00 · OS INTEGRITY · BEDROCK
The device itself must still be trustworthy.
The app installs and runs only on non-jailbroken (iOS) and non-rooted (Android) devices. If the OS sandbox is compromised, the app refuses to launch in a signing role.
Every layer above this depends on the OS still enforcing its own protections. No floor, no fortress.
01 · APP VERIFIED
The app verifies itself before it signs anything.
At runtime, the app re-checks itself against the original App Store / Play Store build. A modified, sideloaded, or tampered app refuses to sign.
If the signing environment can’t be trusted, nothing downstream of it can be either.
02 · FINGERPRINTED
A cryptographic signature, at the moment of capture.
Every photo is signed at the shutter, not after the fact — bound to the exact frame the sensor saw. Pass or fail. No interpretation required.
AI-generated content cannot reproduce a signature it was never present for.
03 · C2PA SIGNED
Wrapped in the open standard.
The signature is packaged in a C2PA-conformant manifest — the open provenance format backed by Adobe, the BBC, Microsoft, and the major camera makers.
One reader works for every certified photo. No proprietary verifier required.
04 · INVISIBLE WATERMARK
Survives recropping. Survives recapture.
Cropping, format conversion, re-encoding, screen-recapture, stylized filters — verification still resolves to the original capture.
An invisible watermark, imprinted at capture, persists where stripped C2PA metadata alone cannot.
05 · PERMANENT PROOF
Anchored to an independent witness record.
Every photo’s hash is co-signed by an independent witness network, producing a tamper-evident record of when this image first existed. Copies are necessarily after the original. Forged dates fail verification.
Distributed across independent witnesses — designed to outlive any single operator, including us.