Support assistant
Application
Text
Output format
Signed output returned
Marking result
Valid at check time
Verification state
doc_01JAI7M4
Document ID
For AI providers
Give text, image, audio, video, PDF, DOCX, XLSX, and PPTX outputs machine-readable provenance at the application boundary. Use the same Mark integration for one product or a portfolio, then retain evidence for customer reviews and EU AI Act Article 50 output-marking duties.
1
API call after generation completes marks the output. Your model, prompts, and streaming path do not change.
8
output formats from the one integration: text, image, audio, video, PDF, DOCX, XLSX, and PPTX.
1,000
AI outputs you can mark each month before you pay anything, with 5 Article 50 compliance certificates.
Flagship workflow
Mark is available now and carries the Article 50 marking work. Meter reports which signed sources an answer used and runs as an early partner program. Trace connects a released copy back to the recipient it went to.
Workflow
Mark: sign the completed output
Call Mark after generation completes, never per streaming chunk, so the signature binds to the completed content object. Return signed content, then store the document ID, marking result, and any failure beside the application event.
Meter: report the sources behind the answer
For a completed answer, report which signed sources were retrieved, grounded, and cited, each checked against its own signature and each carrying a rights verdict for the use you name. Early partner program: the retrieval and citation events come from your pipeline.
Trace: connect a released copy to its recipient
When a signed output leaves your product under an agreement, Trace links a recovered copy back to the recipient or release event it came from.
Product roles in this workflow
Bind portable provenance and verified terms to a content object or completed output.
Record observed retrieval, citation, and other partner-supplied events for bounded usage reporting.
Connect a distributed copy to its intended recipient or event.
Illustrative application-boundary record
The record makes successful marks and failed outputs visible at the same boundary.
Support assistant
Application
Text
Output format
Signed output returned
Marking result
Valid at check time
Verification state
doc_01JAI7M4
Document ID
Report generator
Application
DOCX
Output format
Failed, state retained
Marking result
Not available
Verification state
Not issued
Document ID
Article 50 obligations apply August 2, 2026 for new systems, December 2, 2026 for systems already on the market. Mark supports provider-side output marking and detectability, but does not by itself satisfy every duty, including visible disclosure, exceptions, deployer duties, and organizational review. Confirm each deployment with counsel.
Source use
Mark records what your system produced. Meter reports what it consumed: the signed sources behind one completed answer, each checked against its own signature, each with a rights verdict for the use you name.
Three stages, observed separately
A source can be retrieved without grounding an answer, and grounded without being cited. Keeping the three apart is what makes the report useful to a publisher, a licensing team, and your own retrieval engineers.
Where each fact comes from
Per-source signature verification and its verdict, the rights terms bound to each signed source, and public verification events.
Retrieval, grounding, citation, and product-outcome events. Encypher sits outside your pipeline and cannot see them on its own.
Anything neither side reported. A gap stays a visible gap in the report instead of collapsing into an inferred usage claim.
A source either resolves to a signed record or returns a named reason: SIGNER_UNKNOWN, SIGNATURE_INVALID, or VERIFY_UNAVAILABLE. An unverified source stays visibly unverified rather than disappearing into a total. The completed answer can carry a signed ai.encypher.usage assertion holding those per-source verdicts, so the evidence travels with the output instead of living only in a dashboard.
Each signed source projects to a W3C ODRL policy bound at signing time. A deterministic engine evaluates that policy against the intended use you name and returns permit or prohibit with the rule that decided it. Same inputs, same verdict, every time: a prohibition outranks a permission and an unmatched request defaults to deny.
Encypher returns the verdict. Your retrieval layer decides what to do with it. We report; we are not in your request path and we do not act on your behalf.
Meter runs as an early partner program with no self-serve path. More detail on Encypher Meter.
Try the live capability
Provenance Chat is the public demo. Ask a question, watch the answer sign itself as generation completes, then open the per-message provenance panel to read the C2PA manifest that came back. No account, no API key.
Paste AI-generated text, add Encypher text provenance plus a document-level C2PA manifest, then verify the result in place.
How it works
Verify provenance on retrieved content and sign provenance into completed output, from the same integration.
C2PA is an industry-wide standard for documenting content origin and authenticity, not a publisher initiative to restrict AI. Its 200-plus members include OpenAI, Google DeepMind, Microsoft, Adobe, BBC, Reuters, AP, and Intel. The standard and independent verification libraries are open, so anything Encypher signs can be checked without Encypher.
Encypher helped write the unstructured-text standard introduced in C2PA 2.3 and co-chairs the Text Provenance Task Force. Python and TypeScript SDKs wrap the API, and batch endpoints handle up to 10,000 documents per request.
The verification API checks submitted text or media and returns available signer, timestamp, rights, and integrity data. Teams call it during retrieval or after inference at POST https://api.encypher.com/api/v1/verify with a bearer API key.
The signing API accepts text, images, audio, video, PDF, DOCX, XLSX, and PPTX. A successful call returns signed content with a C2PA manifest recording the supplied generation metadata, which supports Article 50 technical marking from August 2, 2026 for new systems, December 2, 2026 for systems already on the market. DOCX, XLSX, and PPTX sign under C2PA 2.4 and verify version-agnostically; none is a formal conformance-program format. Counsel should confirm each deployment.
Deeper reading: EU AI Act compliance, the C2PA standard, and free verification.
Signal and coverage
Today, signed-output detection, verification events, quote checks, and output records show what Encypher observed without claiming complete downstream coverage.
Live now: source verification, completed-output signing, web-surface detection, and verification-event telemetry.
Web-surface detection and verification-event telemetry show where a signed output was found or checked.
Observed signals only, not every copy, view, or downstream use.
Check generated text against a signed source before publication and retain the similarity result.
The recorded event supports customer and internal review.
Export completed-output signing records for disclosure, legal, and security review.
C2PA authenticates the document as a whole; Encypher markers carry sub-document attribution.
More on content provenance verification.
Early integration partners
Early partners combine retrieval, citation, product-outcome, and agreed distribution events with signed-source and observed verification records. That partner-supplied instrumentation can support source-performance and spread analysis; provenance alone cannot establish either, and each report states its coverage limits.
Encypher authored the C2PA standard for unstructured text and co-chairs the Text Provenance Task Force alongside these member organizations. Logos indicate C2PA membership.
FAQ
The coalition is a commercial program for publishers and AI companies that want common machine-readable terms and a shared contracting path. Coverage, participating sources, and whether future members are included depend on the agreement you sign. Custom bilateral terms can still sit alongside it.
An evidence package records what a signing workflow supplied, such as signer identity, timestamp, rights terms, and integrity data. A document-level C2PA signature can be checked with standards-based tools. Encypher sentence-level text markers use a separate resolver layer and are not independent sentence claims inside the C2PA manifest.
For content you ingest, verification can show whether supported provenance is present and return its recorded terms before a dispute exists. A verification log documents the check your system made. Pipeline-wide retrieval and outcome instrumentation is part of the early integration partner program.
If a coalition publisher raises a dispute, the signed commercial agreement defines the resolution process and the content it covers. The evidence package supports that process; it does not settle a copyright or licensing dispute by itself.
Only if you put it in the blocking path, and you do not have to. Sign and verify are standard HTTPS API calls designed to run asynchronously: you return the model response to your user first, then sign or verify out of band and record the result. Nothing in the integration requires a synchronous call before your response goes out.
We do not publish latency benchmarks, so we will not quote numbers here. What is documented: batch endpoints accept up to 10,000 documents per request for archive and pipeline workloads, rate limits are 1,000 requests per minute on Growth and 10,000 per minute on Enterprise, and enterprise deployments support white-label identity and on-premises options when verification needs to run inside your own infrastructure. C2PA is an open standard, so the verification logic can also run locally against open-source libraries with no network call at all. For inference-scale volumes, talk to us about an async batch architecture review.
The legal landscape is unsettled and active litigation is ongoing. A license can reduce uncertainty about the covered content and create a documented commercial basis for its use, but it does not answer every copyright, privacy, or data-governance question. Counsel should assess the relevant sources, uses, and jurisdictions. Encypher provides the provenance and usage records that support that review.
robots.txt and noai directives apply at crawl time on the publisher’s server. Provenance is attached to a particular signed version of the content and can travel with copies that preserve its C2PA manifest or Encypher text markers. Signing an archive later establishes a new record; it does not retroactively change or license copies already held elsewhere.
Encypher is not an enforcement mechanism. It makes provenance and supplied licensing terms machine-readable and verifiable. robots.txt is a crawl signal; content provenance can remain available after publication when the relevant metadata or markers survive the content path.
For sources that carry Encypher rights terms, yes. Each signed source projects to a W3C ODRL policy bound at signing time, and a deterministic engine evaluates that policy against the intended use you name. The same inputs return the same verdict every time: a prohibition outranks a permission, and a request that matches no rule defaults to deny.
The verdict is advisory and machine-readable. Encypher returns permit or prohibit together with the rule that decided it, and your own retrieval or generation layer decides what to do with the answer. Encypher does not sit in your request path. Where a permit depends on a commercial license, that is a licensing outcome recorded beside the verdict, not a third ODRL decision.
A verdict is only as good as the record behind it. It reflects the terms the signer supplied and bound to the content; it does not establish ownership or settle a dispute.
For verification calls: we receive the text submitted for verification and return provenance metadata. We do not train on your data, do not retain content beyond the verification transaction, and offer a standard data processing agreement at enterprise tier.
For performance intelligence (an early integration partner capability): we record that a provenance check occurred, the result (verified / not found), and the timestamp. We do not store the full content of your AI-generated outputs unless you opt into spread analytics, which requires explicit configuration.
For the highest isolation, a standard document-level C2PA signature can be verified locally with open-source tools. Resolving Encypher sentence-level text markers requires the matching verification record; enterprise customers can discuss a customer-hosted deployment for that layer.
Encypher’s output marking is designed to support Article 50 transparency workflows, with marking obligations applying August 2, 2026 for new systems and December 2, 2026 for systems already on the market. A successful sign operation can record the supplied AI-generation metadata in a C2PA manifest and add supported text markers. Whether that satisfies the law depends on the content, system, deployment, and final implementing rules.
We are not a law firm. Confirm the implementation with counsel in each jurisdiction; we can provide technical documentation for that review. Separate configurations may support other marking regimes, but one implementation should not be assumed to satisfy every mandate.
You can verify signed content from publishers outside the coalition. C2PA is an open standard, and Encypher can validate supported C2PA manifests regardless of coalition membership. Attribution is only as strong as the signer identity, certificate chain, and metadata in that record.
When supported provenance is absent, verification returns a not-found or unverified result rather than proof that the content was never signed. Coalition membership adds a contractual layer; it is separate from technical provenance verification.
Provenance Chat signs an answer in your browser. The early-partner pilot goes further: your retrieval path, per-source verification, and the rights verdict your own gate consumes, mapped with your team.