What this can and cannot prove
A file can settle some questions outright and cannot touch others. Knowing which is which is most of what this tool is for.
Solid ground
- Confirming AI origin when the generator labelled its own output
- Verifying a signed C2PA manifest all the way through: the signature, whether it covers this exact file, and whether the certificate leads back to an authority on the official C2PA list
- Recovering prompts, seeds and model names left in the file
- Showing camera body, lens, exposure and GPS
- Spotting generator-preset dimensions and software encoders after metadata is gone
Out of reach
- SynthID. Google DeepMind’s watermark lives in the pixels, not the metadata, and nothing here can read it. Google can: the Gemini app will check a picture you hand it. That does mean handing Google the file, and it only answers for Google’s own tools.
- A verdict from pixels alone. We do not run a classifier and we will not invent a percentage.
- Whether a certificate was withdrawn after it was issued. Revocation and trusted time-stamps need a server to answer, and asking one would mean telling it about your file. Our copy of the trust list is a snapshot; the card shows the date it was taken.
- Anything at all, sometimes. A screenshot of a screenshot carries none of the recorded details, and no file check can change that. The pixels are the one exception: a watermark hidden inside them can survive.
Why there is no percentage
A number feels like an answer, and that is the problem. The same detector that scores in the nineties on an easy test set drops towards a coin flip on images built specifically to look authentic, and the number it shows you looks exactly the same in both situations. Evidence does not have that property: you can see what was found, and see when nothing was.
When the answer is “can’t tell”
This is the most common outcome, and it is not a malfunction. Anything that has passed through a social platform, a messenger or a screenshot has had its metadata removed. The information is gone, and no amount of analysis recovers what is not there. What helps: ask whoever sent it for the original as a file or a document rather than as a photo, look for the earliest copy online rather than a repost, and check whatever the picture is *about*. The address, the company, the claim, because that is verifiable in a way the pixels are not.