Content Credentials for publishing workflows
What C2PA Proves—and What It Does Not
Successful C2PA validation can establish that the presented asset matches its cryptographic binding, that its manifest signature validates, and that supported trust and timestamp evidence validates under the verifier's configured policy.
Signed assertions show what the signer recorded. They do not independently prove real-world truth, human authorship, identity, ownership, original capture, absence of edits before signing, first publication, editorial approval, or legal compliance.
C2PA is opt-in and credentials can be stripped, so missing credentials do not prove content is false or AI-generated. Detached article sidecars require both the article and manifest data and are C2PA-based, not C2PA-certified.