Docs

Methodology

We validate manifests with c2pa-rs bindings, cache the Trust List, and keep the resolution algorithm as a separate Evidence Provider. Every report records verify_engine_version and c2pa_sdk_version.

What counts as valid

The Claim signature verifies and the asset binding matches. That is still not C2PA Trusted.

What counts as trusted

Only when the certificate chain reaches the currently cached official Trust List.

Limitations

Missing manifests, stripped labels, generative upscalers, and low-bitrate video all weaken conclusions. We prefer unknown to inventing a vendor.

Subpages: C2PA validation · resolution integrity

Author: Roma Verify Editorial · Reviewed: Roma Verify Engineering · Updated: 2026-09-16

Sources

Start verifying