Evaluate Ankorith in your own systems
For IT, security and product teams that want to test content provenance before rolling it out. Your first seal takes minutes; a full evaluation fits into a single sprint.
What you get
There is no separate sandbox: the free plan runs on the production service, so what you test is exactly what you will deploy. Seals are written to the permanent public log — test with non-sensitive files and do not put personal data into seal titles.
Step by step for IT
1. Sign in
Open sign-in and use Google, Microsoft, GitHub, a one-time e-mail link or a passkey. No passwords are stored.
2. Verify your domain
In your account, enter the domain your company publishes under. Prove control of it with one of:
# DNS TXT record _ankorith.yourcompany.com TXT "ankorith-verify=<token>" # or a file on your website https://yourcompany.com/.well-known/ankorith.txt → ankorith-verify=<token>
The token is valid for 7 days. After verification, your seals carry your domain as the verified issuer, and the verification itself is recorded in the public log.
3. Create an API key
The primary key is shown once after domain verification. For each system (CMS, DAM, a generator pipeline) create a named sub-key in your account — or through the API with the primary key — so that keys can be revoked one by one. We store only fingerprints of keys; a key you lose cannot be shown again, only replaced.
curl -X POST https://ankorith.com/seal/api/keys \
-H "Authorization: Bearer $PRIMARY_KEY" -H "Content-Type: application/json" \
-d '{"name":"cms-production"}'
4. Your first seal
You send only the SHA-256 fingerprint of the file and your declaration (photo, human, ai-edited or ai-generated). The file stays with you.
curl
SHA=$(shasum -a 256 banner.jpg | cut -d' ' -f1)
curl -X POST https://ankorith.com/seal/api/bulk \
-H "Authorization: Bearer $ANKORITH_KEY" -H "Content-Type: application/json" \
-d "{\"items\":[{\"sha256\":\"$SHA\",\"declaration\":\"ai-generated\",\"tool\":\"Your model\",\"name\":\"Banner 01\"}]}"
Node.js (18 or newer)
import { createHash } from "node:crypto";
import { readFile } from "node:fs/promises";
const sha256 = createHash("sha256").update(await readFile("banner.jpg")).digest("hex");
const res = await fetch("https://ankorith.com/seal/api/bulk", {
method: "POST",
headers: { Authorization: `Bearer ${process.env.ANKORITH_KEY}`, "Content-Type": "application/json" },
body: JSON.stringify({ items: [{ sha256, declaration: "ai-generated", tool: "Your model", name: "Banner 01" }] }),
});
const { results } = await res.json();
console.log(results[0].verifyUrl ?? results[0].error);
Python
import hashlib, os, pathlib, requests
sha256 = hashlib.sha256(pathlib.Path("banner.jpg").read_bytes()).hexdigest()
r = requests.post("https://ankorith.com/seal/api/bulk",
headers={"Authorization": "Bearer " + os.environ["ANKORITH_KEY"]},
json={"items": [{"sha256": sha256, "declaration": "ai-generated",
"tool": "Your model", "name": "Banner 01"}]})
item = r.json()["results"][0]
print(item.get("verifyUrl") or item.get("error"))
Each result carries the seal id, its position in the public log and a verifyUrl. Up to 100 items per request; a failing item does not stop the others. For a machine-readable label inside JPEG/PNG files, appearance matching and change localisation, use the reserve → embed → issue flow described in the API documentation.
5. Verify
Drop the file on ankorith.com/seal — the fingerprint is computed in the browser and the page checks the signed public log itself. Or verify from your systems:
curl "https://ankorith.com/seal/api/verify?sha256=$SHA"
6. Optional: webhooks and usage
Register an HTTPS endpoint to receive a notification, signed with HMAC-SHA256, for every issued seal. No server ready yet? Use the built-in test receiver described in the API documentation. GET /seal/api/usage returns seals per month and per key.
Integration scenarios
| System | Where to seal |
|---|---|
| CMS | On publish: seal each image and attachment with the editor's declaration; the verify link can be shown next to the image. |
| DAM | On asset approval: store the seal id with the asset, so its origin declaration travels with it through your workflows. |
| Newsroom | On the photo desk: seal with photo before distribution, including the appearance fingerprint and grid. Copies recompressed by social networks are then still found, and changed areas are shown. |
| E-shop | Product imagery: declare honestly what is a photograph and what is AI-edited or generated, as customers and regulators increasingly expect. |
| AI generators | In the output pipeline: seal every generated image as ai-generated with the tool name — machine-readable marking that helps you meet Article 50 of the EU AI Act. Guide |
Security review
The technical description covers architecture, data flows, cryptography and limitations. Legal documents: Data Processing Agreement, Privacy Policy, Terms of Service. Send your security questionnaire to info@gpnovum.cz.
FAQ
Do you receive our files?
No. Fingerprints are computed in the browser or in your own code; we receive the SHA-256 and, for images, an appearance fingerprint and a coarse grid of tile statistics.
Is there a sandbox?
No separate one — the free plan is the production service. Seals are permanent, so use non-sensitive test files. For webhooks there is a test receiver.
Which file types are supported?
Any file can be sealed by its SHA-256 fingerprint. JPEG and PNG can also carry the label inside the file; images additionally get appearance matching and change localisation.
What happens to seals if Ankorith stops operating?
The public log is signed and anchored in Bitcoin through OpenTimestamps; the anchors are standard .ots files that anyone can check with independent tools.
Can we have several domains, higher volumes or an SLA?
Yes — Business and Enterprise plans, or an extended pilot. Contact us.
Does a seal prove that our content is true?
No. It proves who declared what about the file and when, and whether the file has changed since. Responsibility for the declaration stays with the issuer.