About
The tool that tells you when it can't help.
Almost everything in this field is sold with more confidence than the underlying technology can support. Watermark Audit exists to read the signals that are genuinely readable, and to be uncomfortably specific about the ones that are not.
Live demonstration
5 hidden characters in this sentenceThis sentence looks perfectly ordinary to you, and to every reader who has ever seen it.️
It reads perfectly normally. It is not.
That is the whole product in one interaction: something real was there, you could not see it, and now you can. What we will not do is tell you a machine wrote that sentence — because those characters cannot tell us that, and neither can anything else.
Why this exists
In August 2026 the EU AI Act's transparency rules became enforceable, and providers started marking their output. Overnight, a market appeared for tools that check those marks.
Most of it is theatre. Tools advertise “AI watermark detection” while actually searching for zero-width spaces, which are not watermarks. Others return a confidence percentage derived from nothing in particular. The cost of this is not abstract: students get hauled in front of misconduct panels, and freelancers lose contracts, on the strength of numbers that mean nothing.
The genuinely useful signals — cryptographic content credentials, metadata, file integrity — are unglamorous, verifiable, and largely ignored, because they frequently return the boring answer that nothing can be concluded.
This site is built on the belief that the boring answer, delivered honestly, is worth more than a confident one that is wrong.
The one distinction that matters
A watermark proves that content was processed by a model. It does not prove a model authored it.
Someone who writes something themselves and runs it through an assistant for grammar carries exactly the same mark as someone who generated the whole thing from a prompt. Translation carries it. A tidied-up email carries it.
Anthropic says as much in its own documentation: detecting a mark tells you content may have been processed, and does not on its own confirm provenance. Every tool and every page on this site is built to respect that distinction, because ignoring it is how honest people get accused.
The full explanation →Exactly what we read
Not “over 15 types of hidden character.” The precise figure, counted from the scanner's own source rather than asserted in marketing copy:
483
Unicode codepoints detected
37 named individually, 446 across full blocks
6
Categories of hidden character
Zero-width, bidi controls, tag characters, variation selectors, unusual spaces, control codes
0
Bytes of your content sent anywhere
There is no upload endpoint. Verify it in your network tab
And exactly what we can't
This table is on the homepage too, which is unusual — most products keep their limitations somewhere quieter. The “not yet” rows are signals that no independent tool can currently read, ours included. When that changes, the row changes, and not one day sooner.
Provenance signals we read
- LiveC2PA / Content CredentialsCryptographically verified in-browser.
- LiveEXIF · XMP · IPTC metadataFully extracted and grouped.
- LiveInvisible & control charactersDetected across all Unicode categories.
- LiveFile integrity (SHA-256)Hashed locally, tied to every report.
- Not yetGoogle SynthIDGoogle's own detector is waitlisted; no API to build on.
- Not yetAnthropic text watermarkMarking live since 2 Aug 2026; detection docs not yet published.
- Not yetOpenAI text watermarkingBuilt, never shipped — there is nothing to detect.
“Not yet” means the signal genuinely cannot be detected by anyone outside the model provider today. When a real detector ships, it appears here — we won't fake it before then.
Things we will not build
Every one of these is a feature a competitor advertises. Each is omitted deliberately, and each omission costs us traffic from people who wanted the confident answer.
A percentage
No result here will ever say 87% AI. That number would be invented. Every tool that shows you one is converting a guess into a figure because figures feel authoritative.
An authorship verdict
A mark records that a tool touched the text. Someone who wrote an essay and fixed the grammar with a model carries the same mark as someone who generated the whole thing. We will not pretend to tell those apart.
Em dashes as evidence
Em dashes, curly quotes, and the word "delve" are ordinary writing. Treating visible punctuation as a fingerprint is how careful writers get accused of fraud.
Spacing as a watermark
Consecutive spaces and paragraph irregularities are formatting, not marking. Competing tools list these as detection features. They are detecting a typo.
Detection we don't have
We cannot read Claude's, Gemini's, or SynthID's watermarks, so we say so on the front page rather than quietly implying coverage we lack.
Your files
Not stored, not uploaded, not logged. There is no upload endpoint to compromise, because the analysis never leaves your machine.
Don't take our word for it
“Privacy-first architecture” is a phrase anyone can type. Here is how to check ours in under a minute — and the same method works on every tool that makes this claim.
- 1
Open your browser's developer tools and select the Network tab.
- 2
Drop a file into any tool on this site, or paste text into the checker.
- 3
Watch. No request carries your file or your text, because none is ever made.
You will see the analysis engine itself download the first time — a WebAssembly module that does the verification on your machine. That is the point: the code comes to your file, rather than your file going to a server.
Who makes this
An independent project, not affiliated with Anthropic, OpenAI, Google, Adobe, or the C2PA. Nobody in this field is paying us to describe their technology favourably, which is precisely why the descriptions here are less flattering than most.
Every analysis tool is free and will stay free, because it runs on your computer and costs us nothing to provide. Charging for it would mean charging you for your own electricity. If paid plans arrive, they will cover things that genuinely need servers — saved history, shared cases, an API — and never the checking itself.
Found something inaccurate? That is the most useful message you can send, and it gets fixed. hello@watermarkaudit.com