Content Credentials for publishing workflows
C2PA Certificates and Trust Lists, Explained
C2PA product conformance, signer certificate trust, timestamp-authority trust, and separate identity credentials answer different questions. Buyers should verify each layer rather than treating them as one C2PA certificate.
A recognized signing chain supports confidence that the manifest was signed by the corresponding key under the configured trust policy. A separately validated timestamp can provide signing-time evidence. Neither result makes signed assertions factually true.
Conformance does not certify a publisher, article, editorial process, authorship, ownership, origin, or legal compliance. The official C2PA page is the primary source for current conforming-product, signer trust-list, and TSA trust-list records.