Colour never carries the meaning on its own: each verdict also names its anchor state and its machine code, so a screenshot stays readable and an API response stays unambiguous.
Chain reaches an EU qualified provider and a C2PA root.
C2PA trust list reached; no qualified EU seal present.
Manifest and watermark agree with each other.
A visible label was found alongside the manifest.
Mark decoded, manifest missing. No identity.
Mark from a generator outside your workspace.
Signature valid, root on no trust list.
Manifest describes an earlier state of the file.
A revocation or trust list lookup did not complete.
Signature does not match the current bytes.
Policy expected a mark on this channel; none found.
No manifest, no watermark. Not a statement about origin.
Parse the C2PA store, list every assertion and every ingredient the file declares.
Walk from the signing certificate to its root, checking validity windows and revocation.
C2PA trust list and EU trusted list are checked separately and reported separately.
Watermark decoders and integrity hashing, with the confidence stated as a number.
NOT_FOUND means no manifest and no watermark survived. It does not mean a human made the file.
A screenshot, a re-encode or a determined editor can remove a manifest. The watermark often survives; sometimes it does not.
A valid signature proves who signed and that nothing changed since. It does not make the content true.