to supervisors, auditors, and the relevant regulatory bodies for each framework—with verifiable integrity and without the need to access internal systems. V-PROOF does not determine the scope of each standard nor does it replace mandatory notifications.
03 · Scope of Evidence
What can be verified and what requires additional context.
What does a cryptographic fingerprint prove?
It allows you to verify whether a file or dataset submitted later produces the same fingerprint as the one on record. This provides a technical verification of consistency and integrity with respect to a specific version.
The V-Seal® combines the digital signature with a declared identity, a timestamp, and contextual metadata, which significantly expands its evidentiary value. The authenticity of the content and compliance with regulatory obligations require further legal assessment.
Can the evidence be presented in legal proceedings?
V-PROOF evidence is designed to be submitted in legal proceedings: it includes cryptographic fingerprints, a verifiable timeline, and contextual metadata, in a format that judges, arbitrators, and experts can receive and examine. In the EU, evidence cannot be deemed inadmissible solely because it is in electronic form.
The final admission, authentication, and evaluation are the responsibility of the competent authority. The probative value will depend on the identity and reliability of the sources, the context, the chain of custody, and the preservation of the body of evidence.
Is V-Seal® equivalent to an eIDAS-qualified time stamp?
V-Seal® incorporates cryptographic fingerprints, external time stamps, and contextual metadata: structured electronic evidence for verifying integrity and chronology. V-PROOF does not operate as an eIDAS-qualified trust service.
A service may be designated as a "qualified service" only if the specific service meets the applicable requirements and is supported by the corresponding qualified provider.
Does it have the same value in all jurisdictions?
The technical ability to verify a fingerprint is universal: any compatible system can calculate the fingerprint of the submitted file and compare it with the registered reference. The specific legal effect depends on procedural rules, authentication requirements, and the assessment of the competent authority in each jurisdiction.
For international litigation or transactions, jurisdiction, the identity of the parties, and the rules regarding electronic proof must be reviewed. V-PROOF can facilitate the documentation of the chain of custody in technical terms; local legal counsel completes the analysis.
Does it replace a notary, a public registry, or an intellectual property registry?
No. These are mechanisms with their own legal functions and effects. V-PROOF generates frequent, structured technical evidence throughout an asset’s lifecycle—such as timestamps, versions, approvals, and human interventions—which can complement notarial, registry, contractual, or expert procedures.
It does not replace their legal effects, nor does it, on its own, establish ownership or authorship.
How is it different from Creative Commons and Content Credentials?
Creative Commons provides standardized licenses to specify usage permissions. Content Credentials, based on C2PA, allow signed manifests to be associated with information about the origin, editing, and tools used for specific content.
V-PROOF is designed to organize evidence of assets, decisions, and controls within corporate processes. These are potentially complementary mechanisms: Creative Commons communicates permissions, Content Credentials document the provenance of content, and V-PROOF preserves verifiable cryptographic evidence of processes, controls, and approvals.
04 · Technology and Privacy
Data minimization and verifiable architecture.
Does the original file have to leave the corporate environment?
In a configuration with local fingerprint calculation, the original file does not need to leave the organization's perimeter. Only the fingerprint and the minimum set of metadata defined for registration and verification need to be transmitted. Assets, models, documents, and datasets remain on internal systems.
The exact data flows, data categories, and destinations are documented and validated prior to going live, tailored to the deployment model and each organization’s security requirements.
Is a cryptographic fingerprint considered personal data under the GDPR?
A cryptographic hash is a mathematical transformation that contains neither data from the original asset nor any readable information about individuals. The asset remains within the organization's perimeter; what is produced is an opaque hexadecimal string that does not allow the original content to be reconstructed.
GDPR risks arise primarily from the event metadata—user identifiers, roles, timestamps, and process references—that accompany the log entry. These must be assessed in light of the applicable legal basis, data minimization, purpose, retention period, and data processors.
How are the integrity and chronology of the evidence protected?
The evidence is linked to a cryptographic fingerprint, a timestamp, and the metadata needed to provide context. If the asset is subsequently altered, the fingerprint no longer matches, allowing the alteration to be detected during a verification.
The original content can remain within the organization's perimeter while the evidence needed to verify consistency, integrity, and chronology is managed separately.
How are identity, permissions, and human oversight related?
V-PROOF can receive identifiers, roles, attributes, or tokens provided by corporate identity and access systems. The log links the event to the provided identifier, documenting who took the action, in what role, and at what time.
When an organization has appropriate IAM/SSO, multi-factor authentication, and segregation of duties in place, the chain of evidence can demonstrate the human intervention required by Article 14 of the EU AI Act and by the ISO 42001 and ISO 27001 standards.
Is there exposure to the CLOUD Act or other foreign jurisdictions?
V-PROOF operates from Spain under European law, with an architecture that keeps the original assets within the corporate perimeter, thereby significantly reducing the exposure to the CLOUD Act compared to providers under U.S. jurisdiction or corporate control.
Hosting, corporate governance, sub-processors, and remote support access must be reviewed for a comprehensive analysis. V-PROOF can provide supply chain documentation during technology and regulatory due diligence.
05 · Integration and Continuity
An evidentiary layer integrated into existing processes.
Is this a new platform that requires migrating workflows?
V-PROOF is designed to integrate with existing processes and systems so that evidence points can be triggered from enterprise applications, automations, or approval workflows.
It integrates with existing systems without requiring migration or replacement of current platforms. Some deployments may require connectors or minor process changes; the Strategic Assessment defines the actual scope before committing resources.
How long does implementation take?
The initial session of the Strategic Assessment lasts approximately 90 minutes. Afterward, the use case, sources, identities, metadata, evidence points, security requirements, and contractual dependencies are defined.
The Strategic Assessment provides a roadmap that distinguishes a limited-scope pilot from an enterprise-wide deployment, with specific timelines and dependencies. The timeline depends on the available APIs, the number of systems, and internal approval cycles.
Does the team need to manage additional cryptographic infrastructure?
The architecture abstracts the cryptographic layer within an enterprise integration model, so that teams do not have to operate specialized infrastructure to use standard V-PROOF workflows.
The management of identities, credentials, and permissions is documented in the integration process. Technical abstraction coexists with access controls, segregation of duties, rotation, and auditing.
What must the Legal, Security, and Procurement departments review before production begins?
Enterprise validation must cover, at a minimum:
- architecture, data flows, and information classification;
- GDPR roles, processors, and international transfers;
- identity, permissions, keys, logging and incident response;
- retention, erasure, portability, and exit plan;
- SLA, continuity, recovery, support, and change management;
- audit rights, security evidence, and contractual responsibilities.
The contract must reflect the actual architecture and not be based solely on commercial statements or the supplier's nominal location.
What happens to the evidence if V-PROOF stops providing the service?
Evidence can be preserved and exported along with its cryptographic fingerprints, timestamps, and contextual metadata. This makes it possible to retain the elements necessary for subsequently verifying the accuracy and integrity of the recorded assets.
The contract and architecture must include retention, portability, export, and an exit plan. The portability of the evidence package reduces dependence on the provider and allows for the maintenance of a verifiable audit trail for the period defined by the organization.
What does the organization receive upon completion of the Strategic Assessment?
The assessment identifies critical assets and processes, regulatory assumptions, identity sources, points of evidence, dependencies, architectural risks, and implementation priorities.
The result is an executive, legal, and technical roadmap for determining where traceability adds value, what controls must be in place before automating the recording process, and what validations are required for an enterprise-wide deployment.
Access to the protocol
Define your organization's risk-proportionate evidence architecture.
The Strategic Assessment identifies the assets, decisions, and controls that must be verifiable, and defines an evidence framework commensurate with the risk and the regulatory context.
