How it works

What the analysis actually establishes.

The homepage says a decision depends on what happens next. This page is the mechanism behind that: what content can do, who is about to consume it, how it arrived, and how far each of those is actually built.

The stages

Bytes to decision, with the maturity of each step.

01

Identify & expand

Shipping

Content identity from bytes, accepted interpretations, and recursive assets under explicit budgets.

02

Evidence & authority

Hardening

Observations with derivation, completeness and traceability — how strongly a thing is known, not just that it was seen.

03

Capabilities & effects

Partial

What the content can do, normalised across carriers. A canonical contract with mapping identity and coverage — today bounded and diagnostic, not yet policy authority.

04

Context & exposure

Roadmap

Who or what consumes it, with which privileges, how it arrived, and where it is going.

05

Coverage & support truth

Hardening

Whether an absence of findings means anything at all for this content.

06

Content Trust Decision

Roadmap

One request-specific decision — allow, constrain, review, refuse or transform — over the content-intrinsic graph. The authoritative boundary is being built.

07

Transform & verify

Partial

A safer derivative, the residual evidence, and what the transformation preserved or removed.

08

Control points

Partial

The same decision applied at the workbench, the CLI, the endpoint or the content boundary.

Different file, same effect

A PDF launch action, an Office hyperlink, an SVG reference and a hidden model instruction look nothing alike on disk. Normalised as effects, several are the same thing wearing different clothes — which is what lets a control survive the next carrier rotation instead of chasing file extensions.

Execution

Something runs — a macro, a script, an embedded interpreter, a launched handler.

External retrieval

The content reaches out: a remote template, a linked resource, a callback, a tracking fetch.

Data disclosure

Something leaves — credentials, tokens, form contents, or the file itself.

Human coercion

A person is persuaded to act: a lure, a fake workflow, a copy-and-run instruction.

Machine influence

A model, retriever or agent is steered — hidden instructions, poisoned context, tool-use directives.

Partial The effect vocabulary and its coverage across carriers are still being completed.

External integrity evidence — integrated, not absorbed

Content credentials, watermarks, provider markings, device attestations and trust lists are evidence, mapped through versioned provider-neutral profiles into our own model. They do not become canonical types just because a standard defines them, and binding validity stays separate from whether the issuer is trusted.

Content credentials (C2PA as the first planned reference profile)Watermark and disclosure signalsProvider markings and device attestationsTrust lists and verifier services

Roadmap The internal foundation has landed; there is no general verifier or cross-provider decision plane today. C2PA is a planned first reference profile — not present-tense support.

Then: who consumes it

The same capability lands differently depending on the consumer and its privileges.

  • A person reading it. Sees the rendered page. Hidden instruction channels are invisible; the lure is the risk.
  • A renderer or parser. Touches structure the human never sees, often before anyone decides to trust it.
  • A retrieval indexer. Ingests extracted text — including channels that were never meant to be read.
  • An agent with tools. Can act on what it reads. Instruction-bearing content becomes an action path.

Roadmap A single canonical consumer, action and destination contract is being built.

And: how it arrived

Acquisition context changes the decision without changing a byte.

  • Sender authentication and reply-path
  • Browser origin and download zone
  • Repository, branch and revision
  • Collaboration site and sharing scope
  • Mark-of-the-web and OS quarantine state
  • Custody: who handled it, and when

Roadmap Canonical custody is still distributed across surfaces.

See it on a real file.

The workbench runs this analysis locally and shows the evidence, the coverage and the gaps for whatever you drop into it.