How it works
Everything we protect against, and everything we do not.
Written for Designated Safeguarding Leads. It sets out what each of our three methods stops, what it does not, where your photographs are processed, and what you can prove after the fact. If you are evaluating us, this is the page to read, and the one to send to whoever asks you the hard questions.
The three methods
You choose one for each photograph. Every photograph is also signed with a verifiable record, whichever method you chose.
The strongest
Face Regeneration
Replaces the face with a synthesised one. The real face of the child is no longer in the file at all.
The default
Face Cloak
Changes what a machine reads from the face, without changing what a person sees. On your news page the photograph looks exactly as it always did.
The visible one
Face Blur
Removes the identifiable face from the image. Obvious to anyone looking, and the method most schools already recognise.
What each one stops
Ordered so the rows that separate the methods sit near the top. A cross is a boundary, not a failure. Where a method is marked Partial, select it to read exactly what we do and do not claim.
| The threat | Face Regeneration | Face Cloak | Face Blur |
|---|---|---|---|
| Learned from by AI training models | |||
| Matched by facial recognition | Partial1 | ||
| A fake image generated from a photograph the school published | |||
| Organised scraping of the school website for extortion | Partial2 | ||
| The photograph still looks like the child to a parent | |||
| Survives printing | |||
| Survives heavy recompression or further editing downstream | Partial3 | ||
| Holds up against a better model in two years | Partial4 | ||
| A photograph a pupil posted from a personal phone |
What Partial means, in each case
1A direct facial recognition match. Face Cloak disrupts AI face scraping and model training. It is not built to defeat a direct one to one match, and our own testing shows such a match can still succeed. Where that matters, use Regeneration or Blur.
2Organised scraping for extortion. Cloaking makes bulk harvesting much harder, because the faces it collects are not reliably readable. Whether it also defeats a generation pipeline run on a single downloaded file is untested, so we do not claim it. Where that risk matters, use Regeneration or Blur.
3Recompression and further editing. Heavy recompression, filtering or cropping can weaken invisible cloaking, because the protection lives in pixel data. The signature still shows the file was altered, even when the cloaking has degraded.
4Future models. No cloaking method is permanent against models that improve every quarter. That is true of every technique published to date, ours included. Protection can be run again as methods improve, which is why we will not attach a fixed number to it.
* Results vary from picture to picture and are based on probability, not a guarantee.
Photo Origin
Topeng can add your school's name and attribution details to a photograph's metadata when it is prepared for publication. This creates a record of the school associated with the image, alongside details of any protection applied and when the photo was processed.
C2PA Content Credentials can be used where separately approved under the school's licence and configured for authorised school accounts.
Photo OriginWhat the record can include
- Your school's name and attribution details
- The protection method applied through Topeng
- When the photograph was processed
- Details of the approved publication workflow
Availability and setup
The record stays with the photograph when it is shared and helps preserve its context. Metadata supports attribution, but it does not by itself establish legal ownership, prevent copying, or stop someone from removing or changing the metadata.
School-issued C2PA credentials require separate approval, an appropriate school licence, and approved signing credentials. Where enabled, the signed export can identify the school associated with the photograph while Topeng remains the processing platform.
Where our responsibility ends
A school is responsible for what the school publishes. What a pupil posts from a personal phone was never a photograph the school published.
Most of the school deepfake cases reported so far did not begin with a school website. They began with the personal social media accounts of pupils, and nothing we sell touches those. The same is true of a photograph someone takes at the gate, and of any image that never passed through Topeng.
We say this plainly because a tool that claims to cover everything is a tool that cannot be checked. Ours covers the photographs you publish, from the moment you publish them.
Where your photographs go
Usually the first question a safeguarding lead asks, so it is answered here before it is asked. The answer is different for different methods, and we would rather you knew that from us.
Face Regeneration
Uses a third party image model through a commercial API. On a commercial API account, your photographs are never used to train or improve their models, and they are never shared with anyone else. That is a contractual commitment from the provider, not a setting we toggle.
Face Cloak and Face Blur
Run entirely inside our own isolated environment. The photograph never leaves infrastructure we control.
Retention
For Cloak and Blur, temporary files are removed with the isolated processing environment once the job finishes. For Face Regeneration, the third party provider may retain the image for a limited period for abuse monitoring, unless zero data retention is in place.
If something is still unclear
We significantly reduce the risk of a photograph of a child being misused by AI. We do not promise to eliminate it, because no honest tool can. If a question on this page is not answered well enough to take to your board, tell us and we will answer it in writing.