Skip to content

Independent R&D project · Cologne

Back to the research overview

Trust architecture

How evidence stays verifiable across systems and organisations

Confidence assessed per attribute, human verification by a registered attester, open standards that let anyone check a passport, and processing that stays in the EU.

Trust

Trust architecture

In simple terms: the system never just says yes or no. It shows how confident it is in each piece of evidence, and sends anything uncertain to a qualified person to check.

Confidence is assessed per attribute, never as a blanket verdict. High confidence flows automatically; medium confidence is flagged and contextualized and still publishes; an unresolved low-confidence attribute holds issuance of the whole passport until a registered human attester resolves it.

A hash-chained audit trail carries the same trace_id (the identifier tying one evidence trail together, end to end) from ingestion through to the published passport: each entry is linked to the one before it, so editing an earlier entry is detectable by recomputing the chain. The chain is not yet anchored outside the system.

The Confidence Rail: a green signal always means verified evidence, never decorationThree confidence tiers stacked on a rail: high evidence flows automatically, medium is flagged and contextualized and still publishes, and an unresolved low attribute holds issuance of the whole passport until a registered human attester resolves it.The Confidence Rail: a green signal always means verified evidence, neverdecorationHIGHevidence complete & consistent → flows automaticallyMEDIUMminor gaps → flagged, contextualizedLOWinsufficient basis → blocked until a registered human attesterverifiestrace_id carried end-to-end · hash-chained audit trail, edits to earlier entriesdetectable · AI-assisted, human-verified

Trust

The human verification

A low-confidence attribute is never rejected by a machine, and never waved through in the dark. It is checked by a qualified person who puts a name to the check. AI-assisted, human-verified gets a face.

A registered attester verifies evidence. Verifying is not certifying: under the EUDR (EU Deforestation Regulation), the duty of due diligence stays with the operator, always. A third party's verification adds evidentiary weight to the dossier; it does not replace the operator's own responsibility. The attester confirms or corrects what the evidence shows, and takes on technical responsibility for that verification, nothing more.

In Brazil, the leading figure is a CREA-registered agronomist, whose ART (Anotação de Responsabilidade Técnica) fixes personal technical responsibility by law and can be checked in a public registry. Alongside that role, officers who sign Brazil's phytosanitary certificates (MAPA (Brazilian Ministry of Agriculture)) can verify origin attributes, and on the European side, auditors and experts can provide assurance aimed at the importer. A public registry plus personal liability is what turns a signature into evidentiary weight: the person behind it is identifiable, checkable, and answerable, never anonymous.

The agronomist who already serves Brazil's coffee farms and the assurance a European roaster already recognizes are the two human ends of the same corridor.

From uncertain evidence to a signed credentialLow-confidence evidence is checked by a registered attester, identifiable in a public registry and personally accountable, producing a signed conformity credential.Low-confidenceevidenceRegistered attesterPublic registry · personalliabilitySigned conformitycredentialUNTP DCC

This is a role AnyLAI expects to open, not one you can join today. Share a non-binding note of interest via the contact form.

Sovereignty

Standards & hosting

AnyLAI is the project; AnyDPP is what it builds and demonstrates in the Brazil-EU coffee corridor.

  • Digital Product Passports aligned with the UNTP (UN Transparency Protocol) Digital Product Passport profile v0.7.0 and built on W3C (World Wide Web Consortium) Verifiable Credentials, with GS1 (GS1, the global standards body for product identifiers)-compatible identifiers.
  • Hosted and processed within the EU.
  • This site sets no cookie except the one remembering your own language choice. No trackers, no third-party requests.
  • Deforestation-risk screening by remote sensing remains with the operator's platform; AnyLAI composes and verifies the documentary evidence pack (NF-e (Brazilian electronic invoice), CAR (Rural Environmental Registry (Brazil)), MAPA (Brazilian Ministry of Agriculture)) that feeds this screening. This is a deliberate focus, not a missing feature: satellite and geospatial data are commoditized public infrastructure that AnyLAI consumes as a source, while signed evidence, checkable against its sources, is the layer AnyLAI is built to provide.

Importing at scale and evaluating suppliers under the EUDR? A closer look at what the legality requirement covers, and why Brazil's own legal obligations already produce an unusually complete documentary trail.

Read the importer's guide to Brazil's evidence

The same passport format also means it can be checked without any access to AnyLAI's database:

Verifiable outside AnyLAIA signed passport built on UNTP, W3C Verifiable Credentials and a GS1 QR code, checked by three kinds of outside systems: the buyer's own system, a regulatory authority, and any other verifier. None of them needs access to AnyLAI's database; each resolves the issuer's public identifier document to obtain the key it checks against.Verifiable outside AnyLAISigned passportUNTP · W3C VC · GS1Buyer's own systemRegulatory authorityAnother verifiersystemChecked using open standards; none of the three needs to reach AnyLAI to do it.

Sovereignty

Data sovereignty by architecture

In simple terms: your documents are processed on AnyLAI's own server in the EU, and never sent to an outside AI service.

Export documents carry trade secrets: volumes, prices, origins, counterparties. Where that data travels is part of whether the evidence can be trusted.

AnyLAI processes documents with AI that runs on our own server in the European Union. Document data is never transmitted to a third-party model, inside or outside the EU. There are no external AI calls in the processing pipeline: sovereignty by architecture, not by contract.

The original tax document stays with the exporter in Brazil, under the retention Brazilian law requires. AnyLAI processes the compliance evidence in the EU, where it is used, without passing it on to third parties.

Compliance evidence may one day face an auditor's question: where has this data been? Evidence that never left one European server has a short answer.

This page makes no third-party requests. Open your browser's developer tools and check: every request stays on anylai.eu.

The sovereignty perimeterA perimeter labeled EU server, Germany, contains four stages in sequence: document intake, local AI processing, human review, and the signed passport. Outside the perimeter, three greyed-out elements, third-party AI APIs, non-EU clouds, and trackers and analytics, each reach toward it and are blocked before crossing the edge.The sovereignty perimeterEU server · GermanyDocument intakeAI processing(local)Human reviewSigned passportThird-party AI APIsNon-EU cloudsTrackers & analyticsNo external AI calls · data remains in the EU · verifiable in your browser