Content Signing and not.bot Sign My Work

Updated

Your organization publishes under attack. A video-cloned executive moves money. A deepfaked physician sells a "cure" she never endorsed. A fabricated statement in your candidate's name lands the night before the vote. Each attack works for the same reason: the audience has no fast way to tell your real content from a convincing fake, and detection loses ground with every new model.

not.bot Sign My Work inverts the problem. Instead of proving fakes are fake, you make it easy to prove the authentic is authentic. You sign what you publish, every time, and the signature is a visible code rendered into the content. Anyone can scan it with the free not.bot app and confirm that a verified human authorized to act for your organization signed it. Sign everything you publish, and your audience can dismiss anything unsigned in your name as fake.

not.bot Sign My Work is the hosted member of the not.bot product family, made by Julia Social. It is targeted for launch at the end of August 2026.

How signing worksPermalink to How signing works

not.bot Sign My Work runs on top of the not.bot app, so every human signer starts in the app. You enroll once by scanning your passport (in-person enrollment is planned), which creates a phone-held identity that proves you are a real, unique human without revealing who you are. From that identity you create an alias, a separate working identity, and set it aside for signing on behalf of your organization. That alias is what not.bot Sign My Work knows you by.

You log in to not.bot Sign My Work with the alias. A login request reaches the not.bot app, you confirm it, and you are in. No password exists anywhere in the product, in any role.

You sign under a Verified Signer badge rather than the bare alias. A badge is the human-readable line your audience reads, such as "Editor at dailyherald.com," and Julia Social issues it once your organization has proven control of the web real estate it names. One alias can carry several badges, so a communications team member's signing alias might hold a badge for the company and one for each executive they post for, and they pick the badge that fits each piece of content.

Signing one item is quick. You upload the finished content and not.bot Sign My Work encrypts it. A signature request arrives on your phone as a notification. You tap it, review exactly what a future verifier will see, and confirm with your biometric or device passcode.

From there you choose how the code reaches the content. not.bot Sign My Work can render the QR into the content, and you download the result or post it straight to a connected platform. Or you download the bare signature QR and place it into the content with whatever tool you already use. Either way, anyone can scan the visible code on your content.

What you can signPermalink to What you can sign

Four content types at launch. not.bot Sign My Work stores an encrypted copy of the original, the signature carries the decryption key, and a QR rendered into the published artifact is the verification surface.

  • Video. Limited to 75 minutes or 16 GB per video. For caption-style platforms your caption travels inside the signature, so one signature covers the video and the words you published with it.
  • Images. Platform reformats of the same creative keep one signature, with the QR placed again for each crop.
  • PDFs. The QR is stamped on the last page, lower right. A printed copy stays verifiable, which an embedded e-signature cannot offer.
  • Links. Sign a URL, such as a donation page or payment address, so your audience can confirm the destination came from you before they follow it.

Every distinct piece of content gets its own signature. Reformatting content does not need a new signature. Significant edits do. To sign a plain text post, use the not.bot app, which signs text in a few taps; Sign My Work is built for the content you publish at volume.

The known-good copyPermalink to The known-good copy

When you sign through not.bot Sign My Work, an encrypted copy of the original is stored at a permanent address. The unique decryption key is embedded in the QR signature, and not.bot Sign My Work does not store it. Even Julia Social, the company behind not.bot and not.bot Sign My Work, cannot open the content without the key that travels in the signature.

A verifier who scans your signature can pull up the original in the not.bot app, decrypted on their own device, and compare it against whatever version they received. If it matches, the signature is good.

If it does not match, the verifier knows the signature was copied out of the real content and pasted onto something else. The copy they reach through the app is the unsigned original, your content exactly as uploaded before any QR was rendered onto it.

Storage is perpetual and paid at the moment you sign, not by your subscription. A signed video stays verifiable after you stop paying.

Verifying a signaturePermalink to Verifying a signature

Verification needs only the free not.bot app. A QR scanned by a phone without the app routes to the app store, so every signature in the wild is also an invitation into the verification ecosystem.

On a scan, the verifier sees the Verified Signer badge of the human who created the signature, the signer's message, the timestamp, and whether the signature still stands. The badge is the identity the audience reads. The alias beneath it, its petname and identifier, is available on request rather than shown by default. One more tap opens the hosted original, decrypted on the verifier's device, for comparison against whatever version they found.

The trust calculation itself runs against the public blockchain. Whether the signature is authentic, whether the credential is real and unrevoked, and whether the signer is a verified human are all computed from public on-chain state, so no central server decides whether a signature should be trusted, and Julia Social is not in that loop. Two pieces of a scan do come over the network: the encrypted signature payload, which lives on the Julia Social signature store alongside every app-created signature, and, on that extra tap, the known-good copy served by Sign My Work. Both arrive encrypted and are decrypted on the verifier's own device, with the keys never leaving it.

A signature valid when created stays valid until it is voided, or until the known-good original it points to is permanently gone. Nothing else expires it, so a newsroom's ten-year archive does not rot when staff move on, and offboarding a signer never taints what they legitimately signed. A voided signature shows "voided" and the date, and never who voided it. When the known-good original is permanently gone, the whole signature reads as invalid: a scan shows no signer and no organization at all, so an orphaned code cannot be pasted onto unrelated content to borrow authority.

Who uses not.bot Sign My Work, and howPermalink to Who uses not.bot Sign My Work, and how

The same loop serves organizations of every size, and signing becomes the last production step before anything ships: produce, approve, sign, post.

The solo creator or public figure. A physician, entertainer, journalist, or athlete who frequently posts videos uses not.bot Sign My Work as an organization of one. Record the video, open the not.bot Sign My Work web app on their device, pick the file, type the caption while it uploads, tap Sign & Post. A notification arrives on the phone showing what a verifier will see; glance, touch the sensor, pocket the phone. not.bot Sign My Work renders the branded end-card with the QR, publishes to the connected platform, and pushes a confirmation when it is live. About seven taps and one confirmation per video, with the upload as the only wait.

not.bot Sign My Work's first publishing integration is Instagram, and more are planned. For every other platform, you download the signed content and post it yourself.

The communications team. A brand, newsroom, or campaign desk publishing many items a day works from desktop browsers, where "nothing ships unsigned" becomes routine. Each item costs one phone interaction, and the signed content flows back into the schedulers, ads managers, and publishing tools the team already uses. A crisis statement can go from staged to published in minutes, signed. Paid creatives are a sharp case: a dark ad never appears on a public feed, so the in-creative QR is the only authenticity surface a targeted ad has.

The accountability signer. Organizations that sign to take responsibility, such as AI-content disclosures, compliance statements, and chain-of-custody attestations, treat the signature as a record. Signatures stay valid as of their signing time, voiding is timestamped repudiation that preserves the record, deletion is slow and attributed, and the full signing history exports for auditors.

Platforms, through the API. After launch, a business can request signatures from inside its own product rather than sending people to the Sign My Work web tool. An accounting platform can have its CPAs sign the financial statements they reviewed without leaving the platform; a marketplace can collect signed listings from sellers and signed statements of intent from buyers. The business's backend uploads the content and names the signer, the request arrives on that person's phone, and the signature comes back to the business's system. A human still executes every signature.

Organizations, roles, and onboardingPermalink to Organizations, roles, and onboarding

not.bot Sign My Work has two roles.

  • Admins manage settings, billing, invitations, brand templates, and oversight. They are identified by email. Admins cannot sign content.
  • Members sign. A Member is identified by their not.bot alias. not.bot Sign My Work holds no Member email addresses, names, or other personal information, so it never sends a Member email. An email claiming to be Sign My Work addressed to you as a Member is phishing.

An Admin invites a Member with a single-use, expiring link delivered through whatever channel the team already uses. Opening the link runs the ordinary signature login, and the alias that answers becomes the Member. Acceptance is login; no registration form exists.

Verified Signer badges are how an organization authorizes its signers, and what a badge can say depends on the plan, because the plan sets how much of your web presence Julia Social verifies.

  • Social account badges. The signer posts their alias identifier to a social account they control. Julia Social verifies it and issues a badge naming that account, such as "@yourhandle at instagram.com." This identifies the account on purpose, which is what a creator wants.
  • Role badges. The organization posts the alias identifier on a site it controls, next to the role it chooses. Julia Social verifies the posting and issues the role, such as "Customer Support at ExampleCompany.com." The human behind the role stays anonymous.
  • Domain-assigned badges. The organization proves control of its domain once with a DNS TXT record. After that its Admin assigns badges directly, using any name at that domain, with no per-signer review and nothing posted publicly.

Signing is blocked until a Member's badge is live, because an organizational signature without the organization's badge is a contradiction.

The meaning of a not.bot signature is precise: a human authorized to sign on behalf of the organization signed this. It is never a claim of personal authorship. A campaign staffer signing under "Joe Candidate at joecampaign.org" produces what a press release is, made cryptographically checkable. Personally identifying claims are excluded from signatures by default; a signer who wants their own name in a signature, such as a professional signing under their own license, adds it deliberately.

Offboarding is one immediate action. Remove a Member and their membership ends, their sessions are killed, and revocation of their badge begins. Everything they signed stays valid, so the organization's signed history survives staff turnover untouched.

The signing experiencePermalink to The signing experience

No passwords exist, in any role. There is nothing to phish, leak, stuff, or reset. Members log in with a signature: a request reaches the not.bot app, and a biometric or device passcode completes it. Member sessions last 30 days and end early only when the Member logs out or is offboarded. Admins log in by a single-use email magic link plus a mandatory second factor, or a passkey that replaces both, and sensitive actions such as deletion and offboarding require confirming that second factor at the moment of the act.

Every signature request arrives by push notification. On desktop, on mobile, and for login itself, the request lands on the signer's phone and the ceremony runs from there. The push channel is privacy-preserving by construction: requests reach a phone without Julia Social learning who is asking whom to sign, and a user can block any sender.

Mobile is an installable web app. An icon on the home screen, full screen, with push notifications, and nothing to install from an app store beyond the not.bot app the signer already has. One-time setup covers enrolling in the app, adding not.bot Sign My Work to the home screen, connecting a publishing platform, and choosing an end-card template.

The ceremony shows verifier parity. What the app displays for review is exactly what a future verifier will see: the badge, the message, and the content reference. Review-what-you-sign and verify-what-was-signed are the same thing.

Sign-and-download is universal. Every signed artifact, and the bare QR for teams that composite in their own tools, is always downloadable for any platform, scheduler, ads manager, or print shop. Direct-publish integrations remove steps where Julia Social can build them; they do not limit where you publish. Instagram-direct is the first integration: connect once over standard OAuth, and the token is kept encrypted in a key vault separate from the database. You can revoke that access at Instagram at any time.

Staged items do not linger. An uploaded but unsigned item expires after an hour of your inactivity and is deleted. Unsigned material does not accumulate in Sign My Work.

What sets not.bot Sign My Work apartPermalink to What sets not.bot Sign My Work apart

A human signs every item. not.bot Sign My Work holds no signing keys and signs nothing on anyone's behalf. Every signature is produced by a verified human on their own device. There is no automated signing, no service account, and no setting or support request that can produce a signature without a person. This holds for the API as well: the API stages content and delivers the request, and a human still signs.

The signature survives the open internet. Signatures are QR codes rendered into the content: a branded end-card on a video, a stamp on a PDF. Platforms strip metadata. They do not strip pixels. Screenshots, re-encodes, re-uploads, and printouts keep the signature scannable. The code also tells a viewer that verification is available, which a hidden watermark does not do.

not.bot Sign My Work cannot read uploaded content. The originals it stores for verification are encrypted, and it does not keep the decryption keys. The keys travel inside the signatures, held by you. It does not keep copies of your signatures either. Someone who took everything not.bot Sign My Work stores would have no way to open any of it.

Plans and record disciplinePermalink to Plans and record discipline

Plans are simple by design. One subscription covers the organization, and each plan includes a number of signers, a monthly signature allowance, and a monthly video allowance that pool across the organization. There is no metering of any kind: no per-minute video charge, no per-signature charge, and no overage billing, so a Member can never run up a bill. Outgrowing a plan means moving up a plan. Admin accounts are free in any number. The not.bot Sign My Work product page carries the current plans and numbers.

Voiding is the low-friction safety valve. The signing Member can void their own items, and an Admin can void anything in the organization. Verifiers see the signature as voided from their next scan, and the record that it existed remains.

Deletion is the guarded act. Only Admins can delete, with a fresh second factor. The signature stops verifying immediately. Deletion is reversible for 90 days, after which the content is purged permanently and a metadata record of what was deleted, by whom, and when survives in the audit trail. Every deletion lands in a daily digest to all Admins, attributed. Quiet deletion, hasty deletion, and deniable deletion are all structurally impossible; deletion itself remains entirely possible.

Audit export gives Admins the organization's complete signing-activity record as CSV or JSON: every item's signing alias, timestamps, status, void and delete actions with actor and time, and records of deleted items. It is built for the SOC 2, HIPAA, and SOX conversation, where "we sign everything" needs to be a documented control.

Privacy and security for due diligencePermalink to Privacy and security for due diligence

Each property below follows from how the system is built.

A total breach of Sign My Work yields no route to any content. An attacker stealing all of not.bot Sign My Work's storage gets encrypted content and no keys. The maximum exposure is bounded operational metadata: organization names and settings, brand templates, public Member alias identifiers and their membership status, item titles and types and timestamps and statuses, void and delete history, Admin email addresses, billing records, and unusable platform-token ciphertext. No content, no signature, no signature message, no decryption key, no usable session, no Member email, and no cryptographic link between two aliases or between a human and an alias is in that set.

Plaintext media never touches a disk. Unencrypted content exists only in server memory, only while your own request or publish job is being processed, and is wiped when that window closes. Previews are generated in your browser and never uploaded; not.bot Sign My Work's servers never decode your media.

Sessions cannot sign. A Sign My Work session lets you stage and manage content. It cannot produce a signature; only the ceremony on your phone can. Logging out or being offboarded destroys the session server-side at once, which makes any stolen cookie inert.

No scan analytics. not.bot Sign My Work does not count, report, or expose who verifies what, to organizations, Members, or anyone. The trust check runs between the verifier and the public blockchain.

Honest disclosures. Item titles and other operational metadata are stored in plaintext so the dashboard, deletion digest, and audit export can function; keep content out of titles, since the title is the one free-text field stored unencrypted. The roles one alias signs under are linkable to each other in public, though never to the human, so an organization that wants role separation uses one alias per role. In an organization of one, not.bot Sign My Work's own billing records plus the single published alias support an inference tying the payer to the signing alias; a signer whose safety depends on no such link should use the not.bot app's on-device path with app-store billing. not.bot Sign My Work is not an anonymity system against its own records or legal process.

How not.bot Sign My Work fits with Verify and the not.bot familyPermalink to How not.bot Sign My Work fits with Verify and the not.bot family

Where not.bot Verify is server software a business deploys in its own infrastructure to verify users, not.bot Sign My Work is hosted by Julia Social: no servers, no deployment, no key management. You bring a browser and the not.bot app. not.bot Sign My Work's own backend is a not.bot Verify customer, so it runs on the same production-proven machinery it asks no customer to deploy.

Enterprise deployments are the exception, and they arrive after the API. Enterprise not.bot Sign My Work runs on the customer's own not.bot Verify installation. Content never leaves the customer's infrastructure, it is served to verifiers through an encryption gateway the customer operates, and the customer's own retention policy governs how long a signature stays verifiable: when the customer disposes of content on its own schedule, those signatures simply read as invalid. Verification is identical for the public either way.

Availability and requirementsPermalink to Availability and requirements

  • Launch target: the end of August 2026. Until then, not.bot Sign My Work is "coming soon." The API and enterprise deployment follow the launch, in that order.
  • For signing: the not.bot app on iOS or Android with a passport-enrolled identity, and a browser. Mobile signing works best as the installed web app; push notifications need iOS 16.4 or later.
  • For verification: the free not.bot app, with no account of any kind.
  • For organizations: control of the web real estate your plan verifies, which is a social account, a site you control, or your domain's DNS; an email address per Admin; and a card for billing.
  • Hosted by Julia Social. Support: support@julia.social.

Further readingPermalink to Further reading