Standards explained
C2PA and Content Credentials
A detector score guesses at origin from patterns. C2PA does something fundamentally different: it records origin at the moment of creation, cryptographically signed. That makes it the strongest evidence a file can carry about itself — and one most content will never have.
How it works
A camera, editing tool or generator that supports C2PA attaches a signed manifest when saving: who or what made the image, with which tool, when, and which edits followed. Each later step — cropping, exporting, publishing — can be signed again, forming a chain. The chain verifies without knowing the creator: the signature either checks out or it does not.
Why this beats detection
A detector says: this image resembles what we know as synthetic. A valid C2PA manifest says: this party signed that this tool produced this file. The first is a statistical signal with a measurement error; the second is a statement with a cryptographic signature. That is why our results always show Content Credentials next to the score, never beneath it.
Where it stops
- Absence proves nothing. Most cameras, platforms and generators do not sign (yet). No manifest does not mean 'not AI'.
- Metadata can be stripped. A screenshot or a download through a platform that removes metadata breaks the chain. A broken chain is not evidence of bad faith.
- A manifest is as honest as its signer. It proves a party declared something, not that the declaration is true.
- Platforms differ. Some social platforms preserve credentials, others strip them on upload. The same image can carry a chain in one place and none in another.
How to use it
Check a suspect image for credentials first — our image detector reads them automatically and reports them as 'present', 'invalid' or 'absent'. A valid manifest outweighs any score. No manifest: fall back to the manual checks and the detector score together. More about our provenance approach is under governance.