FAQ
Questions we get on every first call.
Building it yourself, your detection stack, privacy, where the data lives, integration, and what happens to your records. Straight answers.
Eight questions
Not answered here? Just ask.
Register interest and tell us what you need, or email hq@xynq.io.
Could we build this ourselves?
You could build the signing and the storage; that part is commodity. What you can’t build alone is recognition. A record only settles a dispute if the other side accepts its format, and no single distributor sees the fraud rings that hop between companies. An internal tool convinces your own team. A signed record in a format the whole industry checks convinces everyone else.
Do we have to rip out our existing detection stack?
No. ORIGIN screens every upload itself and plugs into what you already run: keep your fingerprint match, AI-audio detector or sanctions screen, and pass their outputs in with the upload. Your policy weighs them all. We give you the record. You make the call.
Why not just share a ban list?
A list is a promise. A signed match record is proof. The network shares the signal without any distributor seeing another’s catalogue: when the same actor comes back under a new name, members see it. Each member sets its own thresholds.
What about privacy? Does masking the data make it anonymous?
Masking alone doesn’t: under GDPR a plain hash can still be personal data. So ORIGIN goes further. Identifiers become one-way tokens at the source, and matching runs on inputs that stay sealed end to end, so no member, and no one at XYNQ, ever sees a readable record. Answers are cut to the minimum and never name the reporter. Members get the signal; nobody, including us, ever sees a readable record.
Where is the data stored?
Tenant-isolated by default, hosted in the UK, with EU-region deployment on request. Your catalogue never leaves your tenant; only match signals cross the network, never records. A full data-flow map is available under NDA.
What do we send you per release?
Track metadata and declarations, an audio reference, and identity signals that are turned into one-way tokens at source. Optionally, the outputs of your own detection tools.
How long does integration take?
Typical integration is measured in days, not quarters. It’s one API call and one webhook, in the DDEX vocabulary your catalogue already speaks. If you can’t connect directly, we handle the integration on our side, so the change lands in one team, not five. A 30-day shadow run goes against your live traffic before anything binds.
What happens to our Evidence Packs if we stop paying?
They stay verifiable. Every pack checks out against a public verification page that stays online whether or not you’re a customer, so your counterparties can still validate every record you ever issued. The records are yours.
Next step
Register interest.
See what ORIGIN would catch in your catalogue. Investors and partners welcome too. Leave your email and we’ll reply.