How it works

Everything we protect against, and everything we do not.

Written for Designated Safeguarding Leads. It sets out what each of our three methods stops, what it does not, where your photographs are processed, and what you can prove after the fact. If you are evaluating us, this is the page to read, and the one to send to whoever asks you the hard questions.

The three methods

You choose one for each photograph. Every photograph is also signed with a verifiable record, whichever method you chose.

The strongest

Face Regeneration

Replaces the face with a synthesised one. The real face of the child is no longer in the file at all.

The default

Face Cloak

Changes what a machine reads from the face, without changing what a person sees. On your news page the photograph looks exactly as it always did.

The visible one

Face Blur

Removes the identifiable face from the image. Obvious to anyone looking, and the method most schools already recognise.

What each one stops

Ordered so the rows that separate the methods sit near the top. A cross is a boundary, not a failure. Where a method is marked Partial, select it to read exactly what we do and do not claim.

The threatFace RegenerationFace CloakFace Blur
Learned from by AI training models
Matched by facial recognitionPartial1
A fake image generated from a photograph the school published
Organised scraping of the school website for extortionPartial2
The photograph still looks like the child to a parent
Survives printing
Survives heavy recompression or further editing downstreamPartial3
Holds up against a better model in two yearsPartial4
A photograph a pupil posted from a personal phone

What Partial means, in each case

1A direct facial recognition match. Face Cloak disrupts AI face scraping and model training. It is not built to defeat a direct one to one match, and our own testing shows such a match can still succeed. Where that matters, use Regeneration or Blur.

2Organised scraping for extortion. Cloaking makes bulk harvesting much harder, because the faces it collects are not reliably readable. Whether it also defeats a generation pipeline run on a single downloaded file is untested, so we do not claim it. Where that risk matters, use Regeneration or Blur.

3Recompression and further editing. Heavy recompression, filtering or cropping can weaken invisible cloaking, because the protection lives in pixel data. The signature still shows the file was altered, even when the cloaking has degraded.

4Future models. No cloaking method is permanent against models that improve every quarter. That is true of every technique published to date, ours included. Protection can be run again as methods improve, which is why we will not attach a fixed number to it.

* Results vary from picture to picture and are based on probability, not a guarantee.

Photo Origin

Topeng can add your school's name and attribution details to a photograph's metadata when it is prepared for publication. This creates a record of the school associated with the image, alongside details of any protection applied and when the photo was processed.

C2PA Content Credentials can be used where separately approved under the school's licence and configured for authorised school accounts.

A protected class photograph, carrying its Photo Origin recordPhoto Origin

What the record can include

  • Your school's name and attribution details
  • The protection method applied through Topeng
  • When the photograph was processed
  • Details of the approved publication workflow

Availability and setup

The record stays with the photograph when it is shared and helps preserve its context. Metadata supports attribution, but it does not by itself establish legal ownership, prevent copying, or stop someone from removing or changing the metadata.

School-issued C2PA credentials require separate approval, an appropriate school licence, and approved signing credentials. Where enabled, the signed export can identify the school associated with the photograph while Topeng remains the processing platform.

Where our responsibility ends

A school is responsible for what the school publishes. What a pupil posts from a personal phone was never a photograph the school published.

Most of the school deepfake cases reported so far did not begin with a school website. They began with the personal social media accounts of pupils, and nothing we sell touches those. The same is true of a photograph someone takes at the gate, and of any image that never passed through Topeng.

We say this plainly because a tool that claims to cover everything is a tool that cannot be checked. Ours covers the photographs you publish, from the moment you publish them.

Where your photographs go

Usually the first question a safeguarding lead asks, so it is answered here before it is asked. The answer is different for different methods, and we would rather you knew that from us.

Face Regeneration

Uses a third party image model through a commercial API. On a commercial API account, your photographs are never used to train or improve their models, and they are never shared with anyone else. That is a contractual commitment from the provider, not a setting we toggle.

Face Cloak and Face Blur

Run entirely inside our own isolated environment. The photograph never leaves infrastructure we control.

Retention

For Cloak and Blur, temporary files are removed with the isolated processing environment once the job finishes. For Face Regeneration, the third party provider may retain the image for a limited period for abuse monitoring, unless zero data retention is in place.

If something is still unclear

We significantly reduce the risk of a photograph of a child being misused by AI. We do not promise to eliminate it, because no honest tool can. If a question on this page is not answered well enough to take to your board, tell us and we will answer it in writing.