File Provenance & Forensics

Drop any file.
Know the truth.

Cryptographic fingerprints, EXIF forensics, AI detection, C2PA provenance verification, pixel-level tamper analysis, and Bitcoin-anchored timestamps — all running on your device, with no data leaving.

Get it on Google Play See what it does
Provexa — Inspect
JPG
press-release-photo.jpg
2.4 MB · image/jpeg · analyzed 0.8s ago
SHA-256 Fingerprint
a5031288855de358380e405e6b0ce44403ed241f6b3ea3bf937ed8fa11057420
EXIF present — camera metadata intact. Canon EOS R5, f/2.8, 1/500s, ISO 400
Editor software detected: Adobe Photoshop 25.0. File was processed after capture.
ELA analysis: 3 hotspot regions with elevated error levels. Possible local compositing.
GPS coordinates present: 48.8566° N, 2.3522° E (Paris, FR). Location embedded.
Creation date 2024-11-15 differs from modification date 2026-03-02 by 473 days.
C2PA Manifest
Signed by Adobe Photoshop · cert chain intact
Verified
50+
Detection signals per file
12
Languages supported
100%
Offline — no data leaves your device
6
File types deeply analyzed
Capabilities

Everything in one drop

No signup, no upload limits, no server. Drop the file and get the analysis. Here's exactly what runs.

🔍
Deep Inspect
Full metadata extraction for images, PDFs, Word/Excel/PowerPoint, and audio/video. EXIF, XMP, IPTC, ICC profiles, and document properties — every field, no omissions.
JPEG · PNG · WEBP PDF · DOCX · XLSX MP4 · AVI · MP3
⚠️
AI Detection
Identifies metadata signatures left by Midjourney, DALL-E, Stable Diffusion, Adobe Firefly, Leonardo AI, Runway, and more. Flags when EXIF claims a camera but the file was AI-generated.
Midjourney DALL-E Stable Diffusion Firefly
🛡
C2PA Provenance
Reads and cryptographically verifies C2PA manifests — the open standard for content provenance backed by Adobe, Microsoft, Google, and Sony. Extracts the signer, claim generator, AI declarations, and full action history. Works offline.
Signature check AI declarations Cert chain
🔬
Pixel-Level Tamper Analysis
Error Level Analysis detects regions of a JPEG with inconsistent compression history — the classic tell of a composited or edited area. Also runs JPEG quantization table fingerprinting and copy-move clone detection.
ELA heat map Quant fingerprint Clone detect
Blockchain Timestamp
Stamps any file's SHA-256 fingerprint to the Bitcoin blockchain via OpenTimestamps. Creates an immutable, independently verifiable proof that you possessed this exact file at this exact moment — no authority can alter or delete the record.
OpenTimestamps Bitcoin anchored QR export
Stamp Verification
Drop a file and its Provexa stamp receipt together. Instantly confirms whether the file is byte-for-byte identical to the version that was stamped — or flags exactly where the hashes diverge.
SHA-256 match SHA-512 match Timestamp decode
🧩
Hidden Payload Scan
Detects data appended after a JPEG's EOI marker, PNG's IEND chunk, or PDF's %%EOF — a classic steganography and polyglot-file technique. Also scans for embedded ZIP, RAR, EXE, ELF, GZIP, and PDF containers hidden inside other files.
Trailing bytes Embedded containers Polyglot detect
🔗
Cross-File Correlation
Drop multiple documents and find hidden links between them: shared XMP Document IDs, PDF trailer IDs, Word RSID session tokens, identical JPEG quantization fingerprints, and common authors. Surfaces document families from the same source.
XMP Document ID RSID tokens PDF trailer ID
📄
Forensic Reports
Export a full analysis as JSON, HTML, or PDF. The Courtroom Exhibit mode produces a plain black-on-white Letter-size PDF with no styling — formatted for filing as a legal exhibit or handing to a judge.
JSON · HTML · PDF Courtroom exhibit Declaration text
How it works

Open the app.
Drop the file.

Nothing to configure. No account. The analysis runs locally on your device in under a second for most files.

1
Drop or select any file
JPEG, PNG, PDF, DOCX, XLSX, PPTX, MP4, MP3, WAV, or any other file. Drag it onto the Inspect tab or tap to browse.
2
Provexa reads the file
SHA-256 and SHA-512 are computed. All metadata is extracted. The pixel engine runs if it's a raster image. C2PA bytes are detected and the manifest is parsed and verified. Nothing leaves your device.
3
Anomalies surface automatically
Each finding is labeled — green for expected/clean, amber for suspicious, red for clear flags. You see the evidence, not just a verdict.
4
Export what you need
Download the analysis as JSON, an HTML report, or a courtroom-ready PDF. Stamp the file to the Bitcoin blockchain. Generate a QR code of the hash. Done.
File evidence-photo.jpg
SHA-256 a5031288…11057420
Camera Canon EOS R5
Software Adobe Photoshop 25.0
GPS 48.856°N 2.352°E
ELA hotspots 3 regions flagged
C2PA Verified ✓
Trailing data None
Who uses it

Built for anyone who needs to prove what's real

Legal
Document authentication
Verify that a file hasn't been altered since it was created. Export a courtroom-ready PDF exhibit. Anchor the hash to the Bitcoin blockchain as tamper-evident proof of possession.
Journalism
Source file verification
Determine whether a photo came from a camera or an AI generator. Check whether metadata was stripped. Identify Photoshop edits from quantization fingerprints before publishing.
Corporate
Contract chain-of-custody
Detect whether a contract PDF was modified after signing by checking incremental save count, modification dates, and PDF trailer IDs across document versions.
Research
Dataset provenance
Correlate files from multiple sources to find shared origins. Detect when documents claiming different authors contain RSID tokens linking them to the same Word session.
Insurance & HR
Evidence integrity
Verify that submitted photos, invoices, and claims haven't been altered. GPS metadata, creation timestamps, and pixel-level ELA catch the most common document manipulation techniques.
Personal
Protect your own work
Stamp your creative work, contracts, or correspondence before sending. If a dispute arises, the Bitcoin-anchored receipt proves you had this exact version before the other party did.

No cloud. No account.
No data leaving your device.

Every analysis runs locally — in the browser's JavaScript engine and a WebAssembly module. Your files are never uploaded. The Bitcoin timestamp is the only network call, and it only ever sends a 32-byte hash, never the file itself.

🔒
Local-first
All computation happens on device. Files never leave.
📡
Offline capable
Works without internet after first install. Full feature parity offline.
🪪
No account
No signup, no login, no tracking, no analytics.
Open standards
SHA-256, C2PA, OpenTimestamps, Bitcoin — all independently verifiable by anyone.

Start with
any file you have.

Free to use. No account. Works offline. Available on Android via Google Play.

Get it on Google Play
by URSx · 100% sovereign · no subscription