DeepFake Check
Back to Blog
DeepCheckAI Team 4 min read

C2PA Trusted Time-Stamps: How to Separate Signing Time from Capture Time

Start with one precise question

Keep the exact file and the complete C2PA validation output together. Record where the file came from, when you obtained it, and which validator and version produced the result. The first question is narrow: does the credential contain a time-stamp that the validator can check, and what time does that check describe? Do not begin by asking when the camera captured the scene or when the event happened. Those are separate questions.

C2PA’s validation guidance treats the time-stamp as evidence attached to a signature or credential. A successful check can support the statement that the relevant signed data has a time value that passed the validator’s checks. It does not turn that value into a capture-time field, and it does not establish the date or time of the depicted event. Keep those three statements separate in your notes.

Read the validator result, not a badge

Open the full result and copy the fields the tool actually exposes: the assertion or credential being checked, the time value, the validation status, and any diagnostic message. If a field is absent, write “not displayed.” Do not fill it from a filename, a social-media caption, or a different copy of the file. Preserve the exact source URL and file identifier so another reviewer can repeat the check.

A passing status is a technical observation about this credential and this file. It is not a claim that every other assertion is correct. A failed or unavailable time check is also limited: it says that the validator could not establish the required result for the supplied evidence. It does not identify who changed the file, when a change occurred, or whether the scene was staged. Save the failure code or message instead of converting it into a verdict about the media.

Keep the three clocks apart

Use separate fields in your review record for signing or credential time, media capture time, and event time. The first may come from the C2PA validation result. Capture time might be available in other metadata, but this check does not prove that metadata is accurate. Event time comes from independent reporting, records, or witnesses. If the times disagree, report the disagreement and the evidence behind each field; do not silently choose the most convenient one.

When the question is whether a file was altered, preserve the original download and any transformed copies as separate review targets. If you also use DeepFakeCheck for a probabilistic signal, link the result to the exact copy analyzed and keep it outside the C2PA record. Automated analysis can produce false positives and false negatives. A high-risk signal calls for more checking; a low-risk signal does not authenticate the credential or prove the event.

A compact review checklist

  • 1. Assign an identifier to the exact file and save the complete validator output.
  • 2. Record the time value and status exactly as displayed.
  • 3. Label it as signing or credential time, not capture or event time.
  • 4. Preserve missing fields and diagnostics instead of guessing.
  • 5. Check capture and event claims through independent evidence.
  • 6. Write the final decision with the evidence that supports each clock.

Add an audit note after the checklist: name the inspected copy, state whether the validator exposed a time value, and list claims that still need outside evidence. If the file is downloaded again or transformed, open a separate record so the evidence trail remains clear. The useful conclusion is often modest: this credential passed, failed, or did not expose a checkable time value. That is enough to guide the next verification step. Keep the status, timestamp value, and file identifier together when handing the case to another reviewer. This preserves the boundary between a technical check and an independent claim about what happened without making a time-stamp carry a claim it cannot support.

Sources

  • C2PA, “C2PA Technical Specification — Validate the Time Stamp”: https://spec.c2pa.org/specifications/specifications/2.2/specs/C2PA_Specification.html#_validate_the_time_stamp

Need to check a suspicious file?

Open the matching detector and interpret the result alongside the source and context.

Open Detector