DeepFake Check
Back to Blog
DeepCheckAI Team 5 min read

C2PA Assertion Redaction: How to Review Removed Provenance Fields

Fix the file and review question first

Save the exact media file under review. Record where it came from, the filename, the time obtained, and a checksum if your workflow already uses one. Open that same copy in a compatible C2PA validator and note the validator name and version. This evidence log is an editorial method proposed here, not a procedure required by C2PA.

Write the question before interpreting the result. You may need to know whether a manifest records removal of a metadata assertion, whether two copies expose the same record, or whether a caption about an event is accurate. Those are different questions. A redaction record can help with the first two; it does not settle the third.

Preserve the complete validator output. A screenshot may help another reviewer find the result, but it can hide surrounding messages or the identity of the inspected copy. Keep the file and copied output together so a later review does not depend on a cropped interface.

Read what C2PA calls redaction

C2PA 2.2 says an assertion present in an asset-embedded manifest may be removed from that asset's manifest when the asset is used as an ingredient. The specification calls this process redaction. It describes two forms: removing the whole assertion from the assertion store, or retaining its labelled container while replacing its JUMBF Content boxes with the specified C2PA Redaction UUID box containing zero-valued data.

The claim must also gain a URI reference to the removed assertion in its redacted_assertions field. The specification strongly recommends adding a c2pa.redacted action assertion with a redacted field. Copy the URI, assertion label, action entry if present, and every status the validator shows. Do not reduce those fields to a general label such as history cleaned.

The assertion label matters because its URI reference identifies the type of information removed, such as a thumbnail or metadata. That gives reviewers a concrete item to assess. It does not reveal the removed value. Record the type as shown and leave the former contents unknown unless another retained source establishes them.

If an ingredient assertion referring to a C2PA Manifest is redacted, the associated manifest must be removed from the Manifest Store when no other references to it remain. A missing associated manifest can therefore be consistent with recorded redaction. It should not be described as proof of redaction unless the corresponding record is present.

Check the limits and the surrounding record

Some assertions cannot be redacted under this specification. Claim generators must not redact c2pa.actions or c2pa.actions.v2, because those assertions carry essential asset-history information. They must not redact the listed hard-binding assertions either, because those bindings are needed to determine asset integrity. If a tool reports one of those labels as redacted, preserve the exact output and treat the conflict as an unresolved validation issue rather than silently accepting it.

When redaction does not require a change to the digital content, C2PA says an update manifest must document it and state that the content did not change. Review the update manifest separately from the original claim. Record which manifest contains the redaction reference, which file was inspected, and whether the validator resolved the referenced assertion.

The specification also warns about older ingredient assertions. Redaction in a manifest referenced through deprecated c2pa.ingredient or c2pa.ingredient.v2 causes validation of that assertion to fail; only c2pa.ingredient.v3 supports the cited claim-signature-hash validation method. Preserve the assertion version and failure message. Do not turn this narrow compatibility result into a verdict about the scene shown in the media.

Make a compact comparison table for multiple copies: file identifier, manifest identifier, assertion label, redacted_assertions reference, redaction action, update manifest, validator result, and open question. A blank field means not displayed or not found in that run. It does not mean the value never existed.

Separate recorded removal from an unexplained gap

A recorded redaction leaves inspectable traces, including a claim reference to the redacted assertion and, when supplied, the recommended action record. An unexplained gap lacks enough visible evidence to make that link. Report the two states differently. For example, write that the inspected manifest records redaction of a named assertion, or that the expected information was not displayed and no matching redaction record was found.

Neither sentence establishes why the information was removed, who made the editorial decision, or what the removed value said. Those questions require another source. Check the publisher's original file or page, earlier documented copies, and any retained workflow records. Keep each observation tied to its file instead of combining results from different downloads.

Real-world claims still need independent checking. A well-formed redaction record does not prove that a depicted event happened, that a caption is accurate, or that the party making a claim is honest. Conversely, an absent or failed record does not prove the media is synthetic. Provenance review describes the available record; event verification examines the claim about the world.

Keep detection in a separate evidence column

A saved image, video, audio file, or text can be submitted to DeepFakeCheck for a probabilistic risk signal. DeepFakeCheck does not validate a C2PA redaction record, resolve the redacted_assertions URI, or verify a C2PA signature. Store its output apart from the validator record.

Automated analysis can produce false positives that flag authentic material and false negatives that miss synthetic or altered material. A high-risk result supports further review, while a low-risk result does not restore a removed assertion or authenticate the file. Continue the provenance and external checks regardless of the detector result.

Close the review with the inspected file, validator and version, copied redaction fields, update-manifest result, unresolved gaps, external source checks, detector output if used, and the decision taken. Another reviewer should be able to repeat the same checks without inventing the contents of a removed assertion.

Sources

  • C2PA, “C2PA Technical Specification — Redaction of Assertions”: https://spec.c2pa.org/specifications/specifications/2.2/specs/C2PA_Specification.html#_redaction_of_assertions

Need to check a suspicious file?

Open the matching detector and interpret the result alongside the source and context.

Open Detector