Skip to main content
Encypher Logo

Content provenance

What is content provenance?

Content provenance records a signed origin claim, supplied identity or authorship metadata, integrity, and modification history. The record travels with supported files, and Encypher text markers can travel with copied passages when the marker survives.The C2PA open standard defines document-level provenance manifests. Encypher authored the C2PA standard for unstructured text, and Encypher's marker and resolver layer provides sub-document attribution for articles, social posts, and other unstructured text.

89 / 83

MIME types: sign / verify

400+

C2PA member organizations

Article 50

August 2, 2026 for new systems, December 2, 2026 for systems already on the market

Why now

Why Content Provenance Matters Now

Three forces converged in 2024 and 2025 to make content provenance a practical necessity.

EU AI Act application dates

Article 50 obligations apply August 2, 2026 for new systems, December 2, 2026 for systems already on the market. C2PA manifests and Encypher tools can support machine-readable marking, but legal duties, exceptions, visible disclosure, deployer obligations, and organizational review remain separate. Confirm each deployment with counsel.

Synthetic Media Explosion

AI-generated images, audio deepfakes, and synthetic text appear across news, social media, and enterprise content pipelines. Without provenance, teams often fall back to statistical guessing, which carries false positives. Cryptographic verification checks signed records deterministically instead of guessing.

Publisher Rights Erosion

AI training and RAG systems use publisher content at scale. Signed source records, supplied rights terms, and verification events give counsel technical material for licensing review; they do not establish ownership, authorization, infringement, notice, willfulness, damages, or compliance.

The C2PA standard - backed by Adobe, Microsoft, Google, BBC, and OpenAI, with over 400 member organizations - provides the open infrastructure for content provenance across media types. The standard published its 2.3 specification on January 8, 2026, including the standard for unstructured text, which Encypher authored.

How it works

How Content Provenance Works

Content provenance works through three steps: signing at creation, embedding in the content, and verification by anyone.

  1. 1

    Cryptographic Signing at Creation

    When content is created or published, the Encypher API signs it using an organization signing credential. The signature covers the content hash - a fixed-length fingerprint of the content - along with supplied metadata about the signer, creation time, and any supplied rights terms. If covered content is later altered, the hash no longer matches the signature and verification fails.

  2. 2

    Manifest and Marker Embedding

    For supported file formats, the C2PA manifest is embedded in the file's container using standardized manifest structures. For text, Encypher uses proprietary invisible markers that can persist through copy-paste, email, and many distribution pathways. The C2PA data includes the signed claim, the certificate chain, and any ingredient references; Encypher markers resolve sub-document text attribution through the matching record.

  3. 3

    Free Verification by Anyone

    Anyone can verify document-level C2PA provenance using compatible open-source C2PA libraries or the Encypher verification tool. Verification extracts the manifest, checks the cryptographic signature against the content hash, validates the certificate chain, and returns the provenance record. No account required. Encypher sub-document text attribution uses the marker and resolver layer when a matching record exists.

Coverage

Live Content Provenance Format Coverage

The Encypher API currently reports 93 accepted MIME types: 89 for signing and 83 for verification. They are grouped under 77 canonical formats across 6 media categories. This list comes from the public capability matrix and refreshes hourly.

Video

10 sign / 10 verify MIME types

Additional media coverage: Encypher supports provenance embedding for MP4, MOV, AVI, MKV/Matroska, and WebM. The live matrix reports C2PA signing and verification separately.

Audio and video provenance guide

Documents

32 sign / 29 verify MIME types

Microsoft Office coverage: Encypher supports most Microsoft Office document formats, including DOCX, XLSX, and PPTX, plus EPUB, ODT, and OXPS/XPS.

  • application/pdfsign + verify
  • application/epub+zipsign + verify
  • application/vnd.openxmlformats-officedocument.wordprocessingml.documentsign + verify
  • application/vnd.openxmlformats-officedocument.spreadsheetml.sheetsign + verify
  • application/vnd.openxmlformats-officedocument.presentationml.presentationsign + verify
  • application/vnd.oasis.opendocument.textsign + verify
  • application/oxpssign + verify
  • application/vnd.ms-xpsdocumentAlias for: application/oxpssign + verify
  • application/x-zip-basedsign only
  • application/zipAlias for: application/x-zip-basedsign only
  • applications/x-zip-basedAlias for: application/x-zip-basedsign only
  • application/vnd.ms-excel.sheet.binary.macroenabled.12sign + verify
  • application/vnd.ms-excel.sheet.macroenabled.12sign + verify
  • application/vnd.ms-excel.template.macroenabled.12sign + verify
  • application/vnd.ms-powerpoint.presentation.macroenabled.12sign + verify
  • application/vnd.ms-powerpoint.slideshow.macroenabled.12sign + verify
  • application/vnd.ms-powerpoint.template.macroenabled.12sign + verify
  • application/vnd.ms-visio.drawingsign + verify
  • application/vnd.ms-visio.drawing.macroenabled.12sign + verify
  • application/vnd.ms-visio.stencilsign + verify
  • application/vnd.ms-visio.stencil.macroenabled.12sign + verify
  • application/vnd.ms-visio.templatesign + verify
  • application/vnd.ms-visio.template.macroenabled.12sign + verify
  • application/vnd.ms-word.document.macroenabled.12sign + verify
  • application/vnd.ms-word.template.macroenabled.12sign + verify
  • application/vnd.oasis.opendocument.graphicssign + verify
  • application/vnd.oasis.opendocument.presentationsign + verify
  • application/vnd.oasis.opendocument.spreadsheetsign + verify
  • application/vnd.openxmlformats-officedocument.presentationml.slideshowsign + verify
  • application/vnd.openxmlformats-officedocument.presentationml.templatesign + verify
  • application/vnd.openxmlformats-officedocument.spreadsheetml.templatesign + verify
  • application/vnd.openxmlformats-officedocument.wordprocessingml.templatesign + verify
Text and document provenance guide

Text

14 sign / 13 verify MIME types

Text provenance: Encypher supports provenance embeddings down to a single text character through highly efficient text watermarking.

  • text/plainsign + verify
  • text/csvsign + verify
  • text/tab-separated-valuessign + verify
  • text/htmlsign + verify
  • text/markdownsign + verify
  • text/xmlsign + verify
  • text/csssign + verify
  • application/xmlsign + verify
  • application/jsonsign + verify
  • application/yamlsign + verify
  • application/tomlsign + verify
  • application/javascriptsign + verify
  • application/xhtml+xmlsign + verify
  • text/x-pythonsign only
Text provenance guide

Format guides not listed above

These guides describe format-specific provenance. Check the live capability matrix for current signing and verification support.

The Encypher API handles format detection automatically for supported inputs. View the live API capability matrix.

The standard

The C2PA Open Standard

The Coalition for Content Provenance and Authenticity (C2PA) is the standards body that defines how content provenance manifests are structured, embedded, and verified. With over 400 member organizations - including Adobe, Microsoft, Google, BBC, OpenAI, Qualcomm, and Intel - C2PA is the dominant open standard for digital content provenance.

C2PA 2.3, published January 8, 2026, introduced the text-provenance framework for unstructured text. Encypher authored this standard. Erik Svilich co-chairs the C2PA Text Provenance Task Force.

C2PA operates at the document level: a C2PA manifest authenticates a document as a whole. Encypher's marker and resolver layer provides sub-document attribution at the sentence or paragraph level - a capability not defined as a sentence-level C2PA manifest claim.

Provenance vs detection

Content Provenance vs. Content Detection

Content detection tools - AI detectors, deepfake detectors, and statistical watermark readers like SynthID - attempt to identify content by analyzing statistical patterns. Content provenance verifies signed records and integrity through cryptographic checks. The distinction matters in practice.

PropertyContent ProvenanceContent Detection
MethodCryptographic signature or resolver-backed markerStatistical pattern analysis
AccuracyDeterministic for the signed record being checkedVariable - probabilistic
False positivesNo probabilistic score; the signed record validates or failsSignificant - human text flagged as AI
False negativesUnsigned, stripped, or out-of-scope content cannot be authenticatedFrequent after paraphrasing or editing
Tamper evidenceCovered changes break signature validationNo - content can be edited to evade
Legal standingTechnical record for counsel or audit reviewDetection tools produce probabilistic scores that are routinely contested
Works without original?File-level C2PA can; sub-document markers need the resolver recordDepends on model training data

Architecture

Content Provenance vs. Blockchain

Blockchain provenance

Records content hashes on a distributed ledger. The proof is stored externally, on the chain, so it is lost when content is separated from the chain reference (copy-paste, re-posting, B2B distribution). It adds latency (block confirmation), cost (transaction fees), and governance complexity (which chain, which standard).

C2PA (embedded provenance)

Manifests are embedded in supported file containers, so document-level provenance can travel with the content wherever it goes. C2PA file verification can work offline, with no ledger lookup; Encypher sub-document text attribution remains a separate marker and resolver layer.

Implementation

Implementing Content Provenance

Three integration paths cover the full range of publisher and enterprise use cases.

API Integration

REST API with SDKs in Python, TypeScript, Go, and Rust. Sign a document in a single POST request. Batch endpoints for bulk archive signing. Low-latency verification.

API documentation

WordPress Plugin

One-click activation. Automatic signing on publish. No engineering required. Compatible with WooCommerce, Yoast, and Elementor.

WordPress plugin

Chrome Extension

Verify content provenance on any web page. Instant visual indicators for signed content. Available in the Chrome Web Store.

Chrome extension

Go deeper

Content Provenance by Audience and Use Case

Keep reading

Related Topics

FAQ

Frequently Asked Questions

What is content provenance?

Content provenance is a cryptographic record of a signed origin claim, supplied authorship metadata, integrity, and history. For files, C2PA manifests travel in the file when the format supports embedding. For text, Encypher markers can travel with copied passages and resolve to an Encypher record. Anyone can verify document-level C2PA manifests with compatible tools; Encypher sub-document attribution uses the marker and resolver layer.

How is content provenance different from metadata?

Traditional metadata - like EXIF data in photos or ID3 tags in audio - is stored separately from the content and can be stripped or altered without detection. Content provenance uses cryptographic signatures so any covered content change is visible to verification. If the manifest is removed or the content is edited, verification can no longer authenticate that signed state.

What media types support content provenance?

Encypher publishes its current sign and verification coverage through the live API capability matrix. The matrix lists each canonical MIME type, accepted aliases, media category, sign support, verification support, applicable signing specification versions, and formal conformance status.

Who can verify content provenance?

Document-level C2PA verification does not require an Encypher account. File-level manifests can be checked with compatible C2PA tools; Encypher's free verifier also resolves Encypher text markers when a matching record exists.

Does content provenance work after copy-paste?

For text, it can. Encypher embeds provenance markers using proprietary encoding designed to survive copy-paste across browsers, email clients, and text editors. Sub-document attribution depends on marker survival and the resolver record. For files, C2PA manifests are embedded in the file container where the format supports it. Compression and format conversion can sometimes strip manifests from images - this is an active area of development in the C2PA community.

What does the EU AI Act require for content provenance?

EU AI Act Article 50 obligations apply August 2, 2026 for new systems, December 2, 2026 for systems already on the market. C2PA manifests and Encypher tools can support machine-readable marking, but they do not by themselves satisfy every duty, exception, visible disclosure, deployer obligation, or organizational review. Confirm each deployment with counsel.

How does content provenance help publishers with AI licensing?

A signed record can document publisher-supplied rights terms, verification events, and review history. That record can give counsel technical material for licensing discussions. It does not prove ownership, authorization, infringement, notice, willfulness, damages, or compliance; legal outcomes depend on the facts and counsel.

Is content provenance the same as watermarking?

Cryptographic watermarking and content provenance both create verifiable signals about content origin and integrity, but they are implemented differently. Cryptographic watermarking embeds proof material directly into the content using structural techniques. C2PA manifests are embedded or referenced through standardized manifest containers. Both approaches are deterministic within their stated verification scope: verification either validates the signed record or reports why it cannot.

What happens if someone removes the content provenance record?

If a signed original exists, an unverifiable copy can be compared against it; absence of a manifest means the copy cannot be authenticated, not that tampering is proven. For text embedded using Encypher's proprietary provenance markers, removing markers prevents sub-document resolution for that copy and breaks verification against the original marked source.

How do I add content provenance to my content?

Three main paths: the Encypher API (REST, works with any language), the WordPress plugin (one-click activation), or the Python/TypeScript/Go/Rust SDKs for batch processing existing archives. The free publisher signing tier covers normal publishing use; bulk archive backfill is a paid add-on. Enterprise tiers support millions of documents with custom workflows.

Start Protecting Your Content

Encypher Mark signs, embeds, and verifies provenance across supported text, image, audio, video, document, and font formats.

Explore Encypher Mark