Public verifier · No account required

Verify any Solus document.

Drop a .solus file. The full audit — cryptographic provenance and the writer's typing pattern — runs entirely in your browser. Nothing is uploaded.

Drop a .solus file here

or click to browse your computer

Works with all Solus documents. No account required.

How verification works

Two independent axes. Both have to pass.

Solus doesn't hand out a single "authenticity score." A .solus file's cryptographic provenance and its writer's typing pattern are graded independently, then combined into a verdict. Both run locally — your file never leaves this page.

Axis A Provenance Integrity

Purely cryptographic. The signature has to verify against the certificate body, the certificate body's hash has to match the commitment, the ledger's Merkle root has to reproduce, the paste-policy log has to match the certificate's claim.

20 checks · fail any one → verdict is tampered

Axis B Human-Origin Support

Behavioral. Does the writer have an established typing baseline, and does this submission's rhythm match it? Composition-vs-transcription signal, pause-location distribution, keystroke sufficiency, anti-transcription composite — all measured against the writer's own history.

10 checks · fail any hard one → unsupported; partial → limited

When does Axis B actually turn on?

Axis A is available immediately — all 20 cryptographic checks run on the very first document anyone writes, with no history and no account. Axis B is different: it compares a submission against that writer's own baseline, and a baseline has to be built out of their real writing first. Until it exists, the Axis B checks report amber. That amber describes missing evidence, not suspicious evidence.

3
qualifying sessions — 5+ minutes of sustained writing, almost no pasted content
3
separate days — a baseline built in one sitting isn't a baseline
8,000
accepted keystrokes — roughly 1,300 words of real typing

For most writers that's the first two or three assignments. Verify any file from an enrolling writer and the result shows live meters for exactly how far along they are and what's still outstanding — so "not yet" always comes with a finish line. Once the baseline completes, Axis B runs on every subsequent submission and Verified Human™ becomes available.

Verified Human only appears when both axes come back green — cryptographic provenance intact AND behavioral pattern matches the writer's enrolled baseline. Anything less shows you which axis fell short and why. See the FAQ below for what each verdict means in plain English.

Understanding the verdict

Five possible outcomes. The badge only appears for the first one.

Verified Human

Both axes green

Provenance intact and the writer's typing pattern matches their enrolled baseline. The strongest claim Solus can make.

⚠ Partial

Provenance intact, behavior limited

Cryptographic checks pass, but one or more behavioral signals came back mixed. Not a tamper; teacher reviews in context.

— Not yet available

Provenance intact, no baseline yet

File is cryptographically clean, but this writer has no typing baseline to compare against, so the behavioral axis couldn't run. Normal for a new writer's early work and for legacy files — an absence of evidence, not evidence against. Machine token: unsupported

⋯ Baseline building

Baseline still building

Provenance intact, and the writer is partway to an established baseline. The result shows live meters for sessions, days and keystrokes remaining; the badge unlocks on submissions after enrollment completes.

Tampered

Cryptographic evidence altered

Signature doesn't verify, cert body was mutated, ledger Merkle root doesn't reproduce, or the archive was manipulated. A valid Solus file cannot become tampered by accident — treat this as a serious finding.

Frequently asked

Plain-language answers for reviewers, employers, journalists, and anyone else who's looking at a .solus file for the first time.

What is a .solus file?
A .solus file is a document written in the Solus editor plus a cryptographic certificate that attests how it was written — every keystroke, every pause, every paste event, every cursor jump. The document content itself is encrypted and only readable by the intended recipient. This page verifies the certificate portion, which does not require the decryption key.
What does "Verified Human" mean?
Both verification axes came back green: Axis A (Provenance Integrity) — the cryptographic signature verifies, the certificate body's commitment matches, the ledger's Merkle root reproduces, the paste-policy log matches the certificate's claim — and Axis B (Human-Origin Support) — the writer has an established typing baseline and this submission's rhythm matches it. The badge is only awarded when both hold.
Why didn't a file get the Verified Human badge if it wasn't tampered?
Two common reasons. First, the writer hasn't enrolled — Verified Human requires a typing baseline, and a baseline needs 3 qualifying sessions across 3 separate days totaling 8,000 accepted keystrokes (a qualifying session is 5+ minutes of sustained writing with almost no pasted content) — typically a writer's first two or three assignments. New writers and legacy submissions show as unsupported even when the file is cryptographically clean, and the result panel shows live meters for what's still outstanding. This is an absence of evidence, not evidence against anyone. Second, the writer is enrolled but this submission's typing pattern didn't match — either the rhythm shifted (illness, injury, new keyboard) or someone else typed it. Read the Axis B checks for specifics.
What does "Tampered" mean?
Any Axis A crypto check failed. The signature doesn't verify against the certificate body, the cert body's commitment doesn't match, the ledger's Merkle root doesn't reproduce, or the SOLUS archive header was modified. A valid Solus file cannot become tampered by accident — treat this as a serious finding.
What does "Partial" mean?
Provenance is intact but a behavioral check came back mixed. Doesn't mean the submission is fraudulent — could be legitimately weak signal (very short document, keyboard change, dictation followed by manual editing). The individual check details name which signal fell short.
What does "Enrolling" mean?
The writer is still building their typing baseline (three qualifying sessions across three or more days with 8,000+ keystrokes and no synthetic input). Their submissions won't earn the badge yet, but future ones will once enrollment completes. Cryptographic provenance is still verified normally.
How does the behavioral check work?
Solus captures keystroke timings (dwell, flight, burst structure), pause locations, non-linearity, and attention continuity throughout every writing session. Once a writer has enrolled, we know their typical rhythm. Each new submission's rhythm is scored against that baseline. Transcription from a phone or printed source produces measurably different timings — that's what closes the gap that pure paste-blocking can't. Read the full detection methodology.
Can I read the actual document content?
Not from this page. The document content is encrypted to specific recipients (the student and the teacher assigned in the student's class). Only their private keys — held only on their devices — can decrypt it. This is by design; privacy of student writing is preserved even from Solus's own infrastructure. To read the content, ask the recipient for a decrypted PDF or plaintext export.
The file was verified — what does that not prove?
VALID confirms the file is internally consistent and has not been altered since signing. It does not, by itself, confirm that the signing key belongs to a specific real person you know. A determined attacker could generate a valid .solus file offline with any signing key. The next layer of trust — cross-checking the signing key against a Solus-attested issuer directory — is on the roadmap. For pre-launch pilots, verification is best used alongside knowing where the file came from (which teacher, which class, which institution).
Did this page upload my file anywhere?
No. Verification runs entirely in your browser using the Web Crypto API and JSZip. The file never leaves your device. You can verify this by opening your browser's Network tab, disconnecting from the internet, and dropping a file — verification still works.
How do I save this report?
Click the Print / save as PDF button in the result panel. Your browser will format a clean printable version. In the print dialog, select "Save as PDF" as the destination — no printer required.
What if I'm evaluating this file for an academic-integrity case?
A VALID result establishes that the file has not been altered and that the document was composed in the Solus editor. Read the individual checks (especially "programmatic input blocked" and "paste attempts rejected") for behavioral evidence. If you need to verify content, coordinate with the class teacher or institution admin — they can decrypt with their private key and produce a viewable version.

Your file never leaves your device.

Verification runs entirely in your browser using the Web Crypto API and JSZip. No data is sent to X Point's servers or any third party. You can verify this by disconnecting from the internet before dropping a file — it still works.

Want Solus for your class?

Students write in Solus free. Teachers verify with one click.