Digital Content Provenance & Authenticity
Check provenance first, then talk about truth
Upload an image or video and see whether a verifiable provenance credential exists. Missing evidence is not “not AI”. A valid credential is not proof the depicted event happened.
Images JPG / PNG / WebP / TIFF ≤ 60MB · Videos MP4 / MOV / MKV / WebM ≤ 500MB · up to 20 files. Deleted after processing.
Choose filesThree things we check
How to read a result
Read the one-line verdict first, then open details if you need them. Technical fields are not a true/false score.
-
Read the verdict
For example “Insufficient evidence” or “Provenance verified”, plus a plain-language sentence.
-
Scan four facts
Credential, declaration, resolution, and signer.
-
Open details only if needed
Technical fields stay collapsed until you click.
FAQ
If there is no C2PA, is the file not AI?
No. Screenshots and social re-encodes often strip credentials. Missing evidence is not a negative proof.
Does a valid C2PA mean the photo is true?
No. C2PA verifies signed provenance claims, not factual truth of the depicted event.
Do you store uploads?
Verify processes files temporarily and deletes them. Originals are not kept as long-term assets by default.
Can you tell GPT-Image from Doubao?
Yes when C2PA/XMP/AIGC identifiers remain. If metadata was stripped, we report unknown instead of guessing.
Is the fake-4K checker still here?
Yes. It is now the resolution-integrity module, shown separately from provenance.
Go deeper
What Roma Verify checks
- C2PA Content Credentials: presence, signature, and asset binding.
- Digital signatures and certificates, separately from official Trust List membership.
- AI provenance declarations such as trainedAlgorithmicMedia.
- China AIGC labels as compatibility detection, not a compliance certificate.
- EXIF / XMP / IPTC and PNG textual chunks.
- Resolution integrity: spectral cutoffs and interpolation periodicity.
How it works
- Upload an image or video (videos are sampled into frames).
- Read C2PA, metadata, AIGC fields, and resolution evidence in parallel.
- Return a layered, explainable report — not a single true/false score.
C2PA verification
We separate signature validity, asset binding, certificate validity, and C2PA Trusted. Self-signed or unlisted signers can be cryptographically valid without being officially trusted. See the Trust List guide.
AI content provenance
Roma Verify prioritises signed and declared evidence over opaque AI-probability classifiers. Read provenance vs detector.
For developers
Verify API returns the same evidence JSON. Sign API uses server-side templates; production private keys must not live in the web process.
Privacy and security
Verification processes files temporarily and deletes them. Remote-manifest fetches block private networks. See Methodology.