The chain reaches a recognised C2PA root.
The chain reaches a qualified EU trust service provider.
A C2PA manifest with signature and timestamp: who, when, which model.
Generated per period and workspace, with its own sha256 and a complete audit trail.
The verification core is readable, buildable and self-hostable.
Run on EU infrastructure; keys in your own KMS under sovereign deployment.
Read data residency →