How it works

Every answer, traced back to the thing it rests on.

This is the long version. What we look for in a document, the order we trust things in, and the rules that stop a weak clue turning into an accusation.

What we look for

A document can carry four kinds of clue. They are not equally good, and that difference matters more than anything else on this page. Two of them are evidence. Two of them are guesses.

What it isWhat it can tell youHow much we lean on it
A signed record attached to the file
Content Credentials, the C2PA standard
That a particular tool or company made or handled this file, and that nobody has altered it since.A lot. It is a signature, and we check it against a published list of who is allowed to sign. It is also easy for anyone to strip out, so its absence tells you nothing at all.
A hidden marker in AI-written text
SynthID and similar
That the text is consistent with having come from a particular AI system.A lot, when we can read it. Today that means markers made with keys we hold. We cannot read Google’s or Anthropic’s production watermarks: each needs its owner’s own detector, and we have access to neither.
A record the author kept while writing
a signed chain of drafts
That this person demonstrably produced the drafts that led to the finished document.A lot, for anyone who set it up in advance. Which is the catch, and there is a section about it below.
A guess from the writing style
statistical detectors
That the prose reads, statistically, somewhat like AI output.Very little, deliberately. This is a lead for a person to look into, never an answer. We cap how far it can move a result.

Two rules we do not bend

RULE ONE

Evidence beats guesswork

If the document carries a signature or a marker, that decides the answer. A style detector, however confident it sounds, can never on its own make a result "confirmed". What a document actually carries outranks an inference about how it reads.

RULE TWO

Finding nothing is not a finding

No watermark does not mean a human wrote it. Most writing carries no watermark, short passages carry too little to read, and rewriting removes what was there. When we find nothing, we say we found nothing. We never translate that into "human-written", because it does not mean that.

What happens to your document

STEP 1

Every check runs on its own

Checks run separately, and one failing cannot take the others down. A check that could not run is shown to you as a check that did not run. It never quietly disappears.

STEP 2

The weak checks get their wings clipped

Where a style detector is used, we weight it by how often it is wrong in our own testing, not by the accuracy its vendor advertises. Those two numbers are usually far apart.

STEP 3

The answer is assembled, evidence first

A signature or marker drives the answer. Without one, the most you get is a lead worth a human look, and the result says exactly that.

Your document is never written to disk, and nothing about what it says goes into our logs. We keep sizes and outcomes so we can tell whether the service is working. We do not keep your manuscript.

The one thing that has to happen in advance

To be able to prove you wrote something, you have to start keeping the record before anyone questions you. A signed chain of drafts is strong evidence. It is also impossible to create after the fact, and we will not pretend otherwise. If you come to us the day after an accusation with nothing but the finished file, we can tell you what that file carries, and if it carries nothing, that is the honest end of it.

Better to say that plainly now than sell you something that turns out to be useless on the one day you need it.

What you get back

An answer, the evidence behind it, and a certificate sealing the two together so the check itself can be re-examined later by somebody who does not trust us. That last part is the point. A verification you have to take on faith is worth very little, especially to a compliance officer or an academic panel who will be asked how they reached a decision.

Where this stands today

The certificate scheme works end to end and is tested, including against the public checker we ship. What does not exist yet is production key custody: the signing key is not yet held in dedicated hardware. Until it is, no certificate we issue should be treated as a production credential. We would rather put that on the page describing the feature than in a footnote elsewhere.

See a sample result →   or   how we measure what actually works →