AI Act · Article 50 lands2 Aug 202611 d 02 h 49 mBook a demo →
The product

Decide in a second. Defend for years.

Every intake decision gets the same treatment: screened, signed, and preserved with a full audit trail. Three stages, one API contract, one signed record per call.

ORIGIN product architecture · live pipeline Uploads enter left, pass through the ORIGIN Decision, Evidence Pack, and Oversight stages, and emerge as signed records delivered to DSPs, reviewers, and auditors. The Cross-Tenant Network spans below. Your intake pipeline artist · release · account POST /v1/ingest ORIGIN 01 · DECISION Policy engine CTN match advisory ML reason codes ALLOW · REVIEW · REJECT 02 · EVIDENCE PACK Signed. Hash-chained. inputs · checks · scores policy version · timestamp JSON · PDF · HTML · DDEX SIGNED · verifiable 03 · OVERSIGHT Human in loop REVIEW queue override log append-only audit signed override log DSP delivery signed webhook + pack Reviewer console policy overrides Auditor / regulator export on demand 04 · CROSS-TENANT NETWORK (CTN) shared, signed match records · privacy-safe identifiers · member-governed thresholds one bad actor caught at one member is recognised across the network. Without exposing catalogue data.
01 · Under a second

One call in. One answer back.

Your system sends us the release. We check it against your rules and the network's warnings, and send the answer back in under a second: allow it, reject it, or send it to a person. SDKs are drop-in; if your pipeline can't call an API, we take webhooks.

02 · Signed at issue

Every decision gets a receipt.

The moment the call is made, it's sealed into a signed Evidence Pack: what the system saw, what it decided, and why. Nobody can quietly change it afterwards, and anyone you hand it to can check it's real. Exports in JSON, PDF, HTML and DDEX.

03 · On the record

People stay in charge.

Anything doubtful goes to your reviewers. Every override is recorded with a name and a timestamp in a history that can't be edited, so a year later you can still show exactly who decided what, and why.

04 · The network

One catch warns everyone.

When any member of the network catches a bad actor, every other member is warned automatically. The warning crosses the network. Your catalogue never does. That's the Cross-Tenant Network, below.

DevelopersRead the API before you book anything. Ingest, verify, and the Evidence Pack schema. Public reference, no login, no email gate.

API reference
04 · THE NETWORK · CROSS-TENANT NETWORK (CTN)

When one member catches a bad actor, the rest see them coming.

Every ORIGIN instance is a node on the CTN. When one distributor spots a bad actor, a signed match record propagates through the network to the others. The signal crosses. The catalogue never does. Members govern the thresholds. XYNQ operates the infrastructure.

6,000+
cross-member tests passed in sandbox. Live shadow ingestion opens to a founding cohort in H2 2026.
04 · Cross-Tenant NetworkLIVE SCENARIO
ORIGIN NODE · 01
Distributor A
screening · policy v4
ORIGIN NODE · 05
Distributor E
screening · policy v4
REJECTED AT INGEST
ORIGIN NODE · 02
Distributor B
screening · policy v4
!FLAGGED
SIGNED MATCH RECORDsha256 · independently verifiable
MEMBER · RIGHTS ORG
Rights body
screening · policy v4
ORIGIN NODE · 03
Distributor C
screening · policy v4
ORIGIN NODE · 04
Distributor D
screening · policy v4
Caught once. Known everywhere.
The difference

The same fraud ring, with and without the network.

One catch at one member. What happens next depends entirely on whether the members can hear each other.

Without the network
Day 0Caught at Distributor Abanned · evidence stays in A's inbox
Day 12Approved at Distributor Bnew namesame ring, new bank account
Day 98Three months of royalties paid outclawback window long closed
Day 121Uploading at Distributor Cevery catch starts from zero
With the network
Day 0Caught at Distributor Asigned match record issued to all members
+38 msFive members alertedsignal only · no catalogue data crosses
Day 12Rejected at Distributor Bmatched recordrecognised at upload, before approval
Day 121Rejected at Distributor Cmatched recordzero royalties paid

The signal crosses the network. The catalogue never does.

Policy & regulation

Two layers of policy. One engine that runs both.

Every release into your catalogue clears two kinds of rule. A regulatory floor (DSA Article 17, EU AI Act Article 50, UK Online Safety Act) that applies to everyone. And a private policy ceiling (your thresholds, your DSP's rules, a rights body's member rules) that's yours. ORIGIN runs both in the same call and returns one signed record.

Sankey diagram: policy streams converge into ORIGIN Seven policy streams (four private, three regulatory) flow rightward into the ORIGIN engine. A single signed record exits. PRIVATE POLICY CEILING Distributor policies risk score · release rules DSP incoming rules min-guarantee · content mix Rights-org rules society · label · collective Fraud thresholds payee · velocity · net REGULATORY FLOOR DSA · Article 17 Statement of Reasons EU AI Act · Article 50 provenance · 2 Aug 2026 UK Online Safety Act Ofcom codes ORIGIN Runs both. Signs the call. POST /v1/ingest both layers evaluated in one pass signed evidence out SIGNED Evidence Pack JSON · HTML · PDF · DDEX verifiable · portable private policy streams (blue) regulatory floor streams (amber) signed record (green) Every policy is a stream. All streams converge into ORIGIN. One signed record exits.
Who this is for

Who this helps, and how.

Head of Trust & Safety

The one carrying the queue.

Distributor · 200,000 releases a year · 3-person team

She opens Monday to a full escalation inbox and no time to draft statement-of-reasons filings by hand. Her CEO doesn't know what "Article 17" means but sees the revenue when a partner goes on hold. By Day 30 of the pilot, every ticket in her queue has a signed artefact attached.

CTO / VP Engineering

The one who has to choose build vs buy.

Distributor · owns the ingest pipeline · lean team

His engineering team can build hash chains and signature schemes. They cannot build recognition. He reads the API surface, notices the drift-locked SDKs and the public verify endpoint, and sees the point: the moat isn't the crypto, it's the format regulators and law firms are validating. He champions the pilot because the integration is measured in days, not quarters.

Regulation

Ready for your vendor questionnaire.

XYNQ is registered in Edinburgh (Companies House SC868951). Here's exactly where our compliance stands today.

  • ISO 27001: in audit, not yet certified. With a recognised certification body. Continuous evidence collection runs on a compliance automation platform.
  • ISO 42001: in audit, not yet certified. The AI management system standard. Runs in parallel with 27001.
  • GDPR posture: maintained. Full DPIA completed. Tenant-isolated data processing.
  • Runtime hardening. Tenant isolation, scoped API keys, signed webhooks, append-only audit trail.
  • Regulatory Assessment tool: public. Ten minutes. No sales call attached.
Run the regulatory assessment

Maps your current intake posture against the DSA, the EU AI Act, and UK Online Safety Act. Returns a prioritised gap list.

By Friday of your pilot week

What changes about your job.

One week. Three moments on the calendar.

MONMonday · packs at work

Your queue has evidence attached.

Every DSP escalation opens with a signed Pack. Disputes shrink from weeks to days. Your first email of the week stops being an apology.

WEDWednesday · statements filed

Statement-of-reasons drafts itself.

The Pack IS the statement. Reason codes, policy version, timestamp. Machine-readable, filed automatically to the Transparency Database format.

FRIFriday · good news

Your CEO email has good news.

The number of decisions you can defend hits 100%. The number of clawbacks you lose by default hits zero. The report writes itself.

Book a 15-minute demo. Live product, no slides.

We'll run your catalogue through a policy and show you the decision, the Evidence Pack, and the audit trail. Your data. On your call.

Cookies at XYNQ. We use essential cookies and optional analytics to understand usage. Accept to enable analytics, or reject to continue with essentials only.