It is the first intelligent question every CHRO or CTO asks during an AttestAI demo: if you sell authenticity, how can I verify yours? Legitimate question — and we answer it head-on, because an authenticity tool that refuses audit is a walking paradox. Here are the 7 pillars that make AttestAI results traceable, contestable, and defensible — before a court, a board, or a wronged candidate.
80 / 20
proprietary AttestAI engine / external LLM layer (swappable)
0
black box — every Trust Score point documented with its source URL
7 pillars
that constitute the AttestAI authenticity guarantee
Before the pillars, the implicit question: AI bullshit exists, and it is everywhere. Models that hallucinate, scores that drift, providers who answer "trust me" when asked about method, vendors who hide behind "the model decided" the moment a dispute arises. This opacity is commercially comfortable — and legally untenable since the EU AI Act. AttestAI made the opposite choice, by construction. Here is how.
Pillar 1 — Traceable public sources. AttestAI invents nothing. Every verification points to a public URL anyone can consult: LinkedIn profile, business register (Pappers, Companies House, Crunchbase), press release, conference page, GitHub repository, academic publication. The delivered report cites its sources like a scientific paper. You open the URL, you verify yourself. If a source is wrong or stale, it is immediately detectable — not six months later in court.
Pillar 2 — 80 % proprietary architecture, swappable LLM. AttestAI is not an LLM wrapper. Our proprietary engine — source orchestration, deterministic scoring, journalisation, human oversight, contestation workflow — represents 80 % of the system. The Anthropic Claude Sonnet 4.6 model under DPA Art. 28 only serves as a NLP inference layer for 20 % of tasks: semantic extraction, rephrasing, textual comparison. No fine-tuning on your candidates. If Anthropic disappears tomorrow, changes pricing, or modifies its terms, we switch to another provider in a few days — your method, your history, your audit log remain intact. The dependency is outsourced, the trust never is.
Pillar 3 — Native human oversight. No rejection is ever 100 % automated. Every algorithmic score can be reviewed, contested, and overturned by an HR operator. EU AI Act "limited risk" compliance is not a bolt-on — it is built into the workflow itself. No candidate is eliminated by the machine alone.
Pillar 4 — Immutable audit log. Every verification, every score, every decision is timestamped and journalled to the Article 30 GDPR register standard. You can replay a decision made 3 months ago and see exactly which sources were consulted, the data state at that moment, the resulting score, and who (or what) validated. The log is cryptographically protected — not a modifiable Excel file.
Pillar 5 — Score explainable line by line. No "the model said 73". The Trust Score is the weighted sum of documented criteria: LinkedIn presence, platform tenure, company cross-referencing, title validity, press mentions, date coherence, weak fraud signals. Every point has a source, every weighting is documented, and the detail is delivered to client and candidate alike. The candidate scoring 67 knows why — and can contest point by point.
Pillar 6 — Candidate contestation coded into the workflow. The right to review is not a theoretical clause buried in T&Cs. It is a documented API endpoint and a web page delivered to the candidate at every verification. The candidate contests, the HR operator reviews, the decision is logged. GDPR-compliant (right to object, right to explanation) and EU AI Act-compliant (guaranteed human recourse) — by construction, not by declaration.
Pillar 7 — Vendor contractual guarantee. AttestAI assumes vendor liability. Our DPA Art. 28 is public, our liability clause is too. No deflection to "the algorithm", no exclusion of liability on model outputs. If a verification is shown to be wrong through our negligence, it is our responsibility — not that of an untraceable third-party provider.
Authenticity is not proven in a slide deck — it is proven in an audit log. AttestAI gives you both.
For the CHRO: if a candidate contests a score, you have the log. If the data protection authority asks, you have the Art. 30 register. If your ethics committee wants to audit, you have the source URLs. For the CTO: no black box, documented models, infrastructure hosted on Railway EU + Cloudflare EU, candidate data never used for fine-tuning. For the CFO: the LLM dependency is capped at 20 % of the system and is contractually swappable — no provider lock-in.
Trust is not a marketing argument. It is a verifiable architecture. AttestAI was designed to be auditable, not opaque — because an authenticity tool that refuses its own audit simply has no right to exist on the post-AI-Act European market. Ask the hard questions. We have the documented answers.