Provenance Lens

Changelog

Dated record of detector additions, support status changes, library version bumps and corrections to provider capability claims.

Updated: Published by Provenance Lens

Evidence, not guessing

Provenance Lens reports only what can be checked: a cryptographically signed manifest, a metadata field, a specific codepoint, a documented provider mechanism. When a signal cannot be checked, it says so. It never converts silence into a verdict.

What a report cannot prove

  • A valid signature proves who signed a manifest, not that the manifest's claims are true.
  • Metadata is trivially editable. Treat generator fields as an indication, never as proof.
  • Hidden Unicode characters have many innocent causes, including ordinary copy-paste.

For developers

Install the local scanner. It runs offline, reads the same signals as the hosted version, and emits the same JSON report schema.

Primary sources