NeverPrompted
Attached to every result

Stated limits

These are attached to every result NeverPrompted produces, in every channel, and printed in full on every exported report. They are the output, not commentary on it.

  1. 01

    A detected mark is not proof of authorship. A mark can be present in text a person wrote with assistance, quoted, translated, or edited.

  2. 02

    An absent mark is not proof of human authorship. Marks survive editing poorly, are not applied by every system, and cannot be detected at all without the key used to apply them.

  3. 03

    This deployment holds no detection key published by a model vendor. It tested only the keys listed in this report, so it cannot make any statement about marks applied by a vendor whose key is not public.

  4. 04

    The watermark test operates on word pairs, not on a model’s own subword vocabulary. A vendor’s own detector has access to that vocabulary and can therefore reach a different conclusion on the same document.

  5. 05

    The style measurement compares this document to contemporary reference prose in the same language. Distance from that reference reflects register, subject and translation, and is not evidence of how the document was produced.

  6. 06

    The model-backed classifier (mlClassifier) is trained primarily on English text from a broad set of generators. It only runs on English documents, and its confidence is lower on very short passages or on AI-written text that has been substantially edited afterward.

The asymmetry worth understanding

A detected mark is meaningful evidence that text carrying that key’s signature is present. An absent mark is much weaker evidence of anything, because so many ordinary histories produce it: the generator applied no mark, the mark was applied with a key nobody outside the vendor holds, the text was edited or translated enough to degrade the signal, or a person simply wrote it.

That asymmetry is unavoidable and it is why NeverPrompted never says “cleared”. What it can give you is a documented, dated, hash-anchored record of a specific test on a specific file, with the method named, which is a great deal more than an unexplained percentage, and considerably more durable than a claim that overstates itself.

Two things this product will never do

Claim a rewrite guarantees defeating a specific vendor's undisclosed watermark. No tool honestly can, since nobody outside that vendor holds the key it was applied with. The rewrite feature reduces detectable evidence and states that limit alongside every result, never “undetectable” and never a promise that it will clear any specific check.

Send your document to a NeverPrompted-operated server while rewriting it. Not on the free tier, not on Pro, not through the MCP server, not through the published package/CLI, and not later: there is no REST endpoint for rewriting, by design. Checking has an opt-in hosted mode for API/MCP callers; rewriting gets no exception to the on-device guarantee, because reducing evidence is more sensitive than measuring it. See /rewrite.

Answers, in full

About these limits

Why publish the limits so prominently?
Because this product exists because a number was over-read about somebody. A tool that helps with that and then invites the same mistake in the other direction has not improved anything. The limits are part of every result and every exported report, not a page people are trusted to find.
Doesn’t this make the product sound weak?
It makes it sound accurate. A report that admits what it cannot establish survives contact with a sceptical reader; one that claims to prove innocence collapses the first time someone knowledgeable reads it, and takes the writer’s credibility with it.