RostoRequest invite

Built to be
trusted.

Every Rosto avatar is the likeness of a consenting person, is marked as AI-generated in a machine-readable way, and can be verified, exported, or deleted at any time.

Consent first

An avatar can only be created with an explicit attestation that the photo shows you, or someone who gave you their consent. The attestation is recorded in the avatar's provenance. The uploaded photo itself is kept encrypted only until you accept the result, then deleted.

Marked as AI, verifiably

Every avatar image carries an invisible per-avatar watermark, and every vector avatar embeds a machine-readable provenance record (rosto-aimark/1) stating that the content is AI-generated, with a content hash and a tamper-evident signature. Anyone with an API key can check a file against POST /v1/verify. This is the transparency the EU AI Act's Article 50 asks of synthetic-image systems: marked, machine-readable, detectable.

Your data, your avatar

Serving safety

Avatars are served through rotating capability tokens with per-avatar domain locks, and unapproved avatars are never publicly embeddable. Requests for content that doesn't exist (or isn't yours) are indistinguishable from requests for content that never existed.

Hosting you can leave: Rosto-hosted avatars are delivered from a global CDN and monitored around the clock — and because every avatar exports as a self-hostable bundle, you are never locked in. Take the bundle, host it yourself, and it keeps working without us.

If you embed Rosto

When an avatar fronts an AI agent, tell people they're talking to an AI, and that the face is a synthetic likeness. The embed guide and export bundle include ready-made disclosure text, and the rig can render a built-in disclosure badge.

Terms of service Privacy