FallForge · provable / accountable AI
Prove a redacted document is a faithful, untouched view of a specific committed original — without the verifier ever seeing what was hidden. One file, no server, no AI judging anything.
When an AI (or a person) redacts a document — blacking out names, case numbers, health details, source material — there is normally no way for anyone downstream to check that only the declared parts were touched. Maybe a redaction tool also silently rewrote a sentence. Maybe an extra line quietly vanished. Kar-Veil turns that into something anyone can check by recomputation, not by trusting the redactor's word.
You commit an original document to a single 64-character fingerprint (a Merkle root) before any redaction happens. Later, whoever redacts it publishes a veil proof: the exact text of every line they left visible, plus only the already-known hash of every line they hid. Anyone can recompute the fingerprint from that proof and check it lands on the exact same root — with zero access to the hidden content. If a visible line was quietly edited, or a line was added, dropped, or reordered, the recomputed root will not match, and Kar-Veil names exactly what broke.
Paste the full original document. It is split into lines and each line is hashed with SHA-256 (position-bound), then folded pairwise into one Merkle root.
Uses the document you just committed if there is one, or paste the original again. Tick every line you want to hide, then generate the proof — it contains the full text of every other line, and only the hash of the lines you ticked.
Paste a veil proof. Kar-Veil recomputes the hash of every revealed line fresh from the text in front of it — it never trusts a hash the proof itself states for a visible line — folds in the declared hashes for the hidden lines, and checks the result against the root.
Without this, Kar-Veil can only confirm the proof is internally consistent — not that it is really the document you think it is.
Loads a sample document, commits it, redacts two lines, generates a proof, and verifies it — live, in this page. Then tampers with the proof and re-verifies, so you can see the exact catch happen.
SHA-256("leaf:" + index + ":" + line) — the position is baked into the hash. The line hashes
are folded pairwise with SHA-256("node:" + left + ":" + right) up to one root. An odd hash
at any level is promoted unchanged rather than duplicated against itself, which avoids a known ambiguity
class in naive duplicate-last-node Merkle trees.