- 01
A detected mark is not proof of authorship. A mark can be present in text a person wrote with assistance, quoted, translated, or edited.
- 02
An absent mark is not proof of human authorship. Marks survive editing poorly, are not applied by every system, and cannot be detected at all without the key used to apply them.
- 03
This deployment holds no detection key published by a model vendor. It tested only the keys listed in this report, so it cannot make any statement about marks applied by a vendor whose key is not public.
- 04
The watermark test operates on word pairs, not on a model’s own subword vocabulary. A vendor’s own detector has access to that vocabulary and can therefore reach a different conclusion on the same document.
- 05
The style measurement compares this document to contemporary reference prose in the same language. Distance from that reference reflects register, subject and translation, and is not evidence of how the document was produced.
- 06
The model-backed classifier (mlClassifier) is trained primarily on English text from a broad set of generators. It only runs on English documents, and its confidence is lower on very short passages or on AI-written text that has been substantially edited afterward.
The asymmetry worth understanding
A detected mark is meaningful evidence that text carrying that key’s signature is present. An absent mark is much weaker evidence of anything, because so many ordinary histories produce it: the generator applied no mark, the mark was applied with a key nobody outside the vendor holds, the text was edited or translated enough to degrade the signal, or a person simply wrote it.
That asymmetry is unavoidable and it is why NeverPrompted never says “cleared”. What it can give you is a documented, dated, hash-anchored record of a specific test on a specific file, with the method named, which is a great deal more than an unexplained percentage, and considerably more durable than a claim that overstates itself.
Two things this product will never do
Claim a rewrite guarantees defeating a specific vendor's undisclosed watermark. No tool honestly can, since nobody outside that vendor holds the key it was applied with. The rewrite feature reduces detectable evidence and states that limit alongside every result, never “undetectable” and never a promise that it will clear any specific check.
Send your document to a NeverPrompted-operated server while rewriting it. Not on the free tier, not on Pro, not through the MCP server, not through the published package/CLI, and not later: there is no REST endpoint for rewriting, by design. Checking has an opt-in hosted mode for API/MCP callers; rewriting gets no exception to the on-device guarantee, because reducing evidence is more sensitive than measuring it. See /rewrite.