Skip to content
WatermarkAudit

Content provenance

Know what your digital content can prove.

Verify provenance, Content Credentials, metadata, and hidden signals — privately in your browser. Drop a file to audit it. No upload, no account, no guesswork.

  • Runs entirely in your browser
  • Nothing is uploaded or logged
  • No account needed

A toolkit, one honest standard

Each tool does one thing well and tells you the truth about its limits. Nothing here pretends to detect what can't yet be detected.

What this proves, and what it doesn't

Provenance tooling is only useful if it is honest about its limits. Here is exactly what a result means.

A valid signature is strong evidence

If a C2PA manifest validates, the file hasn't changed since it was signed, and you know which certificate signed it. A cryptographic guarantee, not a probability.

But it proves a record, not a reality

A credential attests to the file's history: who signed it, and that the bytes are unchanged. It cannot tell you whether what the file depicts actually happened — a signed photograph of a staged scene validates perfectly.

No credentials proves nothing

Most files carry no manifest. Resizing, screenshotting, and nearly every platform strip them. Absence is the internet's default state, not a red flag.

A declared origin is a claim

When a file says AI was involved, that's the producing software disclosing it. Nothing here independently detects AI — and we won't pretend otherwise.

Original research

We measured it rather than assuming

A Google-signed image that declared itself AI-generated, sent seven ways. WhatsApp and Telegram each destroyed the credential when sent as a photo and returned the same file byte-for-byte identical when sent as a document. It is not the service, it is the path through it.

Read the results
2 apps
gave both answers
4 of 7
routes preserved it
1 of 5
edits it survived
0
partial survivals

We call them signals, not “watermarks”

“Watermark” gets used for six unrelated things — a logo, a metadata credential, hidden characters, a statistical text signal. They work differently and prove different things. Here is exactly which we can read today, and which no one can yet.

Provenance signals we read

  • LiveC2PA / Content CredentialsCryptographically verified in-browser.
  • LiveEXIF · XMP · IPTC metadataFully extracted and grouped.
  • LiveInvisible & control charactersDetected across all Unicode categories.
  • LiveFile integrity (SHA-256)Hashed locally, tied to every report.
  • ElsewhereSynthID in OpenAI imagesOpenAI marks its images with SynthID and publishes a checker. Not done here: it would mean uploading your file to OpenAI.
  • Not yetGoogle SynthID, everything elseDetection needs Google's own model. The Content Detection API is in preview with named partners only.
  • Not yetAnthropic text watermarkMarking live since 2 Aug 2026. Detection documentation not yet published, so nothing to build on.
  • Not yetOpenAI text watermarkingBuilt, never shipped. There is nothing to detect in text.

Not yet means the signal genuinely cannot be read by anyone outside the model provider today. Elsewhere means it can be read, but only by sending your file to the provider, which this site will not do on your behalf. When a detector ships that runs without uploading anything, it appears here as live and not before.

A mark tells you a file was processed. Not who wrote it.

Text a person wrote and ran through a model for grammar fixes carries the same mark as text the model wrote outright. Treating a mark as proof of authorship produces false accusations against people who did nothing wrong. Use provenance signals as one input to a human review, never as a verdict.

Read the full explainer