{"object":"provenance_sources","engine":"c2pa-rs (contentauth) via c2pa-python","engine_available":true,"engine_version":"0.37.7","pack_version":"2026.07.24","updated":"2026-07-24","trust_sources":[{"id":"c2pa-production","tier":"production","active":true,"artifacts":["C2PA-TRUST-LIST.pem","C2PA-TSA-TRUST-LIST.pem"],"description":"Official C2PA conformance trust list (signing anchors + timestamp authority anchors).","provenance":"raw.githubusercontent.com/c2pa-org/conformance-public/main/trust-list/","snapshot":"2026-07-24"},{"id":"c2pa-interim-legacy","tier":"interim-legacy","active":true,"artifacts":["ITL-anchors.pem","ITL-allowed.sha256.txt","ITL-store.cfg"],"description":"Interim Trust List (frozen 2026-01-01) — end-entity allow-list + EKU config for Content Credentials signed before 2026.","provenance":"contentcredentials.org/trust/","snapshot":"2026-07-24"}],"trust_source_order":["production","interim-legacy"],"supported_formats":["application/c2pa","application/mp4","application/pdf","application/svg+xml","application/x-c2pa-manifest-store","application/x-troff-msvideo","application/xhtml+xml","application/xml","arw","audio/flac","audio/mp3","audio/mp4","audio/mpeg","audio/mpeg3","audio/vnd.wave","audio/wav","audio/wave","audio/x-mp3","audio/x-wav","avi","avif","c2pa","dng","flac","gif","heic","heif","image/avif","image/dng","image/gif","image/heic","image/heif","image/jpeg","image/jxl","image/png","image/svg+xml","image/tiff","image/webp","image/x-adobe-dng","image/x-nikon-nef","image/x-sony-arw","jpeg","jpg","jxl","m4a","m4v","mov","mp3","mp4","nef","pdf","png","svg","text/xml","tif","tiff","video/avi","video/mp4","video/msvideo","video/quicktime","video/x-m4v","video/x-msvideo","wav","webp","xhtml","xml"],"verdicts":{"authentic-provenance":"signed C2PA manifest whose signer chains to a trusted anchor and whose asset hash-binding is intact","untrusted-signer":"structurally valid signed manifest, but the signing certificate does not chain to any bundled trust anchor (self-signed / unknown issuer)","tampered":"a C2PA manifest is present but validation FAILED — the asset was modified after signing (hash mismatch) or the claim signature is broken","unsigned":"no C2PA / Content-Credentials manifest is embedded in the media","unverifiable-remote":"the media carries only a REMOTE / cloud manifest pointer, which our offline policy does not fetch (remote_manifest_fetch is off); there is no embedded credential to verify locally"},"ai_source_types":{"trainedAlgorithmicMedia":"ai_generated","compositeWithTrainedAlgorithmicMedia":"ai_composite","algorithmicMedia":"algorithmic","digitalCapture":"camera_capture","digitalArt":"digital_art","minorHumanEdits":"human_edited","compositeCapture":"composite_capture"},"limits":{"max_media_bytes":33554432,"remote_manifest_fetch":false,"soft_binding_fetch":false,"ml_detection":false},"honest_limits":["no remote-manifest fetch (remote_manifest_fetch=off) — only embedded JUMBF manifests","no soft-binding / cloud-manifest resolution (no network, SSRF-free by construction)","no ML / no deepfake or AI-pixel detection — AI flags are read from the SIGNED claim only","whole-asset in-memory verify: input capped at 32 MiB"],"disclaimer":"C2PA cryptographic-provenance verdict, not a deepfake / AI-pixel detector; a pass verifies a signed credential's integrity and trust chain, not the real-world truth of the content.","note":"Freshness = a data re-snapshot of the bundled trust list (no live daemon). The paid /provenance/verify and /provenance/inspect routes verify against this snapshot."}