Deterministic, third-party re-runnable quote & citation verification. No LLM judge — just string matching and SHA-256.
Paste one or more source documents, then list the quotes an AI (or a person) claims come from
them. CiteLock checks each claimed quote against its source using plain substring search and
Levenshtein similarity — the same algorithm every time, inline in this page's own source code —
and classifies it as VERIFIED (exact, after whitespace/quote-mark normalization),
NEAR MATCH (a close but altered passage — an edited or paraphrased quote), or
NOT FOUND (no matching passage exists in that source at all). The run ends with a
SHA-256 receipt hash: give the same sources and the same claims to anyone, anywhere, and this exact
algorithm produces the exact same hash — that is what "provable" means here, nothing more mystical
than that.
Honest limits. CiteLock only checks whether text is present in the source
you supplied — it cannot tell you whether that source is authentic, unaltered, or
really says elsewhere what it appears to say here. It has no understanding of meaning, so a
verbatim quote can still be misleading out of context. Matching is case-sensitive; only
whitespace, curly quotes/dashes and unicode form are normalized before comparing
(passages ≥90% similar but not exact are labelled NEAR MATCH).
Quotes under three words can't be reliably fuzzy-matched. Nothing you type is sent anywhere or
saved anywhere — this page runs entirely in your browser, offline, and reloading it clears
everything.
1 · Source documents (0)
2 · Claimed quotes (0)
3 · Results
Source
Quote (as claimed)
Verdict
Similarity
Closest passage in source
4 · Verification receipt
This is the SHA-256 hash of a canonical JSON payload built from every
source's hash, every claim, and every verdict above — no timestamp, no randomness. Anyone who
runs the same sources and claims through this same page (open-view-source, it's one file) will
get this exact hash back.
copied
5 · Session ledger (hash-chained audit trail of every run this session)
#
Time
Summary
Receipt hash
Chain hash
Each entry's chain hash covers the previous
entry's chain hash, this run's receipt hash, and this run's verdict summary. Export the ledger,
hand-edit any field in the file, and re-import it — the mismatch is what "tamper-evident" means
here: nothing more than a hash that no longer recomputes.
Independent hash check
Not part of the workflow above — a standalone SHA-256 box so you can
confirm, with your own eyes, that this page uses nothing but the browser's built-in
crypto.subtle.digest. Paste the canonical JSON from the receipt above (or literally
any text) here, or into any other SHA-256 tool, and compare.