DeepFake Check
Back to Blog
DeepCheckAI Team 5 min read

Content Credentials and tamper evidence: a verification guide

Start with the exact file you received

A Content Credential integrity result applies to a particular asset and its associated C2PA Manifest. Before reading a badge or status, save the file you actually received. Record where it came from and when you obtained it. If a platform offers several download sizes, keep the version you checked rather than assuming every rendition carries the same credential. This preservation step is a workflow proposed by this guide; it is not a requirement quoted from C2PA.

C2PA defines provenance as facts about the history of a digital asset. A Content Credential, also called a C2PA Manifest, is cryptographically bound to an asset and contains one or more assertions. Assertions may describe origin, modifications, tools, or AI use. The manifest is digitally signed, and a content hash can represent the asset at the time the credential was created.

Those parts give a verifier specific technical questions to answer: is the provenance information well formed, is it free from detectable tampering, is the signature valid or associated with a known trust list, and is the manifest associated with the asset being checked? Keep these questions separate from whether the scene, caption, or event is true.

Read a passed check narrowly

C2PA says a verifier can confirm that an asset has not been modified since its Content Credential was created and that the provenance information remains unmodified and authentic. It also explains that changing part of the credential invalidates one or more hashes and signals tampering. A passed integrity check therefore supports a narrow result about the checked file, manifest, and recorded provenance.

Copy the application’s wording rather than shortening everything to “authentic.” Note which file was checked, whether the asset association passed, what the integrity status said, and what signer or trust information appeared. Then list only the assertions that were present. If an assertion records an edit, report that recorded edit without inventing the editor’s motive or the effect on the depicted event.

A valid credential does not make every assertion true in the real world. C2PA explicitly says Content Credentials do not make value judgments about whether provenance data is true. The system verifies structure, integrity, signature and asset association; factual verification still requires evidence outside the manifest.

Treat failure as a reason to inspect, not an accusation

A failed hash or integrity result can indicate that the credential, the linked asset, or their relationship no longer matches what the verifier expects. Record the exact status and preserve the file before trying another copy. The C2PA Explainer supports the general conclusion that altered credential data invalidates hashes and signals tampering, but it does not establish who made a change, why it happened, or whether the depicted event is false.

Check mundane possibilities before assigning intent. Confirm that the application examined the saved file you intended, not a preview or screenshot. Compare the filename, size, source page and download route with the earlier copy. If you obtain another version from the publisher, keep both and label them rather than replacing one. These comparison steps are editorial recommendations, not C2PA-mandated procedures.

Absence also needs careful wording. C2PA adoption is optional, so a file without a discoverable Content Credential is not automatically fabricated or untrustworthy. Write “no credential was found with this file and application.” Do not turn that observation into a verdict about the media.

Keep provenance, content analysis, and fact-checking separate

Use three records. The first contains the credential result: asset association, integrity, signature or trust information, and assertions. The second contains file-analysis observations. A saved image, video, audio file or text can be checked with DeepFakeCheck for a probabilistic risk signal, but that result does not validate a C2PA signature or establish the history recorded in a manifest.

Automated analysis can produce false positives and false negatives. A false positive may flag authentic material; a false negative may miss synthetic or manipulated material. Preserve the analyzed copy and attach the result to that copy. A high-risk signal calls for more review, while a low-risk signal does not authenticate the file.

The third record addresses the real-world claim. Open the original publication page, identify the account or organization presenting the media, write down the claimed date and context, and look for independent evidence about the event. A clean credential result and a supported event claim can coexist, but one does not substitute for the other.

Leave the next reviewer a reproducible record

Finish with a compact log: the hash or identifier of the saved file if your tools provide one, the credential application and its exact result, the assertions you relied on, the source page, and the outside evidence still missing. Keep unknowns as unknowns.

The next reviewer should be able to reopen the preserved file, repeat the credential check, compare the displayed assertions, and continue the event verification without relying on your memory or a screenshot of a badge.

Sources

  • C2PA, “C2PA Explainer”: https://spec.c2pa.org/specifications/specifications/2.2/explainer/Explainer.html

Suspect an image might be AI-generated?

Use our advanced deepfake detection tool to analyze images with high precision.

Analyze Image Now