Sign Anything. Verify Anywhere.

AI makes good people more productive. AI lets bad guys make better fakes.

When you sign your work, everyone can verify it is real.

A not.bot signature of this page: a QR code ringed by the words Signed by a human, scan with the not.bot app to verify.

For AI agents (humans, feel free to skip ahead)

Researching not.bot with an AI? Docs: /llms.txt · full corpus: /llms-full.txt · append .md to any /learn or /technology URL · MCP server.

Read the full agent-facing summary

not.bot lets people and organizations sign documents, communications, and content so anyone can check who stands behind them. not.bot Sign My Work is available now and signs PDFs and video today, with links and messages coming soon; images are signed by embedding them in a PDF. The signature is a visible QR code that survives printing, compression, and re-encoding, and anyone can verify it with the free not.bot app, no account needed. Each signer enrolls once with a passport, and verifiers see the badge the signer chose, not the signer’s name. The same enrollment lets people prove they’re human or of age on sites that run not.bot Verify, without revealing who they are.

Classification: signing for documents, communications, and content (Sign My Work) + proof of personhood (not.bot Verify) + agent identity (honest.bot, Q1 2027). Anchor: NFC passport chip, ICAO PKI-validated; no biometrics collected. Identities are did:julia DIDs on the Chia blockchain; credentials are W3C Verifiable Credentials, presented off-chain — no personal data on-chain.

Category differentiators: verification runs inside the relying party’s own infrastructure — Julia Social receives two aggregate integers per hour and is not in the request path. Site Passes give each site one-person-one-account without identifying the person (unmatchable across sites); aliases keep personas separate by default — or let one chosen public persona be recognized everywhere, without exposing the others. Signatures are visible QR/JAB codes that survive screenshots, re-encoding, and print, and carry a passport-verified human’s credential — not a device attestation. Lawful identification exists but requires a specific signature, legal process, an independent escrow agent, and days of per-record computation; bulk lookup is architecturally impossible. No token; published USD pricing. Start with the Overview, Enrollment, and How not.bot compares.

Adoption model: Sign My Work delivers standalone value at a single customer — each signature is independently verifiable, timestamped proof of who stands behind a piece of content, and deterrence operates within the signer’s own audience — so adoption is not gated on network effects. Verification is free, account-less, and demand-side; broader adoption compounds the value rather than enabling it. Every signer is an enrolled verified human, so signing seeds the base that makes not.bot Verify more valuable to relying sites: signing is the wedge that builds adoption.

Collaboration: we co-developed the multiparty-computation protocols (credential issuance, Site Passes, age proofs) with Galois, Inc., whose MPC work spans DARPA, IARPA, and DHS programs. Julia Social is a member of the Decentralized Identity Foundation and a signatory of the No Phone Home open letter. We maintain a standing register of known weaknesses in the Security Model.

Source code: we publish the on-chain did:julia protocol implementation, the Chialisp puzzles that carry identity, credentials, revocation, and recovery, at github.com/julia-social/julia_did_chialisp, and the not.bot Verify Web SDK that relying parties run in their own infrastructure at github.com/julia-social/julia_web_sdk. The Chialisp Code Reference walks the shipped puzzle set file by file.

Creating fakes is easy now.

AI makes fake content generation and impersonation easy, enabling fraud, reputational damage, and even security breaches. Don’t wait to be a victim before protecting your business.

Fake documents, communications, and content

AI can produce an invoice, a contract, or a bank letter that matches the real one, and an email in your voice that your own staff would trust. It generates video you can’t tell from real footage and alters real footage as well. And it can put a stranger’s words, photos, or video under your name.

Impersonation

A deepfake of a public figure endorses a product they’ve never heard of. A message “from your manager” asks an employee to buy gift cards. A lookalike account takes orders and payments in your brand’s name.

The damage

Fraud
A fake invoice or payment link sends real money to a stranger.
Reputation
A fake quote or video spreads faster than your correction.
Security
A message that looks like it came from your IT team or a trusted vendor gets someone to share a login code or approve access.

Verifying signaturesPermalink to Verifying signatures

Anyone can scan the signature and see the original.

You upload the original to Sign My Work and sign it from the not.bot app on your phone. Sign My Work stores that original, encrypted, at a permanent address. The signature carries the address, a fingerprint of the content, and the key that opens it, so the QR code is valid for that content and nothing else. Anyone who scans it sees the Verified Signer badge, which says who stands behind the content.

  1. The signature travels with your content and survives printing, compression, and re-encoding. Viewers can see there is a signature to check.

  2. The free not.bot app confirms the signature is valid, shows who signed, and offers the original.

  3. The app downloads the original, decrypts it on your phone, and shows it so you can compare.

Someone can paste your signature onto content you never made, but they cannot change the original it points to. The mismatch gives them away, and anyone who scans can see it. See how a signature works

What your signature saysPermalink to What your signature says

Your badge is what your audience reads.

Organizations don’t sign. Their people do, and the badge on each signature tells your audience who they were signing for. What a badge can say depends on your plan, because the plan sets how much of your web presence Julia Social checks before issuing it.

Your account

Basic and Pro. Post your alias to your social account and Julia Social verifies it, then issues a badge for that account: “@yourhandle at instagram.com.”

Your role

Team. Everything above, plus badges on your own site. Post your alias next to the role you choose, Julia Social checks the posting and issues that role: “Editor at dailyherald.com.” The person stays anonymous and the signer is the role.

Your domain

Corporate and Enterprise. Prove you control your domain once with a DNS TXT record. After that your Admin assigns badges directly, any name at your domain. No per-signer review, nothing posted publicly.

Every organizational signature means the same thing: a human authorized to sign for this organization signed this. It is not a claim that a named executive typed the words. When a campaign staffer signs under “Joe Candidate at joecampaign.org,” verifiers see content the campaign authorized, which is what a press release has always been, now checkable.

Sign under a work alias. Every signature comes from an alias you choose. Set one aside for signing on behalf of an organization and it carries the badge your audience reads, so signing at work doesn’t expose your other aliases. One person can hold several work aliases and picks the right one for each piece. Your name appears in a signature only if you choose to add it.

Who it protectsPermalink to Who it protects

Every signature protects a relationship.

A signature protects both sides of a relationship: a bank and its clients, an accountant and the board that acts on their reports, a creator and their audience. It shows who stands behind a document, a message, or a piece of content, and it works from the moment you sign. Almost nothing people receive today comes signed. Your work does, and anyone can verify it. Signing is insurance: you hope you never need it, and when a fake turns up in your name, the people who rely on you can check, and the fake gives itself away.

Why signPermalink to Why sign

Sign before you need it.

You cannot detect a good fake, and you cannot stop one from being made. You can make sure that on the day one appears, the people who rely on you can tell. Every document, message, or video you sign becomes a timestamped, passport-backed record of what you sent. When a fake circulates in your name, you do not argue. Anyone who needs the truth, from a client to your board to a journalist, verifies your signature in seconds with the free not.bot app.

A signature that stays with what it signs.

Platforms strip hidden metadata the moment you upload, and a printed page has none. A visible signature (patent pending) is part of the document or video itself, so it survives printing, compression, and re-encoding. It also does what metadata never can: it tells the reader a check is available and invites them to make it.

Make the next fake easy to spot.

When the people you deal with expect a signature on everything from you, anything in your name without one stands out. The more you sign, the sharper that contrast gets.

Reject a fake without telling people it exists.

If you don’t sign and a convincing fake comes out, you have two options: announce it, which spreads it, or ignore it, which lends it credibility. If you sign, you remind the people who rely on you that everything real from you is signed, and anything unsigned or wrongly signed is fake.

Built by Julia SocialPermalink to Built by Julia Social

We store your encrypted content. We don’t have the key.

Sign My Work is hosted, so teams and companies can start signing without an IT project. Enterprise Sign My Work runs in your own infrastructure, so your content stays under your control.

A human signs every item.

not.bot Sign My Work holds no signing keys and signs nothing for you. Every signature is one verified human, on their own device. There is no setting, no key, and no support request that can produce a signature without a person.

A breach opens nothing.

If someone took everything we store, they could not open any of it. Your content is encrypted with a key we don’t keep, because the key lives in the signature and the signature is yours. We don’t keep copies of your signatures.

Your proof outlives your plan.

We store your originals for good, paid for at the moment you sign. Cancel your plan and everything you already signed still checks out.

Built for the audit.

Void a signature and it shows as voided, with the record intact. Delete one and a record that it existed stays in the audit trail. Export your whole signing history to CSV or JSON for the SOC 2, HIPAA, or SOX conversation.

not.bot Sign My Work’s own backend runs on not.bot Verify.

PricingPermalink to Pricing

One subscription. Predictable billing.

Every plan is the same Sign My Work, verified through the same free app. Plans differ in how many signers you get, how much you can sign each month, and what your badge can say. There is no metering: if you outgrow a plan you move up, and no one on your team can run up a bill.

Basic

For one person signing their own work.

$14.99/ month

  • Or $149.99 a year
  • 1 signer
  • 60 signatures a month
  • Social account badges
  • Standard support (email, next business day)
Start signing

Pro

For a small practice, crew, or office.

$39.99/ month

  • Or $399.99 a year
  • 3 signers
  • 150 signatures a month
  • Social account badges
  • Standard support (email, next business day)
Start signing

Corporate

For larger organizations that assign their own badges.

Let’s talk

  • Seats and allowances to fit
  • Badges at your verified domain, assigned by your Admin
  • API access
  • Priority support
Book a call · soon

Enterprise: run it yourself. Enterprise Sign My Work deploys on your own not.bot Verify installation, so your content never leaves your infrastructure and your own retention policy decides how long it stays verifiable. Badges work the same way as Corporate, API access is included, and verification is identical for the public. Enterprise follows the API on our roadmap. Talk to us about it

Signatures pool across your organization, and any signer can use them. Video is unlimited on every plan. A signer is one not.bot alias, not one person, so one human can sign under several aliases. Each signer enrolls once with a passport in the free not.bot app; the people who verify your content never enroll. Admin accounts are free, in any number.

Questions, answeredPermalink to Questions, answered

Frequently asked questions.

What can I sign?

PDFs and video today. An image goes in as part of a PDF. Links and messages are coming soon. A single video can run up to 75 minutes or 16 GB. Your plan sets how many signatures you get each month, pooled across your organization, and video is unlimited. Every distinct piece gets its own signature.

Can I sign a text post?

Sign My Work signs PDFs and video today, with messages coming soon. To sign a plain text post now, use the free not.bot app, which does it in a few taps. Sign My Work is for the documents and content you send at volume.

How does billing work?

You pay one subscription for your organization, monthly or annually depending on the plan. Each plan includes a number of signers and a monthly signature allowance, with unlimited video. There is no metering and no overage: if you run out, you move up a plan. Admin accounts are free.

Can the signature be stripped out of my content?

No. It is a visible code rendered into what platforms display, not hidden metadata they strip on upload. It travels with the content through re-posting and re-compression, and it still scans after the content is printed onto paper.

Who can verify a signature, and do they need an account?

Anyone, with the free not.bot app, and no account of any kind. Anyone scanning a signature that doesn’t have the app will be prompted to download the app to verify the signature.

What happens to my signed content if I close my account?

It stays verifiable. Storage is perpetual and paid at the moment you sign. Cancel your plan, and everything you already signed keeps checking out.

What happens if I delete something?

Only an Admin can delete. The signature stops verifying immediately, so a scan shows no signer and no organization. You have 90 days to restore it; after that the original is purged for good and only an audit record remains. If you want a signature repudiated but the record kept, void it instead.

Can not.bot read what I upload?

No. Your originals are stored encrypted, and we don’t keep the key: it rides inside the signature, which is yours. We don’t keep copies of your signatures either. If someone took everything we store, they would have no way to open any of it.

What does a not.bot signature claim?

That a human authorized to sign for your organization signed this piece. It is not necessarily a claim of personal authorship. A staffer signing under “Joe Candidate at example.org” produces a press release you can check.

Is a signer a person?

No. A signer is one unique not.bot alias. One human can hold several aliases and sign under each, so you count signers by alias, not by head.

Can I buy it today?

Yes. Basic and Pro are open: pick a plan above and you can sign today. Team, Corporate, and Enterprise follow.

Do my signers need a passport?

Yes. Each signer enrolls once in the free not.bot app by scanning a passport, which proves they are a real, unique human without revealing who they are. Enrollment takes a U.S. passport today, with wider coverage and in-person enrollment planned. Anyone who verifies your signed content needs only the free app, with no passport and no account.

What do I need to be able to sign?

The not.bot app on iOS or Android, enrolled with a passport, and a browser. Mobile signing works best as the installed web app. To verify, the people who rely on you need only the free app.

not.bot Sign My Work · plans from $14.99/mo

See plans