Question and scope
Which changes can simple fingerprints detect, and which conclusions remain unsupported? We measured six deliberately constructed captures of a small service notice. These are synthetic fixtures, not observations of real organizations or a representative sample of the web.
The baseline notice says service resumes at 09:00. Variants change the time, an HTML class, a metadata date, the URL, or availability. One case preserves the baseline. No external pages, customer data or private product information were collected.
Method
The script uses Node's SHA-256 implementation on exact UTF-8 fixture strings, then compares hashes with the baseline. A second representation removes tags from these known simple fixtures, collapses whitespace and hashes the resulting text. URL and metadata changes are separate comparisons. Missing content produces a null result, never an unchanged classification.
Run node scripts/provenance-experiment.mjs from the repository. The downloadable dataset includes every input and fingerprint. The code is supplied beside it. The text extractor is deliberately narrow; it is not an HTML parser suitable for production websites.
Findings
The claim edit changes both fingerprints. The markup-only edit changes the raw fingerprint while leaving extracted text unchanged. Changing only metadata or moving the same body to another URL changes neither content fingerprint. The unavailable case has no comparable body.
All six results follow from the specified fixture transformations. They establish behavior of this comparison procedure on these inputs, not detection rates on a wider population. Neither fingerprint establishes whether the reopening claim is true.
| Case | Raw bytes | Extracted text | URL | Metadata |
|---|---|---|---|---|
| Unchanged capture | Same | Same | Same | Same |
| Claim edited at same URL | Changed | Changed | Same | Same |
| Markup-only edit | Changed | Same | Same | Same |
| Metadata-only edit | Same | Same | Same | Changed |
| Moved URL, same body | Same | Same | Changed | Same |
| Unavailable capture | Unavailable | Unavailable | Same | Unavailable |
Implications for a monitoring system
Keep content, location, metadata and retrieval outcome as separate signals. Preserve both raw and derived captures when permitted. Classifying every raw edit as a substantive claim change creates noise; classifying a failed retrieval as unchanged conceals missing evidence.
Use the result to guide review rather than to automate a conclusion about an organization. A fingerprint can support the statement that captured content differs. Understanding the difference still requires inspecting the evidence.
Limitations and version
Version 1.0, 3 October 2026. Six deterministic fixtures, no sampling, no browser rendering, no redirects over a network and no independent truth assessment. The synthetic 404 is an input state, not a measured live response. Dynamic content, encodings, extraction errors and meaningful non-text content are outside scope.
AI assisted the script and analysis. The measurements were executed locally and inspected during preparation. The company owner approved editorial/disclosure publication on 3 October 2026. No independent peer review is claimed. The original synthetic inputs and measurements are supplied for reproducing this experiment; linked standards retain their own rights.
Reproduce the experiment
Download inputs and measured results (JSON)
Download experiment script (JavaScript)
For a standalone run, create src/content and public/research directories, then run the script with Node.js. It writes the two result files shown in the method.
Sources
Suggested citation
AEY GROUP (2026). What a source-change signal can prove. Version 1.0. AEY Research. https://aeygroup.co/research/reports/source-change-signals