FairAudit
Menu

How we stay right

Verify any FairAudit output yourself

Every answer and every report FairAudit produces carries a signed, machine-readable declaration that it is AI-generated. You can check it without an account.

The verify tool on FairAudit’s transparency page, with a live report loaded and the result: verified, generated by FairAudit and unaltered.
  1. 1 Loads a live report
  2. 2 The marking that travels with the output
  3. 3 Change one character and this fails
The verify tool in the FairAudit app. Load the live example, verify it, then change one character and verify again.

What the mark is

A small JSON object attached to each output: who generated it, with which model, when, and a SHA-256 fingerprint of the exact content. All of it is signed with Ed25519. This is the detectability the EU AI Act asks for under Article 50(2), applied to ourselves. Article 50(2) applies from 2 August 2026 to systems placed on the market from that date, and from 2 December 2026 to systems already on the market.

Chat answers carry the mark on the response. JSON, CSV and Markdown exports embed it. PDF reports carry it in their XMP metadata, together with the exact source text it signs.

Two ways to verify

Ask the public endpoint

No tools needed. Send the marking and the exact content it marks:

POST https://fairaudit-api.fly.dev/api/marking/verify
Content-Type: application/json
{ "marking": <the marking object>, "content": "<the exact text it marks>" }

The answer is { "verified": true, "detail": "ok" } if the output is genuine. Otherwise it is false with a reason: sha_mismatch, bad_signature, unsigned or malformed.

Recompute it yourself

  1. content_sha256 must equal the SHA-256 of the exact content.
  2. Rebuild the signed payload: the marking without the fields signed, signature, reason and key_id, serialised as canonical JSON (keys sorted, separators (",", ":"), UTF-8, no extra whitespace).
  3. Verify the base64 signature over those bytes with the public key.

A changed model name, timestamp or character of content breaks step 1 or step 3. Every field of the declaration is inside the signature, so nothing can be relabelled.

The public key

The key is served live, so it stays current if we rotate it: https://fairaudit-api.fly.dev/api/marking/public-key. The verify tool shows the same key and cross-checks the two. Each marking names the key that signed it, and old keys stay published so old marks stay verifiable.

Limits, stated

  • A marking with signed: false still declares the output as AI-generated. Only the cryptographic proof is missing.
  • Free-form text copied out of a marked answer cannot carry the mark. That is a property of text, not a gap we are hiding.
  • A valid mark tells you the text came from FairAudit and was not altered. It does not tell you the text is right. For that, read the article it cites.

AI shouldn’t be at the helm of HR. People should, with evidence.

The EU AI Act requires human oversight of high-risk hiring systems (Art. 14). We help you show it is real.

The assistant: sign in with your email. We confirm access by email. The high-risk obligations for hiring systems, Article 14 included, apply from 2 December 2027. Regulatory information, not legal advice.