The product

Decide in seconds. Defend for years.

Every intake decision gets the same treatment: screened, signed, and preserved with a full audit trail. Three stages, one signed record per decision.

ORIGIN product architecture · live pipeline Uploads enter left, pass through the ORIGIN Decision, Evidence Pack, and Oversight stages, and emerge as signed records delivered to DSPs, reviewers, and auditors. The Cross-Tenant Network spans below. Your intake pipeline artist · release · account one secure call ORIGIN 01 · DECISION Policy engine CTN match advisory ML reason codes ALLOW · REVIEW · REJECT 02 · EVIDENCE PACK Signed. Tamper-evident. inputs · checks · scores policy version · timestamp JSON · PDF · HTML · DDEX SIGNED · verifiable 03 · OVERSIGHT Human in loop REVIEW queue override log permanent record signed override log DSP delivery secure delivery + pack Reviewer console policy overrides Auditor / regulator export on demand 04 · CROSS-TENANT NETWORK (CTN) shared, signed match records · privacy-safe identifiers · member-governed thresholds one bad actor caught at one member is recognised across the network. Without exposing catalogue data.
01 · In seconds

One call in. One answer back.

Your system sends us the release. We check it against your rules and the network's warnings, and send the answer back in seconds: allow it, reject it, or send it to a person. It drops into your existing pipeline; if you can't call it directly, we integrate on our side.

02 · Signed at issue

Every decision gets a receipt.

The moment the call is made, it's sealed into a signed Evidence Pack: what the system saw, what it decided, and why. Nobody can quietly change it afterwards, and anyone you hand it to can check it's real. Exports in JSON, PDF, HTML and DDEX.

03 · On the record

People stay in charge.

Anything doubtful goes to your reviewers. Every override is recorded with a name and a timestamp in a history that can't be edited, so a year later you can still show exactly who decided what, and why.

04 · The network

One catch warns everyone.

When any member of the network catches a bad actor, every other member is warned automatically. The warning crosses the network. Your catalogue never does. That's the Cross-Tenant Network, below.

04 · THE NETWORK · CROSS-TENANT NETWORK (CTN)

When one member catches a bad actor, the rest see them coming.

Every ORIGIN instance is a node on the CTN. When one distributor spots a bad actor, a signed match record propagates through the network to the others. The signal crosses. The catalogue never does. Members govern the thresholds. XYNQ operates the infrastructure.

6,000+
cross-member tests passed in sandbox. Live shadow ingestion opens to a founding cohort in H2 2026.
04 · Cross-Tenant NetworkLIVE SCENARIO
ORIGIN NODE · 01
Distributor A
screening · policy v4
ORIGIN NODE · 05
Distributor E
screening · policy v4
REJECTED AT INGEST
ORIGIN NODE · 02
Distributor B
screening · policy v4
!FLAGGED
SIGNED MATCH RECORDsigned · independently verifiable
MEMBER · RIGHTS ORG
Rights body
screening · policy v4
ORIGIN NODE · 03
Distributor C
screening · policy v4
ORIGIN NODE · 04
Distributor D
screening · policy v4
Caught once. Known everywhere.
The difference

The same fraud ring, with and without the network.

One catch at one member. What happens next depends entirely on whether the members can hear each other.

Without the network
Day 0Caught at Distributor Abanned · evidence stays in A's inbox
Day 12Approved at Distributor Bnew namesame ring, new bank account
Day 98Three months of royalties paid outclawback window long closed
Day 121Uploading at Distributor Cevery catch starts from zero
With the network
Day 0Caught at Distributor Asigned match record issued to all members
InstantlyFive members alertedsignal only · no catalogue data crosses
Day 12Rejected at Distributor Bmatched recordrecognised at upload, before approval
Day 121Rejected at Distributor Cmatched recordzero royalties paid

The signal crosses the network. The catalogue never does.

Policy & regulation

Two layers of policy. One engine that runs both.

Every release into your catalogue clears two kinds of rule. A regulatory floor (DSA Article 17, EU AI Act Article 50, UK Online Safety Act) that applies to everyone. And a private policy ceiling (your thresholds, your DSP's rules, a rights body's member rules) that's yours. ORIGIN runs both in the same call and returns one signed record.

Sankey diagram: policy streams converge into ORIGIN Seven policy streams (four private, three regulatory) flow rightward into the ORIGIN engine. A single signed record exits. PRIVATE POLICY CEILING Distributor policies risk score · release rules DSP incoming rules min-guarantee · content mix Rights-org rules society · label · collective Fraud thresholds payee · velocity · net REGULATORY FLOOR DSA · Article 17 Statement of Reasons EU AI Act · Article 50 provenance · in force now UK Online Safety Act Ofcom codes ORIGIN Runs both. Signs the call. one secure call both layers evaluated in one pass signed evidence out SIGNED Evidence Pack JSON · HTML · PDF · DDEX verifiable · portable private policy streams (blue) regulatory floor streams (amber) signed record (green) Every policy is a stream. All streams converge into ORIGIN. One signed record exits.
Who this is for

Who this helps, and how.

Head of Trust & Safety

The one carrying the queue.

Distributor · 200,000 releases a year · 3-person team

She opens Monday to a full escalation inbox and no time to draft statement-of-reasons filings by hand. Her CEO doesn't know what "Article 17" means but sees the revenue when a partner goes on hold. By Day 30 of the pilot, every ticket in her queue has a signed artefact attached.

CTO / VP Engineering

The one who has to choose build vs buy.

Distributor · owns the ingest pipeline · lean team

His engineering team could build the signing and the storage themselves. What they can't build is recognition. He looks at how it integrates, sees the public verification page anyone can check a record against, and gets the point: the moat isn't the technology, it's the format regulators and law firms are already validating. He champions the pilot because the integration takes days, not quarters.

Regulation

Ready for your vendor questionnaire.

XYNQ is registered in Edinburgh (Companies House SC868951). Here's exactly where our compliance stands today.

  • ISO 27001: in audit, not yet certified. With a recognised certification body. Continuous evidence collection runs on a compliance automation platform.
  • ISO 42001: in audit, not yet certified. The AI management system standard. Runs in parallel with 27001.
  • GDPR posture: maintained. Full DPIA completed. Tenant-isolated data processing.
  • Security by design. Tenant isolation, strict access controls, secure delivery, and a permanent audit trail.
  • Regulatory Assessment tool: public. Ten minutes. No sales call attached.
Run the regulatory assessment

Maps your current intake posture against the DSA, the EU AI Act, and UK Online Safety Act. Returns a prioritised gap list.

By Friday of your pilot week

What changes about your job.

One week. Three moments on the calendar.

MONMonday · packs at work

Your queue has evidence attached.

Every DSP escalation opens with a signed Pack. Disputes shrink from weeks to days. Your first email of the week stops being an apology.

WEDWednesday · statements filed

Statement-of-reasons drafts itself.

The Pack IS the statement. Reason codes, policy version, timestamp. Machine-readable, filed automatically to the Transparency Database format.

FRIFriday · good news

Your CEO email has good news.

The number of decisions you can defend hits 100%. The number of clawbacks you lose by default hits zero. The report writes itself.

Book a 15-minute demo. Live product, no slides.

We'll run your catalogue through a policy and show you the decision, the Evidence Pack, and the audit trail. Your data. On your call.

Cookies at XYNQ. We use essential cookies and optional analytics to understand usage. Accept to enable analytics, or reject to continue with essentials only.