IP Notary · ipnotary.ai

Chain of custody for generative AI artifacts

IPNotary seals work produced with generative artificial intelligence and keeps, alongside it, the proof of how that work was made. Every artifact receives a cryptographic seal with a trusted timestamp and enters a verifiable chain of custody — proof of existence, of origin and of the human contribution to the process. Capture happens at the moment of creation, inside the AI tools your team already uses, and not in a form filled in months later, when nobody remembers what actually happened.

The problem this solves is familiar to anyone who works with AI: model-assisted work lives in a grey zone, and memory is not evidence. The question “who actually made this?” tends to arrive late — in a registration filing, in a takedown, in a licensing audit, in acquisition due diligence. At that point, screenshots, loose files and the team’s recollection are worth very little. IPNotary exists so that the answer is already prepared, dated and checkable by third parties.

How it works

1. Connect it to the tools you already use

IPNotary runs as an MCP server inside the AI environments where the work is actually born — Claude Code, Cursor, Kimi, Cowork and equivalent agentic workflows. There is no need to reroute traffic, hand over your model providers’ credentials or switch tools. Capture works from the record your own environments already produce.

2. Work as usual; the trail writes itself

While you generate, direct, iterate, select and edit, the system records each phase with a per-turn timestamp, verbatim from the source. The generation prompt is encrypted and held in escrow, with only its fingerprint published — evidence of creative direction without exposing your creative secret. Nothing has to be remembered or filled in afterwards.

3. Seal, score and verify

At closing, the artifact is hashed with SHA-256 and the seal is written into a hash-chained, tamper-evident ledger. The output comes in three tiers, depending on the recipient: a certificate for a client, a provenance report for a licensee, an evidence dossier for litigation. All of them resolve to the same sealed fact, and anyone can check the integrity through the public verifier, without depending on us.

Use cases

What sets it apart

Frequently asked questions

What exactly does IPNotary prove?

Three verifiable things: that that exact file existed at that instant, that it has not been altered since, and which human phases of the creative process were documented. Whatever was not documented appears as absent, rather than being presumed.

Does IPNotary register the copyright in my work?

No. IPNotary is not a registration authority and grants no rights. It produces technical, dated and verifiable evidence that can support a registration filing, a licensing deal, a challenge or a diligence review. Ownership is decided by the competent authority or court.

How does prompt escrow work?

The prompt is encrypted and held in custody, with only its fingerprint published. Later it is possible to prove that that specific prompt was the one used, without having exposed the text at sealing time.

Do I have to hand over my AI providers’ keys?

No. Capture starts from the record your own tools already produce. We do not ask for provider credentials and no generation traffic is rerouted through us.

What is the difference between IPNotary, C2PA and a plain timestamp?

They are complementary layers. C2PA describes the technical provenance of the file; a timestamp proves existence at an instant. Neither describes the human contribution between the request and the delivery — that is the layer IPNotary documents and assesses.

How does a third party verify a seal without depending on you?

Through the public verifier at ipnotary.ai/verify.html: recalculate the hash of the file in hand and check the integrity of the chaining. The assessment rules live at ipnotary.ai/ruleset.html, so the score can be checked and contested.