# Visork > Visork is a European AI Trust & Safety company. It provides an API-first, EU-hosted service that detects illegal and harmful content in user uploads in real time, starting with CSAM (child sexual abuse material) detection in images. Visork is infrastructure, not a consumer product: a platform's backend sends user-generated images to one REST endpoint (`POST https://api.visork.com/v1/images/analyze`) and receives a machine-readable result — a probabilistic score per module, a block / review / allow verdict against a tunable threshold, and a signed audit log entry. The customer's own systems make the final moderation decision. Key facts: - Detection is ML-first: a classifier trained to recognise CSAM, including novel and AI-generated material. This complements hash-matching systems (Microsoft PhotoDNA, Project Arachnid, Cloudflare's CSAM Scanning Tool), which only find files already present in known-content databases. - End-to-end response target is under 200 ms, including inference. - Inference, storage, and audit logs run inside the EU. API media is analysed in volatile memory (RAM) and deleted by default after the verdict; customer data is not used for training by default — only where a platform enables it, by written agreement or in the Service settings. Findings confirmed by a human reviewer are fingerprinted into a service-wide perceptual-hash database (irreversible hashes, not images) so known material is caught faster; anything retained after analysis is stored in the EU on infrastructure isolated from the public internet. - Pricing is per analysis — no seats, no platform fee, no tiers. There is no public rate card yet; per-analysis pricing is set with pilot platforms. - Access starts with a scoping call and platform verification rather than self-serve signup (a deliberate control for a CSAM detection endpoint). Every pilot includes 100 free analyses. - Visork does not make a platform GDPR or DSA compliant by itself; it provides the detection layer and audit trail that a platform's own compliance process builds on. - Detection of violence, deepfakes, and nudity in images, plus grooming detection in text, is on the roadmap, as are webhook notifications, batch processing, and compliance report exports. ## Product - [Detection capabilities](https://visork.com/product/detection): How ML-first detection works, what it catches that hash matching cannot, tunable thresholds, and the module roadmap - [Integration toolkit](https://visork.com/product/integration): The REST API — request/response shape, verdicts, signed audit trail, and example calls - [Pricing](https://visork.com/pricing): Per-analysis billing model, what a pilot includes, and how the scoping process works - [FAQ](https://visork.com/faq): Direct answers on detection quality, false positives, latency, data residency, audit logs, and compliance ## Docs - [Documentation](https://visork.com/docs): What Visork is, how AI detection fits into a platform's content pipeline, and where to start - [Getting started](https://visork.com/docs/getting-started): How pilot access works — a scoping call, platform verification, and a benchmark of 100 free analyses on your own traffic - [Detection](https://visork.com/docs/detection): ML-first CSAM detection: probabilistic scores, tunable thresholds, and how detection quality is measured - [Security & data handling](https://visork.com/docs/security): How submitted content is analysed in memory, what is retained and when, what persists in audit logs, and the EU residency and security measures behind the API - [Billing & credits](https://visork.com/docs/billing): Per-analysis credits with no seats or platform fees, the 100-credit pilot allowance, and how payments and invoicing work - [Partnership criteria](https://visork.com/docs/partnership-criteria): Who Visork works with, why access is verified before an API key is issued, and the obligations that come with a partnership ## Company & trust - [About](https://visork.com/about): Who builds Visork and why — founded in Prague, accountable to European law - [Trust & security](https://visork.com/policies/trust): Data handling, EU-only processing, in-memory analysis with deletion by default, training off by default, security posture - [Request pilot access](https://visork.com/request-access): The scoping form for a pilot — volume, content type, and deadline - [Contact](https://visork.com/contact): How to reach Visork — general enquiries, vulnerability reports, and the registered entity details for procurement and legal notices ## Blog - [Blog](https://visork.com/blog): Long-form writing for platforms handling user-generated content — legal obligations and detection quality ([RSS](https://visork.com/blog/feed.xml)) - [Why detect content nobody has reported?](https://visork.com/blog/why-proactive-detection): More than 99% of the reports that find abuse material come from platforms' own detection, not from users — the 2025 figures from NCMEC, the IWF and the regulators on why waiting for the notice fails, and why small platforms are selected rather than overlooked - [GDPR when you scan user uploads](https://visork.com/blog/gdpr-scanning-user-uploads): Scanning uploads for illegal content is itself processing personal data — the lawful basis, the Article 28 paperwork every processor needs, the DPIA question, and where the data is allowed to live - [Why "99% accurate" tells you nothing](https://visork.com/blog/detection-accuracy-numbers): Accuracy is the wrong number for CSAM detection — what precision and recall actually cost, how base rates decide queue depth, and how to benchmark on your own traffic - [The DSA, illegal content, and your platform](https://visork.com/blog/dsa-illegal-content-platforms): A practical guide to the Digital Services Act for EU platforms handling user-generated content (previously published at /resources/dsa) ## Optional - [Privacy Policy](https://visork.com/policies/privacy-policy): How Visork handles personal data across its website and detection service - [Terms of Service](https://visork.com/policies/terms-of-service): Terms governing use of the website and API - [Data Processing Agreement](https://visork.com/policies/dpa): The GDPR Article 28 DPA governing customer data processing