It does not say what it contains is true
This is the most important thing on this page, and it is worth reading twice.
Checking the signature tells you where the document comes from and that nobody
has touched it. It says nothing about whether what it says is true.
The report is generated from a recording provided by the client, and both
the accuracy of the transcription and the truth of what is said in it are their
responsibility. Uttera did not witness what was recorded, does not check it and
does not certify it: it only attests that this document came out of its system
exactly as it stands.
It proves it is ours
The signature is made with a private key that never leaves our servers. If it
verifies, we issued that document and it says exactly what it said when it was
issued.
It is not a qualified signature
It is a technical authenticity proof (Ed25519), not a qualified electronic
signature in the sense of the eIDAS regulation. We say so here and the report says so
too: we do not call it what it is not.
We store nothing for this
Verifying is a public-key operation over what you send us: we look nothing up. That
is why it works on a report from years ago, and why we cannot find one you have
lost.
You can do it without us
The public key is published at /.well-known/uttera-firma.pub. Any
Ed25519 library will check a signature without going through here.
How to do it with curl →
If something does not check out
A file that fails to verify is not automatically fraud: someone opening it
and saving it again with a PDF tool is enough to change the bytes. The first step is
to ask whoever sent it to you for the original.
If you believe someone is using our name, or another company's branding, write to
support@uttera.ai with the report
number, printed on every page. We keep a record of who issued each report and
when, and we can answer a lawful request from an authority. We cannot tell you who
it was: that is someone else's personal data.