Skip to the console

ClearGlass Truth Forensics · evidence integrity console

Truth is an evidence graph.

Hash it. Trace where it came from. Test what it says against sources that did not share its pipeline. Then let a person decide. This console does all four in your browser, and shows exactly where the analysis stops.

  • VERIFIED
  • SUPPORTED
  • INCONCLUSIVE
  • UNVERIFIED
  • SIMULATED / DEMONSTRATION
  • NORMAL
  • REVIEW REQUIRED
  • ANOMALY DETECTED
  • CORROBORATION CONFLICT
  • PROVENANCE GAP
  • CRYPTOGRAPHICALLY VERIFIED

What this is not. The ClearGlass Truth Forensics system provides analytical indicators and provenance analysis. It does not independently establish the truth of real-world events and should not replace qualified forensic, legal, investigative, or evidentiary review.

Privacy. Files you add are read into this tab's memory, hashed and analysed here. They are never uploaded, stored, logged or sent to an AI service. Close the tab or press “Clear session” and they are gone. This page's Content-Security-Policy blocks connections to any other origin.

Live demonstration

DEMONSTRATION DATA — NOT REAL EVIDENCE

Ten synthetic items about a fictional depot and a fictional forklift. No people appear and no real event is described. Every file was generated from fixed arithmetic by python -m truth_forensics demo, and each subsystem has something real to find: a two-second frame gap, a cloned image region, exact digital silence in audio, a byte-identical copy that must not count twice, a camera clock seven seconds off, and a reposted photo whose dock sign was edited.

Run it, read the claim assessment, then open Human review and apply the demonstration reviews to watch the final status change and the audit trail record why.

Loads about 480 KB of synthetic files from this site. Analysis runs in your browser.

Analyse your own evidence

Add files, text, a URL reference or a structured event record. Each item is hashed with SHA-256 and typed from its bytes, never its filename, then analysed in a background worker. Executables and archives are hashed but never parsed, decompressed or run. URLs are recorded as references and never fetched. The limit is 256 MiB per file, and parsers see files up to 64 MiB.

Files

Drop images, audio, video or documents here, or

JPEG, PNG, GIF and WebP · WAV, MP3, AAC, FLAC and Ogg (decoded by your browser) · MP4 and MOV · text and JSON. Anything else is hashed and recorded.

Text, URL or structured event

Analyst observations

What a person reads off the evidence (a sign, a fleet number, a time on a log) is recorded as an analyst assertion. It is always shown as an inference, never as a fact.

How it works

Every item passes through the same thirteen stages. The first twelve are automatic and recorded; the last belongs to a person.

  1. Source and acquisition: who supplied the item, when, and how.
  2. Hash: SHA-256 of the exact bytes, fixed at intake. The original is never modified; any transformation produces a new item with its own hash and a recorded parent.
  3. Provenance: an append-only ledger in which each record includes the hash of the one before it.
  4. Metadata: EXIF, PNG text and time chunks, MP4 movie headers, RIFF INFO tags. Read, reported, and never trusted.
  5. Content analysis: JPEG and PNG structure, quantization tables, CRCs, copy-move block matching; WAV digital silence, splice-like steps and room-tone shifts.
  6. Temporal analysis: the frame-interval table from the container, turned into a NORMAL / REVIEW / ANOMALY / SUPPORTED timeline.
  7. Cross-source correlation: copies, derivatives, shared upstream sources and near-duplicate images collapse into one independence group before anything is counted.
  8. Manipulation indicators: each one states what was found, how, on what evidence, with what confidence, what else could explain it, and what the system cannot determine.
  9. Confidence assessment: rule-based. HIGH needs three independent agreeing groups with no anomalies; one source is never more than PARTIALLY SUPPORTED.
  10. Evidence graph: facts the engine recorded are solid edges; everything read from metadata or an analyst is a dashed inference.
  11. Audit record: every analyzer run records its input and output hashes.
  12. Human review: accept, reject, escalate, mark inconclusive, annotate, comment or request a second review. The analyst cannot decide their own analysis, and nothing becomes VERIFIED without a human ACCEPT.

Evidence vs inference

Observation

What the bytes, metadata or records contain. “EXIF DateTime is 2026:03:15 09:12:44.” “All channels are exactly zero from 2400 to 2550 ms.”

Interpretation

What a rule makes of an observation. “The file was written after capture.” “Exact silence inside a recording is typical of muting or editing.”

Conclusion

A status the rules assign, with its review state beside it. “Claim: INCONCLUSIVE (human review pending).”

Never

“This video is fake.” The report generator refuses engine text that asserts certainty, and says instead: Manipulation indicators detected; human review required. Or: No manipulation indicators detected by the available analyzers. Authenticity cannot be established solely from this analysis.

Chain of custody

A hash proves the bytes have not changed since the hash was taken. It proves nothing about the event the bytes depict. That is why the console separates CRYPTOGRAPHICALLY VERIFIED (the hash matches an earlier custody receipt) from VERIFIED (integrity verified and accepted by a human reviewer), and why neither is a statement about what happened.

Canadian law draws the same line. Under sections 31.1 and 31.2 of the Canada Evidence Act, a party must show an electronic document is what it purports to be, and the best evidence rule is met by proof of the integrity of the system that recorded or stored it. Section 34.1 of Ontario's Evidence Act sets out comparable rules for electronic records. The provenance ledger is designed to make system integrity something you can show, not assert.

Synthetic media: what detection can and cannot do

Generative tools leave some traces: a generator name in a software tag, generation settings in a PNG text chunk, a Content Credentials manifest. They also leave many traces nobody can see without a trained model, and strip or rewrite most of the ones anybody can. NIST's AI 100-4 (November 2024) surveys provenance, labelling and detection approaches and treats them as complementary layers, not a single test.

This console does not bundle or call a synthetic-media classifier. It reports metadata signals as metadata signals, detects Content Credentials (C2PA) manifest presence without validating the signature, and records the classifier as an adapter boundary that is not implemented. The absence of an indicator is never reported as evidence of authenticity.

Bifocal evidence verification

A single media stream is one lens. ClearGlass Bifocal Verification holds it against channels that did not come through the same pipeline: an independent sensor that observed the same place, a reference clock for the capture device, and a custody record that fixed the file's hash earlier. Each applicable check agrees or conflicts, and a channel in the same independence group as the primary is excluded from scoring.

The result is a consistency score out of 100, shown only when two or more channels are present, and always with the statement: This score is an analytical heuristic and is not proof of authenticity. Camera telemetry, RFC 3161 timestamps, detached signatures, device attestation, live sensor feeds and C2PA validation are listed as adapter boundaries. They are not implemented, and the console says so.

AI governance

Every analyzer run is recorded with its provider, model, version, input hash, output hash, time, analyst, highest indicator confidence, limitations and human-review state. Here the provider is always clearglass-local and the model a deterministic rule set. No external AI provider is configured or called. An adapter would have to be enabled explicitly, and every call would be recorded the same way.

Analysis output is never promoted to fact on its own. The final status is always analysis plus human review, and demonstration data stays SIMULATED whatever a reviewer does.

Limitations

Standards and sources

Engine source, tests and methodology: truth_forensics/, assets/js/truth-forensics-engine.js and docs/TRUTH_FORENSICS.md in the ClearGlass repository. The Python and browser engines are held to byte-identical output by a parity test.