Back to blog
Integrity

Provenance Without Surveillance

A new category of 'authorship verification' works by watching you type. We think that's the wrong trade — and we built the alternative: proof that doesn't require being watched.

F

Folio Team

August 3, 2026 5 min read

A new kind of authorship-verification tool is spreading through edtech, and it works by watching you type.

GPTZero's Writing Replay, built into Google Docs, records typing rhythm and copy-paste activity while you write, then runs a proprietary pattern model over that behavioral data to certify that the writing is "really yours." It's a real product, doing what it says it does. We're not disputing that.

We just think it's the wrong trade. Proving you wrote something shouldn't require being watched while you do it.

Two different problems, both looking for a way out

It's worth being precise about what's actually happening in this market, because two separate things are going on and they get conflated constantly.

The first is AI-content detection — tools that read a finished text and guess whether a model wrote it. That category is in visible retreat. Vanderbilt disabled Turnitin's AI detector in August 2023, and said so publicly: their own math on the advertised sub-1% false-positive rate meant roughly 750 of the 75,000 papers they process a year could be wrongly flagged. Johns Hopkins, the University of Waterloo, and dozens of other institutions have made the same call since, for the same reason — the tools can't tell fluent human writing from fluent machine writing, and the errors land hardest on students writing in a second language. We wrote about why that failure is structural, not incidental, in Proof of Authorship.

The second is behavioral authorship verification — tools like Writing Replay that don't try to read the text at all. Instead they watch you: how fast you type, where you paste from, the rhythm of your keystrokes. It's a reasonable response to the first category's failure — if you can't verify a document from its content, verify the person instead. But it trades one problem for another. Now proving your work is honest requires handing over a behavioral profile of how you write, indefinitely, to a third party.

Institutions retreating from the first category shouldn't have to walk straight into the second to get the same promise met.

What we do instead

Folio never logs keystrokes, and we never build a profile of how any individual writes. That's not a policy we adopted after the fact — it's a permanent constraint on the product, and it rules out an entire category of "just track more signals" fixes that would otherwise be tempting.

What we track instead is the document, not the person. While you write, your editor periodically sends us a hash of the current draft — a fingerprint, not the text itself. Your words don't leave your machine on this path. Each fingerprint we receive gets timestamped, linked to the one before it, and answered with a fresh random number that the next fingerprint has to include. That number didn't exist until we issued it, so nobody — not us, not you — can construct next Tuesday's link today.

The result is a hash-chained ledger of a document's real history, closed off with a single verifiable root — the same mechanism behind the Integrity Certificate and its public verify link. It shows a document took shape over sittings and days, the way real writing does, without recording a single keystroke or knowing anything about how you personally type. We published the full mechanism, including the parts that don't work in Folio's favor, in Proof of Authorship and the technical specification behind it — we'd rather you check our work than take our word for it.

Our product FAQ states this as plainly as we can put it: does Folio watch how I type? No, and it never will.

What this means if you're evaluating tools

If your institution is choosing between authorship-verification products right now, here's the question we think actually matters, underneath the marketing on either side: what does the tool need to observe to make its claim?

  • A content-detection tool needs to read the finished text and guess at its origin — and that guess is measurably worse for non-native English writers, which is exactly why the category is losing institutional trust.
  • A behavioral tool needs to watch the writer, continuously, to build the profile its claim depends on.
  • A provenance tool needs to watch the document's history — timestamped, hash-committed, and checkable by anyone with the link, without needing to know anything about the person typing.

Only the third one lets you verify the claim without also expanding what the institution is monitoring about its students. That's the trade we'd make in their position, so it's the one we built.

If you're building in this space, or you're at an institution weighing what to do next, we'd like to hear from you.


Attested writing is opt-in per document. The certificate it produces is verifiable by anyone at a public link, with no account and no software.

Ready to write better research?

Folio's Scholar plan is free, forever. Sign up and start in minutes.

Start writing free