A deterministic Unicode integrity auditor for text an AI system reads, writes, or is asked to act on.
Glyphguard scans any pasted text for Unicode tricks used to smuggle hidden or spoofed content past humans and keyword filters: invisible characters, bidi overrides, homoglyph lookalikes, styled "math-alphabet" letters, fullwidth forms, and the invisible Unicode tag block. The scan is a pure function of the input text — no model, no judgment call. Re-run the same text through this same page (or a fresh reimplementation of the method below) and you get a byte-identical report and SHA-256 hash, every time.
Honest limits — read before trusting a "clean" result
The homoglyph list is a curated set of ~40 well-known Cyrillic/Greek/Latin lookalikes, not the full Unicode Confusables database (thousands of entries). A "clean" result means none of this list matched, not that no lookalike character exists anywhere in Unicode.
Mixed-script flagging only fires when Latin is mixed with Cyrillic or Greek inside the same whitespace-delimited token — chosen to avoid false alarms on ordinary multilingual or emoji text. Other script combinations are not flagged.
The Mathematical Alphanumeric Symbols decode covers Latin letters and digits only (13 styles), not the Greek math-style ranges in the same block.
Variation selectors are flagged as present (a known covert-data channel) but their payload is not decoded.
This is static text analysis, not a sandbox — it cannot tell you what a model or browser will actually do with the text, only what unusual characters are hiding inside it.
Nothing here is sent anywhere. Every check runs locally in this browser tab.
1 · Scan text
Try an example:
2 · Result
#
Pos
Codepoint
Char
Category
Severity
Detail
No rows — nothing matched any check.
3 · Proof
SHA-256 over the exact input text, and over the canonical (sorted-key) JSON report below. Re-running the scan on identical text always reproduces both hashes, byte for byte; changing a single character anywhere changes both.
Input SHA-256—
Report SHA-256—
4 · Verify a report
Paste text and a report.json exported above (yours, or anyone else's). Glyphguard re-runs the scan from scratch and checks whether the result is byte-identical to what was claimed — the same re-run a third party would do to confirm a report wasn't doctored.
5 · Self-test
Runs the whole promise live, in this tab: scan a sample → export its report → verify it matches → tamper with a copy of the report → verify again and confirm the tamper is caught.