How we stay right
Verify any FairAudit output yourself
Every answer and every report FairAudit produces carries a signed, machine-readable declaration that it is AI-generated. You can check it without an account.
- 1 Loads a live report
- 2 The marking that travels with the output
- 3 Change one character and this fails
What the mark is
A small JSON object attached to each output: who generated it, with which model, when, and a SHA-256 fingerprint of the exact content. All of it is signed with Ed25519. This is the detectability the EU AI Act asks for under Article 50(2), applied to ourselves. Article 50(2) applies from 2 August 2026 to systems placed on the market from that date, and from 2 December 2026 to systems already on the market.
Chat answers carry the mark on the response. JSON, CSV and Markdown exports embed it. PDF reports carry it in their XMP metadata, together with the exact source text it signs.
Two ways to verify
Ask the public endpoint
No tools needed. Send the marking and the exact content it marks:
POST https://fairaudit-api.fly.dev/api/marking/verify
Content-Type: application/json
{ "marking": <the marking object>, "content": "<the exact text it marks>" }
The answer is { "verified": true, "detail": "ok" } if the output is genuine.
Otherwise it is false with a reason: sha_mismatch,
bad_signature, unsigned or malformed.
Recompute it yourself
content_sha256must equal the SHA-256 of the exact content.-
Rebuild the signed payload: the marking without the fields
signed,signature,reasonandkey_id, serialised as canonical JSON (keys sorted, separators(",", ":"), UTF-8, no extra whitespace). - Verify the base64
signatureover those bytes with the public key.
A changed model name, timestamp or character of content breaks step 1 or step 3. Every field of the declaration is inside the signature, so nothing can be relabelled.
The public key
The key is served live, so it stays current if we rotate it:
https://fairaudit-api.fly.dev/api/marking/public-key. The verify tool shows
the same key and cross-checks the two. Each marking names the key that signed it, and old
keys stay published so old marks stay verifiable.
Limits, stated
-
A marking with
signed: falsestill declares the output as AI-generated. Only the cryptographic proof is missing. - Free-form text copied out of a marked answer cannot carry the mark. That is a property of text, not a gap we are hiding.
- A valid mark tells you the text came from FairAudit and was not altered. It does not tell you the text is right. For that, read the article it cites.
AI shouldn’t be at the helm of HR. People should, with evidence.
The EU AI Act requires human oversight of high-risk hiring systems (Art. 14). We help you show it is real.
The assistant: sign in with your email. We confirm access by email. The high-risk obligations for hiring systems, Article 14 included, apply from 2 December 2027. Regulatory information, not legal advice.