00 · OS INTEGRITY · BEDROCK
The device itself must still be trustworthy.
The app installs and runs only on non-jailbroken (iOS) and non-rooted (Android) devices. If the OS sandbox is compromised, the app refuses to launch in a signing role.
Every layer above this stands on the OS enforcing its own protections.
01 · APP VERIFIED
The app verifies itself before it signs anything.
At runtime, the app re-checks itself against the original App Store / Play Store build. A modified, sideloaded, or tampered app refuses to sign.
A trusted signing environment is what makes everything downstream trustworthy.
02 · FINGERPRINTED
A cryptographic signature, at the moment of capture.
Every photo is signed at the shutter, bound to the exact frame the sensor saw. Pass or fail: a clear answer, every time.
The signature exists only for what the sensor actually captured.
03 · C2PA SIGNED
Wrapped in the open standard.
The signature is packaged in a C2PA-conformant manifest — the open provenance format backed by Adobe, the BBC, Microsoft, and the major camera makers.
One standard C2PA reader works for every certified photo.
04 · INVISIBLE WATERMARK · PRO
A second mark, inside the pixels.
Pro adds an invisible watermark imprinted at capture: a second, harder-to-remove marker that travels in the pixels alongside the C2PA signature.
Imperceptible to viewers, embedded directly in the pixel data.
05 · PERMANENT PROOF · ENTERPRISE
Anchored to an independent witness record.
With Enterprise, every photo’s hash is co-signed by an independent witness network, producing a tamper-evident record of when this image first existed. Copies are necessarily after the original. Forged dates fail verification.
Distributed across independent witnesses — designed to outlive any single operator, including us.