Content provenance
What is content provenance?
Content provenance records a signed origin claim, supplied identity or authorship metadata, integrity, and modification history. The record travels with supported files, and Encypher text markers can travel with copied passages when the marker survives.The C2PA open standard defines document-level provenance manifests. Encypher authored the C2PA standard for unstructured text, and Encypher's marker and resolver layer provides sub-document attribution for articles, social posts, and other unstructured text.
89 / 83
MIME types: sign / verify
400+
C2PA member organizations
Article 50
August 2, 2026 for new systems, December 2, 2026 for systems already on the market
Why now
Why Content Provenance Matters Now
Three forces converged in 2024 and 2025 to make content provenance a practical necessity.
Synthetic Media Explosion
Publisher Rights Erosion
The C2PA standard - backed by Adobe, Microsoft, Google, BBC, and OpenAI, with over 400 member organizations - provides the open infrastructure for content provenance across media types. The standard published its 2.3 specification on January 8, 2026, including the standard for unstructured text, which Encypher authored.
How it works
How Content Provenance Works
Content provenance works through three steps: signing at creation, embedding in the content, and verification by anyone.
- 1
Cryptographic Signing at Creation
When content is created or published, the Encypher API signs it using an organization signing credential. The signature covers the content hash - a fixed-length fingerprint of the content - along with supplied metadata about the signer, creation time, and any supplied rights terms. If covered content is later altered, the hash no longer matches the signature and verification fails.
- 2
Manifest and Marker Embedding
For supported file formats, the C2PA manifest is embedded in the file's container using standardized manifest structures. For text, Encypher uses proprietary invisible markers that can persist through copy-paste, email, and many distribution pathways. The C2PA data includes the signed claim, the certificate chain, and any ingredient references; Encypher markers resolve sub-document text attribution through the matching record.
- 3
Free Verification by Anyone
Anyone can verify document-level C2PA provenance using compatible open-source C2PA libraries or the Encypher verification tool. Verification extracts the manifest, checks the cryptographic signature against the content hash, validates the certificate chain, and returns the provenance record. No account required. Encypher sub-document text attribution uses the marker and resolver layer when a matching record exists.
Coverage
Live Content Provenance Format Coverage
The Encypher API currently reports 93 accepted MIME types: 89 for signing and 83 for verification. They are grouped under 77 canonical formats across 6 media categories. This list comes from the public capability matrix and refreshes hourly.
Images
15 sign / 14 verify MIME types- image/jpegsign + verify
- image/jpgAlias for: image/jpegverify only
- image/pngsign + verify
- image/webpsign + verify
- image/tiffsign + verify
- image/avifsign + verify
- image/heicsign + verify
- image/heifsign + verify
- image/heic-sequencesign + verify
- image/heif-sequencesign + verify
- image/svg+xmlsign + verify
- image/x-adobe-dngsign + verify
- image/gifsign + verify
- image/jxlsign + verify
- image/x-tiff-basedsign only
- image/x-riff-basedsign only
Video
10 sign / 10 verify MIME typesAdditional media coverage: Encypher supports provenance embedding for MP4, MOV, AVI, MKV/Matroska, and WebM. The live matrix reports C2PA signing and verification separately.
- video/mp4sign + verify
- video/quicktimesign + verify
- video/x-msvideosign + verify
- video/aviAlias for: video/x-msvideoverify only
- video/msvideoAlias for: video/x-msvideoverify only
- video/x-m4vsign + verify
- video/matroskasign + verify
- video/x-matroskaAlias for: video/matroskasign + verify
- application/mxfsign + verify
- video/x-riff-basedsign only
- video/x-bmff-basedsign only
- application/mp4sign + verify
Audio
13 sign / 12 verify MIME types- audio/wavsign + verify
- audio/waveAlias for: audio/wavsign + verify
- audio/x-wavAlias for: audio/wavsign + verify
- audio/mpegsign + verify
- audio/mp3Alias for: audio/mpegsign + verify
- audio/mpaAlias for: audio/mpegsign + verify
- audio/mp4sign + verify
- audio/x-m4aAlias for: audio/mp4sign + verify
- audio/m4aAlias for: audio/mp4verify only
- audio/aacsign + verify
- audio/flacsign + verify
- audio/oggsign + verify
- application/oggAlias for: audio/oggsign only
- audio/x-riff-basedsign only
Documents
32 sign / 29 verify MIME typesMicrosoft Office coverage: Encypher supports most Microsoft Office document formats, including DOCX, XLSX, and PPTX, plus EPUB, ODT, and OXPS/XPS.
- application/pdfsign + verify
- application/epub+zipsign + verify
- application/vnd.openxmlformats-officedocument.wordprocessingml.documentsign + verify
- application/vnd.openxmlformats-officedocument.spreadsheetml.sheetsign + verify
- application/vnd.openxmlformats-officedocument.presentationml.presentationsign + verify
- application/vnd.oasis.opendocument.textsign + verify
- application/oxpssign + verify
- application/vnd.ms-xpsdocumentAlias for: application/oxpssign + verify
- application/x-zip-basedsign only
- application/zipAlias for: application/x-zip-basedsign only
- applications/x-zip-basedAlias for: application/x-zip-basedsign only
- application/vnd.ms-excel.sheet.binary.macroenabled.12sign + verify
- application/vnd.ms-excel.sheet.macroenabled.12sign + verify
- application/vnd.ms-excel.template.macroenabled.12sign + verify
- application/vnd.ms-powerpoint.presentation.macroenabled.12sign + verify
- application/vnd.ms-powerpoint.slideshow.macroenabled.12sign + verify
- application/vnd.ms-powerpoint.template.macroenabled.12sign + verify
- application/vnd.ms-visio.drawingsign + verify
- application/vnd.ms-visio.drawing.macroenabled.12sign + verify
- application/vnd.ms-visio.stencilsign + verify
- application/vnd.ms-visio.stencil.macroenabled.12sign + verify
- application/vnd.ms-visio.templatesign + verify
- application/vnd.ms-visio.template.macroenabled.12sign + verify
- application/vnd.ms-word.document.macroenabled.12sign + verify
- application/vnd.ms-word.template.macroenabled.12sign + verify
- application/vnd.oasis.opendocument.graphicssign + verify
- application/vnd.oasis.opendocument.presentationsign + verify
- application/vnd.oasis.opendocument.spreadsheetsign + verify
- application/vnd.openxmlformats-officedocument.presentationml.slideshowsign + verify
- application/vnd.openxmlformats-officedocument.presentationml.templatesign + verify
- application/vnd.openxmlformats-officedocument.spreadsheetml.templatesign + verify
- application/vnd.openxmlformats-officedocument.wordprocessingml.templatesign + verify
Text
14 sign / 13 verify MIME typesText provenance: Encypher supports provenance embeddings down to a single text character through highly efficient text watermarking.
- text/plainsign + verify
- text/csvsign + verify
- text/tab-separated-valuessign + verify
- text/htmlsign + verify
- text/markdownsign + verify
- text/xmlsign + verify
- text/csssign + verify
- application/xmlsign + verify
- application/jsonsign + verify
- application/yamlsign + verify
- application/tomlsign + verify
- application/javascriptsign + verify
- application/xhtml+xmlsign + verify
- text/x-pythonsign only
Format guides not listed above
These guides describe format-specific provenance. Check the live capability matrix for current signing and verification support.
The Encypher API handles format detection automatically for supported inputs. View the live API capability matrix.
The standard
The C2PA Open Standard
The Coalition for Content Provenance and Authenticity (C2PA) is the standards body that defines how content provenance manifests are structured, embedded, and verified. With over 400 member organizations - including Adobe, Microsoft, Google, BBC, OpenAI, Qualcomm, and Intel - C2PA is the dominant open standard for digital content provenance.
C2PA 2.3, published January 8, 2026, introduced the text-provenance framework for unstructured text. Encypher authored this standard. Erik Svilich co-chairs the C2PA Text Provenance Task Force.
C2PA operates at the document level: a C2PA manifest authenticates a document as a whole. Encypher's marker and resolver layer provides sub-document attribution at the sentence or paragraph level - a capability not defined as a sentence-level C2PA manifest claim.
Provenance vs detection
Content Provenance vs. Content Detection
Content detection tools - AI detectors, deepfake detectors, and statistical watermark readers like SynthID - attempt to identify content by analyzing statistical patterns. Content provenance verifies signed records and integrity through cryptographic checks. The distinction matters in practice.
| Property | Content Provenance | Content Detection |
|---|---|---|
| Method | Cryptographic signature or resolver-backed marker | Statistical pattern analysis |
| Accuracy | Deterministic for the signed record being checked | Variable - probabilistic |
| False positives | No probabilistic score; the signed record validates or fails | Significant - human text flagged as AI |
| False negatives | Unsigned, stripped, or out-of-scope content cannot be authenticated | Frequent after paraphrasing or editing |
| Tamper evidence | Covered changes break signature validation | No - content can be edited to evade |
| Legal standing | Technical record for counsel or audit review | Detection tools produce probabilistic scores that are routinely contested |
| Works without original? | File-level C2PA can; sub-document markers need the resolver record | Depends on model training data |
Architecture
Content Provenance vs. Blockchain
Blockchain provenance
Records content hashes on a distributed ledger. The proof is stored externally, on the chain, so it is lost when content is separated from the chain reference (copy-paste, re-posting, B2B distribution). It adds latency (block confirmation), cost (transaction fees), and governance complexity (which chain, which standard).
C2PA (embedded provenance)
Manifests are embedded in supported file containers, so document-level provenance can travel with the content wherever it goes. C2PA file verification can work offline, with no ledger lookup; Encypher sub-document text attribution remains a separate marker and resolver layer.
Implementation
Implementing Content Provenance
Three integration paths cover the full range of publisher and enterprise use cases.
API Integration
REST API with SDKs in Python, TypeScript, Go, and Rust. Sign a document in a single POST request. Batch endpoints for bulk archive signing. Low-latency verification.
API documentation →WordPress Plugin
One-click activation. Automatic signing on publish. No engineering required. Compatible with WooCommerce, Yoast, and Elementor.
WordPress plugin →Chrome Extension
Verify content provenance on any web page. Instant visual indicators for signed content. Available in the Chrome Web Store.
Chrome extension →Go deeper
Content Provenance by Audience and Use Case
Keep reading
Related Topics
FAQ
Frequently Asked Questions
What is content provenance?
Content provenance is a cryptographic record of a signed origin claim, supplied authorship metadata, integrity, and history. For files, C2PA manifests travel in the file when the format supports embedding. For text, Encypher markers can travel with copied passages and resolve to an Encypher record. Anyone can verify document-level C2PA manifests with compatible tools; Encypher sub-document attribution uses the marker and resolver layer.
How is content provenance different from metadata?
Traditional metadata - like EXIF data in photos or ID3 tags in audio - is stored separately from the content and can be stripped or altered without detection. Content provenance uses cryptographic signatures so any covered content change is visible to verification. If the manifest is removed or the content is edited, verification can no longer authenticate that signed state.
What media types support content provenance?
Encypher publishes its current sign and verification coverage through the live API capability matrix. The matrix lists each canonical MIME type, accepted aliases, media category, sign support, verification support, applicable signing specification versions, and formal conformance status.
Who can verify content provenance?
Document-level C2PA verification does not require an Encypher account. File-level manifests can be checked with compatible C2PA tools; Encypher's free verifier also resolves Encypher text markers when a matching record exists.
Does content provenance work after copy-paste?
For text, it can. Encypher embeds provenance markers using proprietary encoding designed to survive copy-paste across browsers, email clients, and text editors. Sub-document attribution depends on marker survival and the resolver record. For files, C2PA manifests are embedded in the file container where the format supports it. Compression and format conversion can sometimes strip manifests from images - this is an active area of development in the C2PA community.
What does the EU AI Act require for content provenance?
EU AI Act Article 50 obligations apply August 2, 2026 for new systems, December 2, 2026 for systems already on the market. C2PA manifests and Encypher tools can support machine-readable marking, but they do not by themselves satisfy every duty, exception, visible disclosure, deployer obligation, or organizational review. Confirm each deployment with counsel.
How does content provenance help publishers with AI licensing?
A signed record can document publisher-supplied rights terms, verification events, and review history. That record can give counsel technical material for licensing discussions. It does not prove ownership, authorization, infringement, notice, willfulness, damages, or compliance; legal outcomes depend on the facts and counsel.
Is content provenance the same as watermarking?
Cryptographic watermarking and content provenance both create verifiable signals about content origin and integrity, but they are implemented differently. Cryptographic watermarking embeds proof material directly into the content using structural techniques. C2PA manifests are embedded or referenced through standardized manifest containers. Both approaches are deterministic within their stated verification scope: verification either validates the signed record or reports why it cannot.
What happens if someone removes the content provenance record?
If a signed original exists, an unverifiable copy can be compared against it; absence of a manifest means the copy cannot be authenticated, not that tampering is proven. For text embedded using Encypher's proprietary provenance markers, removing markers prevents sub-document resolution for that copy and breaks verification against the original marked source.
How do I add content provenance to my content?
Three main paths: the Encypher API (REST, works with any language), the WordPress plugin (one-click activation), or the Python/TypeScript/Go/Rust SDKs for batch processing existing archives. The free publisher signing tier covers normal publishing use; bulk archive backfill is a paid add-on. Enterprise tiers support millions of documents with custom workflows.
Start Protecting Your Content
Encypher Mark signs, embeds, and verifies provenance across supported text, image, audio, video, document, and font formats.