Provenance Lens
Methodology
Every inspector, what it reads, which library and version performs the check, and how each status value is derived. Reproducible and versioned.
Evidence, not guessing
Provenance Lens reports only what can be checked: a cryptographically signed manifest, a metadata field, a specific codepoint, a documented provider mechanism. When a signal cannot be checked, it says so. It never converts silence into a verdict.
Runs in your browser
The check runs in your browser. Your file is not uploaded โ it never reaches our servers. You can verify that in your browser's network tab while a scan runs.
Browser report scope
A browser-produced report is a tool for the person running it, not a certificate. It is generated on the user's machine and is not attestable by the operator.
For developers
Install the local scanner. It runs offline, reads the same signals as the hosted version, and emits the same JSON report schema.