UtteraUttera

Verify a report

Every PDF report we issue is cryptographically signed. Here you can check whether a report came from us and whether anyone has touched it on the way — with no account, no key and without asking us for permission. That is the whole point of signing with asymmetric cryptography: the public key is published and anyone can check it, even on their own without going through this page.

Just upload the report

There is nothing to copy or paste: the signature travels inside the PDF itself. Choose the file and we will tell you whether we issued it and whether anyone has touched it.

The file is sent to check the signature and discarded when we answer. We do not store it, and we look nothing up: verifying is a public-key operation over what you send us.

What this proves, and what it does not

It does not say what it contains is true

This is the most important thing on this page, and it is worth reading twice. Checking the signature tells you where the document comes from and that nobody has touched it. It says nothing about whether what it says is true.

The report is generated from a recording provided by the client, and both the accuracy of the transcription and the truth of what is said in it are their responsibility. Uttera did not witness what was recorded, does not check it and does not certify it: it only attests that this document came out of its system exactly as it stands.

It proves it is ours

The signature is made with a private key that never leaves our servers. If it verifies, we issued that document and it says exactly what it said when it was issued.

It is not a qualified signature

It is a technical authenticity proof (Ed25519), not a qualified electronic signature in the sense of the eIDAS regulation. We say so here and the report says so too: we do not call it what it is not.

We store nothing for this

Verifying is a public-key operation over what you send us: we look nothing up. That is why it works on a report from years ago, and why we cannot find one you have lost.

You can do it without us

The public key is published at /.well-known/uttera-firma.pub. Any Ed25519 library will check a signature without going through here.

How to do it with curl →

If something does not check out

A file that fails to verify is not automatically fraud: someone opening it and saving it again with a PDF tool is enough to change the bytes. The first step is to ask whoever sent it to you for the original.

If you believe someone is using our name, or another company's branding, write to support@uttera.ai with the report number, printed on every page. We keep a record of who issued each report and when, and we can answer a lawful request from an authority. We cannot tell you who it was: that is someone else's personal data.