V-PROOF Resources — Regulatory Framework and Integration

Resources · Regulatory Framework · Integration

Regulatory Framework and Integration Guide.

V-PROOF It generates verifiable evidence of assets, decisions, and controls—using cryptographic fingerprints, human traceability, and signatures from an independent third-party organization—integrated into corporate processes without replacing existing systems.

Digital trust must be verifiable.

For decades, much of digital activity was based on a practical assumption: that the origin, version, and context of a digital asset could be reconstructed when necessary.

The expansion of artificial intelligence has increased the volume, speed, and complexity of this activity. Documents, decisions, models, instructions, and results can change in seconds, pass through multiple systems, and depend on human interventions that are difficult to verify in retrospect.

In this environment, trust cannot rest solely on internal statements. Organizations need to retain evidence of what happened, regarding which version, at what time, under which policy, and with what human intervention.

V-PROOF It is conceived as an evidentiary layer that links assets and events with cryptographic fingerprints, contextual metadata, timestamps, and the signature of an independent external entity. Its purpose is to facilitate subsequent verification of correspondence, integrity, and chronology—which can be reviewed from outside the organization—while minimizing exposure of the original content.

It converts the execution of specific controls into structured evidence that can be independently reviewed by auditors, authorities, and external organizations. It does not replace professional judgment, organizational responsibility, technical controls, legal assessment, or compliance procedures.

V-PROOF Protocol® · The " Trust Layer " for the AI Economy

Operational evidence for decisions that must be explainable.

Why might an organization need V-PROOF right now?

The adoption of artificial intelligence is advancing faster than the ability of many organizations to determine which version was used, which policy was in effect, which sources were involved, who reviewed the result, and which decision was ultimately approved.

V-PROOF It incorporates verifiable records at the time of each action: with cryptographic fingerprints, documented human traceability, and a signature from an independent third-party organization. It strengthens preparedness for audits, investigations, claims, due diligence, and regulatory oversight. It does not replace the internal control system.

What business value can it bring?

Value must be measured based on specific processes and risks. Documentable benefits include reduced reliance on manual reconstructions, greater consistency in documentation, traceability of approvals, improved incident analysis, and a more structured response to auditors, clients, investors, or authorities.

The outcome depends on the scope of the implementation, the quality of the data sources, internal adoption, and the maturity of existing controls. V-PROOF does not guarantee savings, financial returns, or the absence of penalties.

How can you protect digital and intangible assets?

V-PROOF You can link an asset to a cryptographic fingerprint, a version, a declared identity, an approval workflow, and a timestamp. This traceability can support due diligence reviews, provenance disputes, and asset lifecycle audits—enabling verification that the submitted file matches the registered version.

A legal determination regarding ownership, authorship, or title requires an assessment of contracts, identities, contributions, and all other forms of evidence. V-PROOF does not, by itself, create intellectual property rights.

What types of assets and events can be recorded?

Evidence points can be defined for documents, code, designs, models, datasets, prompts, evaluations, versions, approvals, configuration changes, business decisions, and technical issues.

The selection is based on a materiality matrix: legal or regulatory relevance, operational criticality, risk, source of identity, necessary metadata, and retention period—criteria that the Strategic Assessment helps define for each organization.

Evidentiary contribution, not automatic compliance.

How c V-PROOF help ensure compliance with EU AI Act?

Depending on the organization's role and the system being analyzed, V-PROOF may retain evidence related to risk assessments, data governance decisions, technical documentation, versions, logs, instructions, approvals, human oversight, transparency, post-market surveillance, and incidents.

The evidence generated can be verified by regulatory authorities without accessing internal systems and can be signed by an independent external body, thereby reinforcing its value in compliance assessments and certification processes.

How does this relate to Sections 9, 12, and 14 of the AI Act?

For certain high-risk systems, Article 9 governs risk management; Article 12 requires automatic event logging capabilities; and Article 14 requires human oversight measures appropriate to the risk, autonomy, and context of use.

V-PROOF Provides verifiable evidence of risk assessments, events, human interventions, and approvals: signed by an independent external entity and verifiable by regulatory authorities. It supplements the system's native logging capabilities; it does not replace them.

What is the relevant regulatory timeline?

Prohibited practices and AI literacy requirements take effect on February 2, 2025. Governance rules and certain requirements for general-purpose models take effect on August 2, 2025. Transparency requirements take effect in August 2026.

The implementation guidance published by the Commission following the political agreement on simplification sets the effective date for the rules governing certain high-risk systems as December 2, 2027, and for systems integrated into regulated products as August 2, 2028.

Before establishing a compliance plan, it is necessary to verify the legislative text that is formally in force, the transitional provisions, the type of system, its intended purpose, and the organization’s specific role.
Does it work with content generated or modified by AI?

Yes. V-PROOF can record the specific version of the asset, the information provided about the system used, the applicable policy, the controls performed, and any human intervention that took place prior to its approval or publication.

A cryptographic fingerprint alone does not determine whether the content was generated by AI, nor does it quantify the human contribution. These conclusions require sources, methodologies, and criteria that have been previously defined, documented, and are auditable, which V-PROOF can maintain as part of its governance records.

How does “ V-PROOF ” relate to ISO/IEC 42001, ISO/IEC 27001, and ISO/IEC 23894?

ISO/IEC 42001 establishes requirements for an artificial intelligence management system; ISO/IEC 27001 establishes requirements for an information security management system; and ISO/IEC 23894 provides guidance on AI risk management.

V-PROOF It can support documented information, traceability, version control, approvals, security logs, evidence of controls, and the signature of an independent third-party organization that validates the entire system, thereby strengthening the organization’s position during internal audits and certification processes. It does not, on its own, certify any management system.

Does it support DORA, NIS2, CRA, ENS, or other frameworks?

When the framework applies, V-PROOF can organize evidence related to changes, access, testing, approvals, incidents, corrective actions, continuity, recovery, and third-party oversight.

The evidence generated can be presented to supervisors, auditors, and the relevant authorities for each framework: signed by an independent external organization and verifiable without accessing internal systems. V-PROOF does not determine the scope of each standard nor does it replace mandatory notifications.

What can be verified and what requires additional context.

What does an SHA-256 hash prove?

It allows you to verify whether a file or dataset submitted later produces the same fingerprint as the one on record. This provides a technical verification of consistency and integrity with respect to a specific version.

V-SEAL combines the digital fingerprint with a declared identity, external chronology, contextual metadata, and the signature of an independent third-party organization—which significantly expands the scope of evidence. The accuracy of the content and compliance with regulatory obligations require further legal assessment.

Can the evidence be presented in legal proceedings?

V-PROOF evidence is designed to be submitted in legal proceedings: it includes cryptographic fingerprints, a verifiable timeline, and a signature from an independent third-party organization, in a format that judges, arbitrators, and expert witnesses can receive and examine. In the EU, evidence cannot be deemed inadmissible solely because it is in electronic format.

The final admission, authentication, and evaluation are the responsibility of the competent authority. The probative value will depend on the identity and reliability of the sources, the context, the chain of custody, and the preservation of the body of evidence.

Is " V-SEAL " equivalent to an eIDAS-qualified timestamp?

V-SEAL It incorporates cryptographic fingerprints, external time stamps, contextual metadata, and may include a signature from an independent third-party organization: structured electronic evidence for verifying integrity and chronology. V-PROOF does not operate as a qualified eIDAS trust service.

A service may be designated as a "qualified service" only if the specific service meets the applicable requirements and is supported by the corresponding qualified provider.

Does it have the same value in all jurisdictions?

The technical ability to verify a digital signature is universal: any system can calculate the SHA-256 hash of the submitted file and compare it with the registered reference. The specific legal effect depends on procedural rules, authentication requirements, and the assessment of the competent authority in each jurisdiction.

For international litigation or transactions, jurisdiction, the identity of the parties, and the rules governing electronic evidence must be reviewed. V-PROOF can provide technical documentation regarding the chain of custody; local legal counsel completes the analysis.

Does it replace a notary, a public registry, or an intellectual property registry?

No. These are mechanisms with their own legal functions and effects. V-PROOF generates frequent and structured technical evidence throughout an asset’s lifecycle: timestamps, versions, approvals, human interventions, and signatures from external agencies, which can complement notarial, registry, contractual, or expert procedures.

It does not replace its legal effects nor does it, on its own, constitute a title of ownership, authorship, or title.

How is it different from Creative Commons and Content Credentials?

Creative Commons provides standardized licenses to specify usage permissions. Content Credentials, based on C2PA, allow signed manifests to be associated with information about the origin, editing, and tools used for specific content.

V-PROOF It is designed to organize evidence of assets, decisions, and controls within corporate processes. These mechanisms are potentially complementary: Creative Commons communicates permissions, Content Credentials document the provenance of content, and V-PROOF preserves evidence of processes, controls, and approvals with a signature from an independent external body.

Data minimization and verifiable architecture.

Should the original file be transferred outside the corporate environment?

In a configuration with local fingerprint calculation, the original file does not need to leave the organization's perimeter. Only the fingerprint and the minimum set of metadata defined for registration and verification need to be transmitted. Assets, models, documents, and datasets remain on internal systems.

The exact data flows, data categories, and destinations are documented and validated prior to going live, tailored to the deployment model and each organization’s security requirements.

Is an “ hash ” considered personal data under the GDPR?

A cryptographic hash is a mathematical transformation that contains neither data from the original asset nor any readable information about individuals. The asset remains within the organization's perimeter; what is produced is an opaque hexadecimal string that does not allow the original content to be reconstructed.

GDPR risks arise primarily from the event metadata—user identifiers, roles, timestamps, and process references—that accompany the log entry. These must be assessed in light of the applicable legal basis, data minimization, purpose, retention period, and data processors.

What roles do IPFS and blockchain play?

A content-based identifier (CID) links the evidence package to its exact version: any modification results in a different CID, making any alteration detectable. Anchoring to an immutable blockchain (L1/L2) creates a public, immutable timeline that reinforces chronological verification and makes retroactive modifications difficult.

Persistence on IPFS requires an active pinning policy. A public network alone does not constitute a qualified timestamp or a legal guarantee; it is an additional layer of independent technical verification.

References published on a public network are observable. The design should avoid including personal or confidential data, or metadata that could lead to unintended inferences.
How are identity, permissions, and human oversight related?

V-PROOF It can receive identifiers, roles, attributes, or tokens provided by corporate identity and access systems. The log links the event to the provided identifier, documenting who took the action, in what role, and at what time.

When an organization has appropriate IAM/SSO, multi-factor authentication, and segregation of duties in place, the chain of evidence can demonstrate the human intervention required by Article 14 of the EU AI Act and by the ISO 42001 and ISO 27001 standards.

Is there any exposure to the CLOUD Act or other foreign jurisdictions?

V-PROOF It operates from Spain under European law, with an architecture that keeps the original assets within the corporate perimeter, thereby significantly reducing exposure to the CLOUD Act compared to providers under U.S. jurisdiction or corporate control.

Hosting, corporate governance, sub-processors, and remote support access must be reviewed for a comprehensive analysis. V-PROOF can provide supply chain documentation during technology and regulatory due diligence.

An evidentiary layer integrated into existing processes.

Is this a new platform that requires migrating workflows?

V-PROOF It is designed to integrate with existing processes and systems so that evidence points can be triggered from enterprise applications, automations, or approval workflows.

It integrates with existing systems without requiring migration or replacement of current platforms. Some deployments may require connectors or minor process changes; the Strategic Assessment defines the actual scope before committing resources.

How long does implementation take?

The initial session of the Strategic Assessment lasts approximately 90 minutes. Afterward, the use case, sources, identities, metadata, evidence points, security requirements, and contractual dependencies are defined.

The Strategic Assessment provides a roadmap that distinguishes a limited proof of concept from an enterprise-wide deployment, with specific timelines and dependencies. The timeline depends on the available APIs, the number of systems, and internal approval cycles.

Should the team manage digital assets or public network keys?

The architecture can abstract interaction with public networks and operate under a corporate contractual model, without requiring the client to acquire digital assets or trade directly on secondary markets.

The management of identities, credentials, and permissions is documented in the integration process. Technical abstraction coexists with access controls, segregation of duties, rotation, and auditing.

What must the Legal, Security, and Procurement departments review before production begins?

Enterprise validation must cover, at a minimum:

  • architecture, data flows, and information classification;
  • GDPR roles, processors, and international transfers;
  • identity, permissions, passwords, logging, and incident response;
  • retention, erasure, portability, and exit plan;
  • SLA, continuity, recovery, support, and change management;
  • audit rights, security evidence, and contractual responsibilities.

The contract must reflect the actual architecture and not be based solely on commercial statements or the supplier's nominal location.

What happens to the evidence if V-PROOF stops providing the service?

The records persist independently of V-PROOF. The SHA-256 hash, the CID on IPFS, the transaction on the blockchain, and the signature from the external entity can be verified using standard tools as long as the referenced data is available and the network is operational.

The contract and architecture must include retention, portability, export, and an exit strategy. Public anchoring reduces dependence on the provider; the portability of the evidence package eliminates the single point of failure.

What does the organization receive upon completion of the Strategic Assessment?

The assessment identifies critical assets and processes, regulatory assumptions, identity sources, points of evidence, dependencies, architectural risks, and implementation priorities.

The result is an executive, legal, and technical roadmap for determining where traceability adds value, what controls must be in place before automating the recording process, and what validations are required for an enterprise-wide deployment.

Access to the protocol

Define your organization's risk-proportionate evidence architecture.

The Strategic Assessment identifies the assets, decisions, and controls that must be verifiable, and defines an evidence framework commensurate with the risk and the regulatory context.