Global site search

Search guides, labs, glossary, and research

Type two or more characters to search.

Start with a channel, artifact, or defense term

Examples include zero-width, metadata, tokenizer, or prompt injection.

    MANIFESTS · SIGNATURES · WATERMARKS

    Content Provenance and Authenticity Signals

    Separate provenance, integrity, authenticity, attribution, and truth while examining manifests, signatures, Content Credentials, fingerprints, and watermarks.

    Quick answer

    What does this Machine Tradecraft expansion explain?

    Content provenance records an asset’s claimed origin and transformation history; integrity shows whether protected bytes changed; authenticity and attribution bind claims to an identity; none of those properties alone proves that the depicted or stated content is true.

    Hard binding
    A cryptographic hash binds a manifest to exact asset bytes.
    Soft binding
    A fingerprint or watermark can help recover credentials after transformation or metadata stripping.
    Central principle
    Provenance can make history inspectable without establishing real-world truth.
    Reviewed implementation boundary

    Know what is measured, approximated, and still external.

    The submitted report remains byte-identical. This separate review, checked 2026-08-26, narrows implementation claims and gives visitors a decision path before they generalize from a local result.

    IMPLEMENTATION MODE Image metadata and provenance-token structural scan
    VISIBLE SOURCE PROFILE 2 standards/specifications · 0 research · 1 government · 3 implementation
    SOURCE BODY Preserved; corrections live in this review layer
    Directly computed

    Output produced deterministically by the local runtime.

    • Exact outer digest, supported image dimensions, PNG/JPEG structural metadata, and occurrences of selected provenance-related byte strings
    • Whether the uploaded file contained the specific allowlisted marker tokens searched by the lab
    • A clear structural-only result with no network call
    Bounded approximation

    Useful model or subset that must not be mistaken for full conformance.

    • String occurrence is not a conforming JUMBF, CBOR, COSE, claim, assertion, or hard-binding parser
    • Absence of selected strings does not prove absence of provenance, watermarking, or sidecar credentials
    • No perceptual fingerprint or invisible watermark detector runs in the public runtime
    Requires external verification

    Conclusion that needs an exact implementation, trust system, model, parser, or human review.

    • C2PA validation requires conforming manifest parsing, hard-binding checks, signature validation, certificate-chain and trust-list policy, timestamps, and revocation handling
    • Soft-binding resolution may require authorized remote repositories and privacy review
    • Truth, context, intent, and real-world accuracy always require independent evidence
    Decision support

    Choose the next evidence step instead of treating one result as a verdict.

    QuestionWhat the local page can answerWhat it does not establishNext evidence step
    Does the file contain selected provenance-related strings?Yes — the byte scan reports exact occurrences.A valid C2PA manifest or signature.Use a conforming verifier and record its policy and trust inputs.
    Is the signer trusted?No trust evaluation is performed.Identity, chain validity, revocation, timestamp, or trust-list acceptance.Run an approved verifier with current trust data.
    Is the media true?No provenance mechanism can answer this alone.Physical or semantic truth.Corroborate with independent contextual and forensic evidence.
    Focused deterministic fixture

    Governed PNG metadata fixture and token scan

    Demonstrates structural metadata versus cryptographic verification and truth boundaries.

    Expected boundary: The lab reports exact bytes and selected markers while refusing a validity verdict.

    Open prepared laboratory
    Compare independent views

    One artifact, several machine-readable representations

    No single view is automatically authoritative. Preserve the source, identify each parser or receiver, and compare their outputs before authorizing a consequential decision.

    01Asset bytes

    The exact file digest and detected media structure.

    02Manifest

    Claims, assertions, ingredients, actions, and bindings when structurally present.

    03Signature fields

    Algorithm, certificate, and timestamp claims requiring cryptographic validation.

    04Soft signals

    Watermarks or perceptual fingerprints designed to survive selected transforms.

    05Trust policy

    Accepted issuers, identities, revocation, and verification time.

    06Truth assessment

    Separate contextual investigation outside the cryptographic claim.

    Bounded method

    Analysis workflow

    The workflow preserves evidence before transformation and keeps structural inspection separate from execution, remote verification, or model behavior.

    1. Hash and preserve the asset before transformation.
    2. Locate embedded or sidecar provenance structures.
    3. Validate hard bindings and signatures with an approved verifier and trust policy.
    4. Check certificate status, timestamps, exclusions, and ingredient lineage.
    5. Treat missing credentials as unknown, not proof of fabrication.
    6. Assess semantic truth through independent evidence.
    Defense in depth

    Controls carried into implementation

    These controls are contextual. They reduce a defined risk; they do not guarantee safety, truth, attribution, or resistance to every adaptive attack.

    01

    Display structural, cryptographic, trust, and semantic states separately.

    02

    Avoid UI language that turns a valid signature into a “true” badge.

    03

    Minimize privacy-sensitive provenance assertions.

    04

    Preserve manifests through platform transforms where policy permits.

    05

    Use multiple validators and record version, trust list, and revocation behavior.

    Shared vocabulary

    Key terms

    Definitions are linked into the site-wide glossary and back to the full report.

    Content provenance

    An auditable record of an asset’s claimed origin and transformations.

    Manifest

    A structured container of claims, assertions, ingredients, and a signature.

    Assertion

    A specific statement recorded inside a provenance manifest.

    Ingredient

    A source asset incorporated into a derived asset.

    Trust anchor

    A root identity or authority accepted by a verification policy.

    Perceptual fingerprint

    A similarity-preserving descriptor used to associate transformed content with known records.

    Robust watermark

    A hidden signal designed to survive specified transformations.

    Continue with primary material

    External standards and research

    These links are provided for visitors who want the governing specification, paper, framework, or implementation documentation. Links open in a new tab; the site does not fetch them during runtime analysis.

    Authoritative guidance Standards organization

    C2PA

    Organization and ecosystem overview.

    First-party guidance, framework, registry, or standards-program material.
    c2pa.org
    Authoritative guidance Specification index

    C2PA specification index

    Versioned technical specifications.

    First-party guidance, framework, registry, or standards-program material.
    spec.c2pa.org
    Authoritative guidance Government report

    NIST Synthetic Content Overview

    Provenance, watermarking, and detection taxonomy.

    First-party guidance, framework, registry, or standards-program material.
    www.nist.gov
    Implementation reference Verification tool

    Content Credentials Verify

    Public verification interface; use with stated trust and privacy limits.

    Tool, vendor, or implementation documentation; behavior is version-specific.
    contentcredentials.org
    Implementation reference Adoption guide

    Content Credentials adoption resources

    Publisher and tool integration guidance.

    Tool, vendor, or implementation documentation; behavior is version-specific.
    contentcredentials.org
    Implementation reference Vendor documentation

    Google DeepMind SynthID

    Vendor description of cross-modal watermarking.

    Tool, vendor, or implementation documentation; behavior is version-specific.
    deepmind.google
    Supporting resource Implementation guidance

    C2PA implementation guidance

    Implementation and user-experience guidance.

    Useful supporting material that does not replace the governing specification or original study.
    spec.c2pa.org
    Continue the investigation

    Read the evidence, then test the bounded model

    The full submitted report is preserved byte-for-byte in the governed research library and in durable repository documentation. The laboratory turns selected concepts into deterministic local output without external calls or hidden persistence.

    Detailed report

    Content Provenance, Content Credentials, Watermarks, and Authenticity Signals

    A detailed separation of provenance, integrity, authenticity, attribution, truth, manifests, C2PA claims, trust models, editing chains, watermarking, fingerprints, synthetic-content detection, privacy, and verification limits.

    Read governed report
    Focused laboratory

    Inert Media Provenance Inspector

    Inspect a bounded PNG or JPEG for digests, metadata, textual provenance markers, JUMBF/C2PA-like structures, and structural claims without performing cryptographic trust validation.

    Open bounded laboratory