Skip to main content
Trust & compliance

Data Provenance Framework

How training data is legally sourced, consented, collected to SOP, de-identified, QA'd and delivered with documented evidence — provenance tracked per record.

Data provenance is the documented story of how a dataset came to exist — where each record was sourced, the consent behind it, how it was collected to a standard procedure, how personal information was removed, and how it passed quality assurance before delivery. This framework tracks that story per record so the dataset stays auditable, consented and defensible end to end.

Why provenance matters

How is training data legally sourced and consented?

A model inherits the legal and ethical posture of its data. If a corpus cannot show where it came from or whether contributors agreed to its use, it is a liability no matter how large it is. Provenance turns a pile of files into a dataset a buyer can stand behind in a compliance review.

Sourcing with rights and consent

Data is sourced from contributors and channels with the rights to provide it. Informed consent is captured in the contributor's own language and recorded per contributor, so usage rights are explicit rather than assumed.

Collection to a documented SOP

Collection follows a structured standard operating procedure — the same discipline behind our collection methodology — so every record carries the metadata needed to audit it later.

De-identification and quality assurance

Personal information is removed through our PII-scrubbing pipeline, then the data passes multi-layer QA with native-linguist review before sign-off. Keeping data resident and consented is what makes a proprietary, sovereign dataset responsible to build.

The provenance lifecycle

From source to documented delivery

Each stage has a control and produces an artifact. The same lifecycle scales from a single-language pilot to a managed multilingual program.

  1. 1

    Source

    Identify contributors and channels with the rights to provide the data, scoped to the use case.

    Rights to source confirmed

  2. 2

    Consent

    Capture informed consent in the contributor's language, recorded per contributor.

    Consent captured per contributor

  3. 3

    Collection (SOP)

    Collect to a documented standard operating procedure with metadata captured per record.

    SOP + metadata enforced

  4. 4

    De-identification

    Strip personal information — faces, license plates, names and other PII — via the scrubbing pipeline.

    PII removed + manual audit

  5. 5

    Multi-layer QA

    Native-linguist and multi-stage validation against the agreed quality bar.

    Multi-layer QA sign-off

  6. 6

    Documented delivery

    Deliver with a data card recording provenance, consent basis and quality evidence.

    Provenance documented per record

Stage, control, evidence

Provenance controls and artifacts

What happens at each stage, the control that governs it, and the evidence or artifact it produces for audit.

StageControlEvidence / artifact
SourceSourcing scoped to rights-holding contributors and channelsSourcing record / rights basis
ConsentInformed consent captured in the contributor's languageConsent record per contributor
Collection (SOP)Structured SOP with metadata captured per recordPer-record metadata log
De-identificationAutomated PII detection and redaction plus manual auditRedaction / audit log
Multi-layer QANative-linguist review and multi-stage validationQA report against the quality bar
Documented deliveryDelivery with a documented data cardData card: provenance, consent basis, quality metrics

Representative controls and artifacts. Acceptance thresholds, residency and the applicable consent basis are scoped per engagement — no fixed figures are implied here.

Related work

Provenance in practice

  • Sovereign data

    Residency, consent and provenance for regulated and government programs.

    Learn more
  • PII scrubbing

    How faces, plates and names are removed before delivery.

    See the pipeline
  • Collection methodology

    The SOP behind balanced, documented, auditable corpora.

    Read more

About data provenance

Questions about provenance and consent

How is consent captured?

Informed consent is captured in the contributor's own language and recorded per contributor, so usage rights are explicit rather than assumed.

What evidence do you deliver with a dataset?

A documented data card recording provenance, the consent basis and quality evidence, with per-record metadata behind it for audit.

Can provenance be kept India-resident?

Yes. Provenance, consent and storage can be kept in-jurisdiction. See Sovereign data for the residency posture.

Build a dataset with provenance from the first record.

Tell us the data types and markets — we'll scope sourcing, consent and QA against this framework.