Media and platforms · Trust and safety data
Every label knows its policy line. Every face said yes.
Moderation data an audit can trace to your policy, detection pairs the depicted person consented to, and research, verification and content systems with a person at the gate. Reviewed, built and run in the EEA.
The three questions Which line · who reviewed · lawfully
A classifier that flags is easy. Three things make its data usable
Whether the label points to a line of your policy. Whether the person who decided was protected. Whether the pair can lawfully exist.
-
Which policy line does the label point to?
HA1 · repeated targeting of a named person · remove
Every label in the delivery points to one clause of your policy taxonomy, the reviewer's decision sits beside the model's flag, and the two are measured against each other with kappa rather than a percentage, so an audit can trace any decision to the line it was made under.
-
Who reviewed it, and how were they protected?
Reviewer r-218 · exposure 4 of 6 · queue paused
Graphic items arrive blurred and are revealed only by the reviewer's choice, every reveal counts against a per-session cap, and the queue pauses when the cap is reached. The protocol is written before the first item, the reviewer can opt out of a queue without penalty, and the wellness ledger travels with the delivery.
-
Can the pair lawfully exist?
Consent c-4471 · depicted person · voice clone vc-2210
A detection dataset is made of real people. Every real-versus-generated pair carries the consent of the person depicted, a separate consent where a voice is cloned, the generator and its version, and the compression and re-encoding the pair has been through, so a reviewer can trace any pair to the consent of the person depicted.
What YPAI labels, evaluates and builds Six engagements · data and systems · one policy at a time
Start from the policy your platform has to enforce
Three data engagements and three systems, each bought on its own and configured for one policy, one taxonomy and one language set. Four things are settled before the first item, whether it is labelled or built.
Agreed before the first item
- The policy taxonomy, clause by clause
- The reviewer protocol and its exposure cap
- Consent, provenance and residency
- What the record per item contains
-
Content moderation training data
Multilingual, multimodal labels that point to a clause of your policy, reviewed under a wellness protocol.
Text, image, audio and video items labelled against your policy taxonomy across hate speech, harassment, sexual content, violence, self-harm, fraud and the categories only your platform has, by identity-verified reviewers in the languages your platform runs in. Two reviewers where the protocol asks for it, agreement measured as kappa per clause, and disagreements adjudicated rather than averaged.
-
Detection pairs and integrity evaluation
Real and generated recordings of the same consenting person, and a study that says what people and models actually catch.
Provenance-tagged real-versus-generated pairs across face, full body and voice, with the person's consent for the recording and a separate consent for the clone, the generator and its version, and the compression, re-encoding and cropping the generated side has been through. Then a human-perception study under a written protocol: raters judge pairs blind, agreement is measured, and the result is reported by generator, post-processing and subject rather than as one number.
-
Video annotation for platforms
Events, tracking and action labels on the video your platform hosts, with the tracking quality reported.
Multi-object tracking, video object segmentation, temporal events and action localisation on the video your platform hosts, under a written task protocol with HOTA and IDF1 reported per delivery, so a safety, recommendation or highlight model is trained on labels with their quality attached.
-
Source desks and verification systems
A research pipeline that extracts every checkable claim in a draft and anchors it to a source a journalist approves.
Research and intelligence systems for a newsroom or a verification desk: ingestion of filings, transcripts, datasets and reports, evidence extraction, monitoring, and grounded answers with citations and source traceability. The pipeline proposes the anchor; a person approves it, and the approval is in the record. Built and run in the EEA, on your environment where the archive cannot leave it.
-
Content and marketing pipelines
Generation, refresh and outreach in your house voice, with a person at the gate and the model in the EEA.
Programmatic and research-based content production, content refresh and structured publishing workflows, outreach and enrichment automation, and conversational assistants, integrated with your CMS and your data. A house-voice model fine-tuned on your own material and evaluated against a held-out set, deployed EEA-resident or in your environment, with an approval gate before anything is published.
-
Moderation agents with an audit trail
Agent workflows that route, escalate and explain, with human gates and a replay a regulator can read.
Agent state machines for moderation and trust-and-safety operations: routing by policy clause, escalation to a person at the gates the policy names, retry and fallback, and deterministic replay of every action. An audit-log layer with EU AI Act risk mapping and policy-anchored gating, so the record of why an item was actioned can be produced for a review.
Try it yourself: the review queue For the trust and safety lead · one policy · the record per decision
Sit the queue. Decide with the clause. Read what leaves
You are the reviewer. Twelve items come to you as descriptions of what they contain, never the content. The model's flag is shown with its confidence score, a second reviewer has decided blind, and you decide with a clause. Agreement is measured as kappa, and the wellness ledger counts every reveal.
-
The clause is the label.
Every label points to one line of the policy, and the line is what a reviewer, a model and an audit compare.
-
Kappa, not a percentage.
Agreement between the reviewer and the model, and between two reviewers, is reported as kappa, which discounts the agreement two raters would reach by chance.
-
A reveal is counted.
Graphic items are blurred until the reviewer chooses to see them. Every reveal is written to the wellness ledger, and the cap pauses the queue.
The item
A comment on a sports result with strong language and no target
Model flag SY1 Model confidence 0.62
Reviewer two
Your decision
Pick the clause the item breaks, or keep it.
This session
- Decided
- 0
- Escalated
- 0
- Exposures
- 0 / 6
Agreement as kappa
- vs the model none
- vs reviewer two none
Judge the pair For the detection team · two raters · by post-processing
Two recordings of one person. Which one is generated?
You are rater one. Each pair is a real and a generated toy signal of the same consenting subject, with the generator, the post-processing and the consent on the tag. Rater two has judged blind. Your accuracy, theirs and your agreement are reported with denominators and cut by post-processing, which is what a detection team needs to know where its detector and its people are weakest.
The pair
Pick the side you think is generated. The tag is revealed when you have.
The tag
- Pair
- none
- Subject
- none
- Generator
- none
- Post-processing
- none
- Consent
- none
- Voice clone consent
- none
- Rater two
- none
This study
- Judged
- 0
- You
- none
- Rater two
- none
- Agreement
- none
Correct by post-processing
- None none
- H.264 none
- Resampled none
- Cropped none
- Noise none
Approve the anchor For the verification desk · every claim · a source a person approves
A draft comes in. Every checkable claim leaves with a source
You are the journalist. An invented draft of eight sentences is on the desk. The pipeline has marked which sentences make a checkable claim, anchored each to the best document in a small corpus with a plain overlap score, and left opinion unsupported. You approve or reject every anchor, and the approval is what leaves.
The draft
The anchor
Pick a sentence in the draft.
- Source
- none
- Kind
- none
- Date
- none
- Overlap
- none
What the source says
Pick a sentence in the draft.
This desk
- Checkable
- 6
- Anchored
- 6 / 6
- Approved
- none
- Rejected
- 0
- Unsupported
- 2
Anchored Weak anchor No source found Approved Rejected Opinion · not checkable
Who we label for Platform × policy family · configured per programme
Six kinds of platform. What the programme covers for each
A video platform, a marketplace and a newsroom do not fail in the same places. The matrix shows which policy families the programme covers for each kind of platform, in which modalities and languages, and which demo on this page shows the method.
Real-versus-generated pairs and authenticity review for a verification desk, with the generator and the post-processing on the tag, and a research desk that anchors every claim to a source.
Clauses this row turns on SY1
- In the programme by default
- On request
- Its own protocol
- Out of scope by default
Configured per platform and policy. Try the demo named in each row to see its method. Nothing on this page is a real delivery or a real result.
What the delivery contains One row per decision, judgement and anchor · the fields an audit checks
One record. The queue, the study and the desk write to it
Every decision from the queue with its clause, every judgement from the study with its tag, and every anchor the desk approved with its source, in one record with the second rater, the time and whether it counted. Written by what you did above.
Read a row left to right: the kind of entry and its id, what was decided under which clause, source or tag, then the model's flag or score, the second rater's call, the seconds it took, and on the right whether the row counted toward the wellness ledger, the study or the piece.
- No entries yet. Decide an item in the queue, judge a pair or approve an anchor above.
- Decided
- 0
- Exposures
- 0
- Pairs judged
- 0
- Anchors approved
- 0
Example record, built from what you ran above
The first queue One policy · one language · one protocol
One policy, one language, one reviewer protocol
A pilot labels one policy in one language under one reviewer protocol, and judges one pair set. The taxonomy, the protocol and the record's fields are fixed before the first item, and the pilot ends with a delivery your safety team can audit and a decision. You judge it against your model.
Fixed before the first item: the policy taxonomy, clause by clause, the reviewer protocol and its exposure cap, consent, provenance and residency, the kappa floor below which a clause is re-briefed, and what the record per item contains.
-
Policy
Your taxonomy mapped clause by clause, with the examples each clause turns on.
-
Protocol
Blur by default, the exposure cap, rotation and opt-out, written and signed before the first item.
-
Queue
One language labelled by identity-verified reviewers, two where the protocol asks, kappa per clause.
-
Pairs
Real-versus-generated pairs with consent and provenance, judged blind and reported by post-processing.
-
Decision
Continue to the full policy, change the taxonomy, or stop, with the record as the evidence.
The pilot ends with a delivery your safety team can audit.
Consent, reviewers and residency GDPR · reviewer wellness · EEA
The controls a review of trust-and-safety data will ask for
A Norwegian company under GDPR. Every real recording carries the depicted person's consent, reviewers are identity-verified and work under a written wellness protocol in our own review console, and the material is stored in Europe by default and processed in the EEA where required.
- Jurisdiction
- Norway · GDPR-native
- Lawful basis
- Consent per record · Article 6
- Reviewers
- Identity-verified · EEA-resident · wellness protocol
- Languages
- All European languages · Nordic depth · MENA and selected global
- Exposure
- Blur by default · per-session cap · opt-out
- Console
- Our own review console · the ledger in the delivery
- Audit
- A decision record per item · exportable for a review
- Provenance
- Generator, version and post-processing on every pair
- Contracts
- Standard DPA terms · SCCs available
- Erasure
- 30-day end-of-contract SLA
Scope a programme A feasibility read · a bounded first queue
Tell us the policy and the platform
We scope against the policy your platform has to enforce, agree the taxonomy, the protocol and the consent model, and test the method on one policy in one language.
- Scope
- Taxonomy
- Protocol
- First queue
- Delivery
A bounded first queue carries its own acceptance criteria and its own record. You judge it against your model.
Briefs are treated as confidential. We are used to policies that cannot be published and material that cannot leave the EEA.
The brief Tell us the platform, the policy and the languages, and what the model has to catch. We reply with a feasibility read.