Verify a receipt.
Independent, client-side cryptographic verification. No data leaves your browser. Paste a receipt, upload a JSON file, or open a verification link — the receipt in a Glacis permalink rides in the URL fragment, which browsers never send to a server.
The link carries the receipt after the #. Fragments are never sent to a
web server, so pasting one into a ticket or an email does not hand the receipt to us,
to your CDN, or to anyone’s access log. Whoever opens it verifies it in their own browser.
Reviewing a vendor? Require receipts.
You just checked someone else’s claim in your own browser, with no account and no trust in us. That is the whole point: the party making the claim should not be the only party who can check it. Ask every AI vendor for the same thing, and start minting your own.
For AI buyers
A receipt is evidence that a specific claim was generated about a specific event, at a specific time, in a form that cannot be quietly rewritten afterwards. It is not a verdict on whether the system behaved well, and no receipt can be. Four questions get you most of the way through a vendor review:
- Is there a receipt per covered event, or a document about events? A policy PDF describes intent. A receipt records what happened.
- Who countersigned it? A vendor signing its own receipts is keeping a diary. Evidence needs a signature from a key the vendor does not hold.
- What do the signed bytes actually cover? Fields outside the signature can be edited without breaking it. Ask for the list; this page prints it for every receipt it checks.
- Can you check it yourself? Ask for a link that verifies in your browser, with no account and no call to the vendor’s API. If verification requires the vendor’s cooperation, it is not independent.