Know Exactly What AI Wrote.
Prove It.
Mark your AI output, keep an audit trail, and walk into August 2, 2026 ready.
What You Get
A mark on every passage
Every AI-generated or AI-assisted passage is signed as it is produced: which model, what time, which author. Human-written passages can be signed the same way.
An audit trail you can open
A running record of who signed what and when. Any change to a signed passage after signing is recorded, including who made it.
An evidence package on demand
When a court, regulator, client, or internal audit asks, export a tamper-evident report anyone can verify without trusting Encypher.
Your own keys (BYOK)
Signing runs under your organization's own key. Your key material never leaves your environment, a requirement for privileged work.
How do you prove which parts of a document AI wrote?
Law firms, consulting firms, and regulated enterprises face a new question on every document: which sentences came from AI, which came from humans, and which were AI-drafted then edited? An AI policy does not answer that question. Cryptographic content provenance does.
Picture it: an associate drafts a filing with an AI assistant. Every passage the assistant writes is marked the moment it is written, and every human edit afterward is recorded too. Months later a court order, a client, or your own compliance team asks what AI actually did on that document.
Instead of interviews and version-history archaeology, you export a report that answers at the sentence level: this passage was AI-drafted, this one was human-written, this one was AI-drafted and then reviewed and edited, by name and date. The document itself carries the proof.
The Gap Between Policy and Proof
Most organizations have an AI use policy. Almost none can prove what that policy produced on a specific document.
What "We Have a Policy" Cannot Do
Answer a court order
Federal courts are requiring attorneys to certify AI use. A policy memo does not satisfy a signed certification requirement.
Identify which paragraph was hallucinated
If opposing counsel or a regulator challenges a specific citation, you need sentence-level proof, not an attestation that "AI may have been used."
Prove retroactively
Without provenance embedded at creation time, any claim about a document's origin is unverifiable - and therefore contestable.
Protect against internal dispute
When a client asks "did your team use AI on this engagement," a policy cannot tell you what actually happened on a specific deliverable.
What Cryptographic Provenance Does
Marks provenance at creation
Every AI-generated or AI-assisted passage is signed with model metadata, timestamp, and author at the moment it is produced, not reconstructed later.
Proof for every sentence, independently
Each sentence has independent cryptographic proof. You can show that paragraph 4 was AI-generated while paragraphs 1-3 and 5 were human-authored. How it works under the hood is in the technical section below.
Tamper-evident export
Evidence packages are independently verifiable - the proof is embedded in the document itself, not on Encypher's servers.
Detects post-signing modification
Any change to a signed passage is cryptographically recorded. You can prove a section was edited after signing, and by whom.
Where Provenance Proof Is Required
The question is no longer hypothetical. Courts, regulators, and clients are asking for documentation that standard AI governance frameworks cannot produce.
Law Firms
Federal and state courts are issuing standing orders requiring attorneys to certify AI use in filings. Bar associations are publishing ethics guidance on disclosure obligations. Attorneys using AI assistants (Harvey, Westlaw AI, Copilot) need to certify not just "AI may have been used" but which specific passages - and that those passages were reviewed.
- +Court filing certification: paragraph-level AI attribution
- +Malpractice defense: prove which citations were AI-generated vs. attorney-verified
- +Sanctions defense: evidence that AI output was reviewed before filing
- +Client billing documentation: distinguish AI-assisted from attorney work
Consulting and Advisory Firms
Enterprise clients - especially in regulated industries - are adding AI disclosure requirements to engagement terms. A strategy memo or due diligence report that contains AI-synthesized sections without disclosure creates professional liability. Firms need to demonstrate exactly what was AI-produced and what was partner-level analysis.
- +Client deliverable provenance on request
- +M&A due diligence: which synthesis was AI, which was analyst judgment
- +Engagement audit trail for regulatory review
- +Professional standards compliance (AICPA, CFA, etc.)
Financial Services
Some regulatory and internal-controls frameworks may require documenting AI use in filings. Research reports, prospectuses, and regulatory submissions that use AI-generated content without provenance documentation create material risk. Financial firms need an audit trail that satisfies both internal compliance and external regulatory review.
- +Regulatory filing AI-disclosure documentation
- +Research report provenance for analyst certification
- +Internal audit trail for AI governance frameworks (SR 11-7 equivalent)
- +EU AI Act compliance for customer-facing AI outputs
Enterprise Legal and Compliance
General counsel and compliance teams at large enterprises face a discovery problem: when litigation or regulatory investigation touches internal documents, they need to produce provenance information that currently does not exist. Signing documents at creation builds that record before it is needed.
- +e-Discovery: identify AI-generated content in document review
- +Contract lifecycle: prove which clauses were AI-drafted vs. negotiated
- +Board reporting: accurate AI usage disclosure in governance reports
- +HR and policy documents: provenance audit for internal investigations
How Sentence-Level Provenance Works
Provenance is embedded at creation time and travels with the document wherever it goes.
BYOK: Your Keys. Your Infrastructure.
For law firms and regulated enterprises, attorney-client privilege and data residency requirements mean you cannot send document content to a third party's signing service. Encypher's BYOK model addresses this: your organization registers its own Ed25519 public key, and all signing uses your key. Encypher provides the infrastructure; your key material never leaves your environment.
Key custody stays with you
Encypher never stores, transmits, or accesses your key material. HSM, AWS KMS, Azure Key Vault supported.
Independently verifiable
C2PA assertions embed your certificate. Anyone can verify the signature against your public key without trusting Encypher.
Data residency compatible
Signing can run within your infrastructure. Document content does not need to leave your environment.
Encypher authored Section A.7, the text-provenance section of the C2PA specification, and co-chairs the Text Provenance Task Force alongside these member organizations. Logos indicate C2PA membership.
Frequently Asked Questions
Questions from legal, compliance, and IT teams at law firms and regulated enterprises evaluating Encypher.
Have a question not covered here?
Build the Record Before You Need It
The time to establish document provenance is at creation, not during litigation or regulatory review. Schedule a technical architecture review to see how Encypher fits your document workflow and governance requirements.