FREE / LOCAL / C2PA 2.4

Inspect one. Compare two. Audit a batch. Reproduce a report.

Read Content Credentials, compare provenance changes, review up to 2,000 files and reproduce an exported report without uploading any source asset. Integrity, signer trust and AI declarations remain separate observations.

OPEN THE WORKSPACE CONNECT FREE MCP
A valid credential proves integrity of signed data, not factual truth. No credential does not mean fake.
C2PA 2.4PINNED CAI SDK
EN / ES / ZHBROWSER LANGUAGE
1 / 2 / 2K / RINSPECT / COMPARE / BATCH / REPRODUCE
0 BSOURCE FILE UPLOADED

EVIDENCE POLICY / LOCAL / 2,000 ROWS

Turn provenance observations into repeatable review routing.

Choose one of four explicit presets, adjust ten visible rules and export a checksum-bound profile. The same decision can be replayed in the browser or by the free focused MCP without sending source media.

PRESETS
4 explicit starting profiles
RULES
10 visible routing rules
SCALE
Up to 2,000 observations
REPLAY
Browser + 2 focused MCP tools

INSPECT / COMPARE / BATCH / REPRODUCE

A local workspace for evidence, not verdicts.

Inspect one file, compare two evidence states, review up to 2,000 files or reproduce an exported report. The 8.7 MB verifier loads only after a source file is selected.

Drop a file to inspect its Content Credentials.

Your file stays in this browser. The official C2PA Trust List snapshot is embedded; no runtime trust-list request is made.

JPEG, PNG, WebP, GIF, AVIF, MP4, MOV, M4A or PDF / MAX 50 MB

BROWSER SDK / DEVELOPER PREVIEW / 0.3.0

Put the evidence engine inside your own workflow.

Import one versioned ESM module for local inspection, provenance timelines, sanitized credential paths, Manifest Diff, 2,000-file batch review, evidence envelopes, BagIt packages and report reproduction. No API key and no source upload.

H/M_JS_SDK@0.3.0DEVELOPER_PREVIEW
import { createContentCredentialsClient }
  from "https://hogarmas.net/content-credentials/sdk/v0.3.0/index.js";

const client = createContentCredentialsClient();
const result = await client.inspect(file);

console.log({
  integrity: result.report.integrity.state,
  signerTrust: result.report.signer.state,
  aiOrigin: result.report.aiOrigin.state,
  timelineEvents: result.timeline.eventCount,
  timestampTrust: result.trustDiagnostics.timestamp.state
});
UPLOAD::0API_KEY::0METRICS::0
Browser-local by contract
The SDK sends no source bytes, metrics or browser-storage writes.
Bounded at scale
One file at a time, up to 2,000 files, with compact batch rows.
Pinned and inspectable
Versioned ESM, TypeScript declarations, runtime snapshots and SHA-256 manifests.
Evidence, not verdicts
No truth score. The workspace identifies its pinned official trust snapshot and exposes a sanitized credential path, not a complete certificate chain or compliance claim.

This H/M developer preview wraps @contentauth/c2pa-web 0.13.1. It is not an official C2PA SDK, conformance certificate or legal compliance service.

FOUNDING DELIVERY / USD 790

Turn a collection export into a decision-ready exception review.

Bring one or two H/M Collection Evidence Packages, each with up to 500 processed rows. Receive a prioritized exception memo, an optional baseline-to-current drift memo, a 90-minute review and an updated verified handoff within five business days.

INPUT
One review-copy package, or a baseline/current pair; up to 500 processed rows per package. Source media remains with you.
OUTPUT
Exception memo, optional drift memo, 90-minute review and verified package handoff.
BOUNDARY
No source custody, truth ruling, legal opinion or compliance certification.
REQUEST THE USD 790 SPRINT

Scope, scheduling and payment are confirmed by email before work begins. Taxes and implementation work are excluded unless separately scoped.

PROOF MODEL / NO THEATER

A credential is a chain of evidence, not a truth machine.

The verifier preserves each boundary so a valid signature cannot be mistaken for trusted identity, factual accuracy or proof that no AI was used.

  1. 01

    Manifest presence

    The file carries a readable C2PA manifest store. Missing credentials remain an absence, not a verdict.

  2. 02

    Cryptographic integrity

    The pinned CAI verifier validates claim signatures, hashed assertions and asset bindings.

  3. 03

    Signer trust

    Trusted, untrusted and unknown are shown separately against a pinned official C2PA Trust List snapshot. The legacy ITL and official TSA list are not used.

  4. 04

    Declared provenance

    Actions, ingredients, digital source types and AI Disclosure assertions are reported as signed claims.

LIMITS THAT MATTER

Do not turn provenance into a fake detector.

Does a valid credential prove the image or claim is true?

No. It can prove that signed manifest data and the bound asset have not changed in ways the validation catches. It cannot establish factual truth.

Does no credential mean fake or AI-generated?

No. A camera, editor or platform may never have added one, and metadata can be stripped. Absence cannot prove origin.

Why can integrity be valid while the signer is untrusted?

A signature can be mathematically intact while its certificate is outside the verifier's trust anchors. Identity trust is a separate decision.

Does this certify EU AI Act Article 50 compliance?

No. It surfaces machine-readable evidence inside one file. Visible disclosures, deployment context, exceptions and legal duties require separate review.