Free · no account · the file is read and discarded, never stored

What does this file actually claim?

We read the C2PA manifest, rebuild the certificate chain, test it against both trust anchors and run the watermark detectors. Then we tell you exactly what we found, and what we did not.

VERIFY A FILEEU trusted list last synced 3h ago.
Drop a file here
Image, audio or video · 50 MB max · processed in memory, not written to storage
Choose a fileUse a sample
OR TRY A PREPARED CASE
01EVERY VERDICT WE CAN RETURN

Twelve outcomes. None of them rounded up.

Colour never carries the meaning on its own: each verdict also names its anchor state and its machine code, so a screenshot stays readable and an API response stays unambiguous.

SIGNED_QUALIFIEDC2EU
Qualified seal

Chain reaches an EU qualified provider and a C2PA root.

SIGNED_TRUSTEDC2EU
Trusted signature

C2PA trust list reached; no qualified EU seal present.

MARKEDC2EU
Marked and signed

Manifest and watermark agree with each other.

DISCLOSEDC2EU
Disclosure present

A visible label was found alongside the manifest.

WATERMARK_ONLYC2EU
Watermark only

Mark decoded, manifest missing. No identity.

MARKED_EXTERNALC2EU
Marked elsewhere

Mark from a generator outside your workspace.

!SIGNED_UNTRUSTEDC2EU
Signed, untrusted root

Signature valid, root on no trust list.

!MODIFIEDC2EU
Modified after signing

Manifest describes an earlier state of the file.

PENDINGC2EU
Verification pending

A revocation or trust list lookup did not complete.

INVALID_SIGNATUREC2EU
Invalid signature

Signature does not match the current bytes.

UNMARKED_RISKC2EU
Unmarked, obligation likely

Policy expected a mark on this channel; none found.

NOT_FOUNDC2EU
No evidence found

No manifest, no watermark. Not a statement about origin.

02WHAT RUNS, IN ORDER
01
Read the manifest

Parse the C2PA store, list every assertion and every ingredient the file declares.

02
Rebuild the chain

Walk from the signing certificate to its root, checking validity windows and revocation.

03
Test both anchors

C2PA trust list and EU trusted list are checked separately and reported separately.

04
Run the detectors

Watermark decoders and integrity hashing, with the confidence stated as a number.

WHAT THIS TOOL CANNOT TELL YOU
Absence is not proof

NOT_FOUND means no manifest and no watermark survived. It does not mean a human made the file.

Marks can be stripped

A screenshot, a re-encode or a determined editor can remove a manifest. The watermark often survives; sometimes it does not.

Trust is about identity

A valid signature proves who signed and that nothing changed since. It does not make the content true.