Provenance Lens

Methodology

Every inspector, what it reads, which library and version performs the check, and how each status value is derived. Reproducible and versioned.

Updated: Published by Provenance Lens

Evidence, not guessing

Provenance Lens reports only what can be checked: a cryptographically signed manifest, a metadata field, a specific codepoint, a documented provider mechanism. When a signal cannot be checked, it says so. It never converts silence into a verdict.

Runs in your browser

The check runs in your browser. Your file is not uploaded โ€” it never reaches our servers. You can verify that in your browser's network tab while a scan runs.

Browser report scope

A browser-produced report is a tool for the person running it, not a certificate. It is generated on the user's machine and is not attestable by the operator.

For developers

Install the local scanner. It runs offline, reads the same signals as the hosted version, and emits the same JSON report schema.

Primary sources