Skip to content
AI Website Security
Verify · free, for everyone, forever

Received one of our documents? Verify it without trusting us

Our documents are signed. Anyone — an abuse desk, an insurer, a buyer — can check that signature themselves. No account, no sign-up, and without the file leaving their computer: verification happens in the browser.

The check happens in two stages

A valid signature, and ours: check both.

This is the only way to fool a signed document, and we would rather teach it to you ourselves: anyone can sign a fake with their own key. It will show as “valid”. What sets it apart from one of ours comes down to a single line to compare.

First stage

Is the document intact?

The tool recomputes the signature in your browser. If a single character of the document has been altered — a digit, a date, a file name — verification fails. This part requires trusting no one.

Second stage

Does it really come from us?

The tool displays the fingerprint of the key that signed it. Compare it with the one published below. If the two are not identical, the document may well be intact — but it is not from us.

AI Website Security public key fingerprint · Ed25519

a453 d9ec 0e45 e928 512b 13cd b2eb 3fa1

It is published here, on our site, and not in the document being shown to you — a document carrying its own reference would prove nothing. Note it down, or come back and read it: it does not change.

Try it now

A real document, for you to verify yourself in thirty seconds

Here is a document we actually issued. Download it, open the tool, drop it in: you will see the signature verified in your browser, and the key fingerprint displayed. Compare it with the one above — they must be identical.

1

Download

The sample document, in JSON format. It contains no file paths.

2

Drop it in

In the verification tool. Nothing is sent: the computation happens on your machine.

3

Compare

The displayed key fingerprint must match the one published on this page.

This document concerns a site we operate, it is dated 11 August 2026, and its timestamp comes from a third-party authority. It says “nothing observed” — which is also a way of showing that a favourable finding exists, and that it can be verified like any other.

Read the type first

Three documents, three distinct scopes

Every document states its type in full, and the verification page repeats it before anything else. This is deliberate: the risk is not that a document gets forged, it is that it gets made to say what it does not say.

Certificate

What it asserts

On the date indicated, every executable file inventoried had a named provenance.

What it does not assert

It does not say that the site is secure: it may have a known vulnerability or a stolen password.

Findings

What it asserts

Here is what was observed and what was done, on these dates.

What it does not assert

It does NOT claim that the site is clean. Mistaking it for an attestation is the most costly misreading.

Restoration

What it asserts

During the period indicated, the attested state of the site was not broken.

What it does not assert

It does not say that no intrusion took place anywhere other than in the files.

One notch finer than the signature

Check ONE line, without receiving the inventory

The signature says the document is intact. It does not say that a specific file was indeed part of the state observed that day — and that is precisely what an abuse desk wants to know before restoring a site.

Each named file therefore carries its own certificate: its path, its fingerprint, and the chain of hashes leading up to the attested root. Whoever receives it recomputes and concludes on their own.

What it learns stops there. A certificate contains no other path, no other fingerprint: the list of the merchant's 40,000 files stays with the merchant. It is the same arithmetic that makes proof possible and disclosure impossible.

Beyond twenty files, the certificates are not attached and the document states it plainly: a finding is not an inventory export in disguise. They are then requested one by one.

How it works

The signature proves the document has remained intact. Our honesty, for its part, is judged by what we publish

The document is signed with a key whose public part travels with it. Your browser recomputes the signature from the content: if a single character has been altered — a file path, a date, a number — verification fails.

So no one needs to believe us, or even to know us. That is what makes our documents usable when facing someone who has no reason to trust us — an abuse desk, precisely.

The scope of this page

  • It sends the document nowhere: all computation happens in your browser.
  • It requires no account, no email address, no cookie.
  • It loads no external resources — you can save it and use it offline.
  • It keeps no record of the document you show it.

One caveat, because it matters: a valid signature proves the document really comes from us and that it is intact. It does not prove the site is clean today — for that, you must read the date, and the type.