// C2PA Content Credentials

A label nobody can check
is just an assertion.

You have decided when your organisation discloses the use of AI. The harder question comes next: why should anyone believe the disclosure? Trusteddit issues the certificates that turn an editorial statement into a cryptographic record your audience, your licensees and your regulator can check for themselves.

// the real problem

You can promise you publish no AI images. Nobody can verify it.

A trusted-AI policy is a statement about intent and internal discipline. It is the right thing to have and it is worth having, but from the outside it cannot be checked. Anyone who wants to believe you has to believe you.

Over time that is the weakest point in a house whose actual product is trust. Content Credentials move the burden of proof: instead of restating the promise, you hand over a manifest anyone downstream can verify in seconds.

// authorship

One certificate per contributor. Not one per masthead.

A house-wide signature only proves your organisation distributed the asset. A contributor certificate proves who made the work, and when. If a single image is challenged, you show that one chain rather than vouching for the whole newsroom.

In hybrid workflows authorship is the central question, not a footnote. Where a person and a system work on the same asset, attribution decides who is accountable, who is credited and who is paid. A certificate per person answers that technically, traceably, and without renegotiating it case by case.

For photographers, picture editors, designers, illustrators and video journalists it also builds a provable body of work that travels with them. That is an argument to make to your freelancers, not only to your audience.

// the gap

Your policy binds your staff. It does not bind your suppliers.

A picture desk takes material every day from freelance photographers and from partner agencies at home and abroad. What holds internally does not automatically hold there. That interface, not the editorial meeting, is where a promise either survives or fails.

Signing and checking at ingest separates evidenced from unevidenced material before it reaches the archive, the licensing catalogue and onward distribution. And when partners start sending you credentialed images, you have to validate and carry those credentials forward, or the chain breaks inside your own house.

// glass-to-glass

From the lens to the screen, documented end to end.

Four steps that together evidence the path from capture, through the photo desk, to what your audience sees.

A four-station loop diagram: a camera captures, Trusteddit signs, the credentialed file is republished anywhere carrying a green Content Credentials badge, and a viewer at a screen running Verifieddit is returned to the creator, with the signed image and its green badge at the centre.
The loop only closes at verification. This diagram carries Content Credentials itself: download it and check it with the extension.

01

Issue

Trusteddit issues the C2PA producer certificate, one for the organisation and one for each contributor.

02

Sign

Signed at the source with a trusted RFC 3161 timestamp, a single POST from inside your existing workflow. DAM, MAM and editorial system stay where they are.

03

Publish

The file goes to the archive, the licensing catalogue, partners and the open web. The proof travels inside it, including through republication by third parties.

04

Verify

Chrome extension, Firefox add-on, web validator and SDK. One click opens the whole manifest, not just a verdict.

// verification

Signatures with no verifier are dead weight.

Issuing is only half of it. Verifieddit ships a free extension for Chrome and a free add-on for Firefox, plus the web validator and the SDK. One click shows the full manifest: who signed, which certificate authority stands behind them, what the timestamp says, which edits are recorded, and whether an AI origin was declared. It reads content from any other provider too.

// regulation

EU AI Act Article 50 applies from August 2026.

The transparency obligations reach organisations that deploy AI systems or distribute their output. Content Credentials are not a substitute for legal advice. They are the technical means to record marking and provenance in a machine-readable, checkable form rather than asserting it in a self-declaration.

Trusteddit runs the certificate authority, publishes its Certificate Policy and CPS to RFC 3647, and discloses revocation and root fingerprints. See the trust posture.

// who this is for

Anywhere a named person makes original work.

  • News and picture agencies
  • Publishing houses and newsrooms
  • Advertising and communications agencies
  • Graphic design, animation and post studios
  • Architecture practices
  • Artist organisations and collecting societies
  • Press clubs and foreign press associations
  • Multimedia portals and creator networks

The pattern is the same in all of them. The organisation holds the relationship, the individual holds the credit, and the certificate keeps the two attached once the work leaves your systems.

in production

The Phenom App logo

The Phenom App

Visit thephenom.app

SanMarcSoft's Trusteddit platform is the exclusive technology partner to The Phenom App, where field footage is captured and the authenticity of the recording is the entire question.

Every file is signed at the source and timestamped, so the receiving side can check the chain of custody instead of arguing about it.

the guarantee

Your first signed asset shows as valid in the public Verifieddit extension within 30 days, or we keep working with your team, free, until it does.

We can offer that because the verifier is public. You do not have to take our word for whether a signature holds. You can look.

Twenty minutes, and your engineers get a sandbox key.

We price on contributor certificates, not seats. For organisations at agency scale we size it on the call, including a private CA or dedicated timestamp authority where the throughput justifies it.

Your engineer wants a sandbox key, not a sales call. Send them there first; the meeting goes faster.