C2PA is an open technical standard for recording and cryptographically verifying the provenance of digital media. It can carry signed claims about how an image, video or audio asset was created or edited. C2PA does not prove that the depicted event is factually true.
Key facts
A C2PA manifest is bound to asset hashes.
Signature validity is not Trust List inclusion.
Credentials can be stripped by screenshots and transcodes.
Content Credentials is the user-facing name.
Key fact: A valid C2PA signature proves that the signed claim is cryptographically valid for the asset; it does not by itself prove the depicted event is true.
What it means
C2PA is maintained by the Coalition for Content Provenance and Authenticity. Implementations embed a Manifest Store in JPEG/PNG/MP4 or use a remote/sidecar manifest.
How it works
A generator creates a Claim with assertions (actions, ingredients, digitalSourceType, …).
A certificate signs the Claim.
A verifier recomputes binding hashes, checks the signature, then consults a Trust List before saying Trusted.
How Roma Verify checks it
We use the c2pa-python Reader (c2pa-rs), split present / signature / binding / certificate / trust, and cache the official Trust List.
Limitations
No manifest does not imply “not AI”. A manifest does not imply news-truth. Remote manifests require SSRF controls.
Author: Roma Verify Editorial · Reviewed: Roma Verify Engineering · Updated: 2026-09-16