A provenance-hygiene tool with a hard line drawn in code, not just marketing: what it removes reliably and verifiably, versus what it can only ever attempt, best-effort, never certified.
The name is broad on purpose — so the README, and this page, exist to scope it accurately before anything else. "Watermark removal" means three unrelated things here.
The word-choice pattern is keyed by the vendor. Detecting or certifying its removal from outside the vendor is cryptographically impossible, not just unimplemented. Module 2 offers a best-effort, quality-costing disruption — never a guarantee.
best-effort · unprovableSigned metadata on images, PDFs and SVGs — not a hidden watermark, per Anthropic's own documentation. Detected by real JUMBF box structure, not text matching, and removed deterministically for PNG, JPEG, WebP, and most PDF embeddings.
reliable · verifiableZero-width characters, bidi-override tricks, tag-character steganography, and stray EXIF/XMP/doc-properties left behind by AI tooling generally — deterministic, byte-diff tested, no cryptographic barrier involved.
reliable · verifiable| Channel | Reliable | Best-effort |
|---|---|---|
| Invisible Unicode / bidi / tag-character carriers | Layer A, unit-tested | — |
| C2PA manifest — PNG / JPEG / WebP | Structural JUMBF/UUID validation | — |
| C2PA manifest — PDF (non-attachment) | exiftool + qpdf structural rewrite | — |
| C2PA manifest — PDF file attachment | Detection only | Removal out of scope (needs a full PDF library) |
| File metadata — PDF/PNG/JPEG/WebP/DOCX/SVG/HTML/MD | Yes | — |
| Claude's statistical text watermark | Cryptographically impossible | Module 2, disrupts, never certifies |
No format was shipped until a real, structurally valid marked sample proved the marker's bytes are actually gone from the output — not just that the tool exited 0.
Every finding is classified confirmed / probable / informational —
only confirmed is removed by default, so the false-positive rate stays measurable
instead of asserted.
Without the vendor's signing key, no tool — this one included — can detect or certify removal of a keyed statistical watermark. That's a cryptographic property of the scheme, not an engineering gap. Anyone selling "guaranteed" or "detector-proof" text-watermark removal is selling something that cannot exist.