Research/Explainer

Two families of proof

In short

  • A credential is legible and cryptographically strong, but it travels in metadata, and metadata gets thrown away.
  • A watermark survives almost any handling, but carries a few bits and cannot explain itself.
  • The 2026 consensus is to use both: a credential for meaning, a watermark to find the credential again.

It's always one of two things

Everything in this field is one of two things. Either you attach a statement to the file, or you hide a signal in the pixels. The first is legible and strong, but it travels in metadata and metadata gets thrown away. The second survives almost anything, but it can only carry a few bits and can never explain itself.

Here they are, side by side

Credentials · metadata

C2PA Content Credentials

  • A signed manifest inside the file: creator, device, software, every edit.
  • Cryptographic. Tampering is detectable, authorship is attributable.
  • Stripped by nearly every social platform on upload.
  • Open standard under the Linux Foundation. Used by Adobe, Google, OpenAI, Sony, Nikon, Leica, Canon.

Watermarks · pixels

Invisible watermarks

  • A pattern spread across the image that a matching detector can read.
  • Survives crop, compression, screenshots, mild edits. Carries a short payload or a yes/no.
  • Cannot say who or why on its own. Needs a lookup.
  • SynthID, TrustMark, Stable Signature, Tree-Ring, StegaStamp.

A credential answers the questions a person actually asks: who made this, with what, and what was done to it since. It does so with a signature, so the answer can be checked rather than trusted.1 A watermark answers one narrower question, which is whether this particular pattern is present, and it keeps answering after the file has been screenshotted, cropped and re-compressed.

What survives being passed around?

The table below is qualitative and drawn from the literature. It describes ordinary handling, not a determined attacker. Regeneration, where an image is passed through a generative model and re-synthesised, is the case that separates the methods.4

MethodTypeSurvives JPEGSurvives cropSurvives screenshotSurvives regeneration
C2PA manifest aloneSigned metadatastrippedlostlostlost
Durable CredentialManifest + soft bindingsyesyesyespartial
SynthID-ImageLearned, post-hocyesyesyespartial
TrustMarkLearned, post-hocyesyesyespartial
Tree-RingIn-model, initial noiseyesyesyesmostly
Visible proof overlayTypesetyesif uncroppedyeslost

Table 1Qualitative survival under ordinary handling. Words in every cell, so colour is never the only channel.

Survival profile by methodQualitative, from the literature. Full bar survives, half partial, hollow lost.
Durable CredentialJPEGCropShotRegenSynthID-ImageJPEGCropShotRegenTrustMarkJPEGCropShotRegenTree-RingJPEGCropShotRegenManifest aloneJPEGCropShotRegenProof overlayJPEGCropShotRegen

Six small charts share one x and one y. The eye compares shapes, which a grouped bar of 24 columns would hide.

Table view
MethodJPEGCropScreenshotRegeneration
Durable Credentialyesyesyespartial
SynthID-Imageyesyesyespartial
TrustMarkyesyesyespartial
Tree-Ringyesyesyesmostly
Manifest alonelostlostlostlost
Proof overlayyespartialyeslost
Sources 2, 4

So you need both

C2PA's answer to stripped metadata is the Durable Content Credential. Alongside the manifest's hard binding, a hash of the pixels, the file carries one or more soft bindings: an invisible watermark and a perceptual fingerprint. When a platform strips the manifest, the watermark still carries an identifier that can be looked up, and the credential is recovered.2,3

  1. 03Your credentialwho, when, with what · signed
  2. 02Your markin the pixels · invisible · points to 03
  3. 01The photographuntouched
one sheetthree sheets · one file · looks the same

The 2026 consensus, written into both the C2PA specification and the EU's Code of Practice, is that you need both. A credential for meaning, a watermark to find the credential again.5 deprint is that pairing, with the maker holding the key.

One difference in how deprint does it is who holds the pointer. Rather than a vendor's repository, the maker's identifier resolves to a manifest the maker published and can revoke.

Sources

  1. C2PA FAQ, Linux Foundation
  2. Durable Content Credentials, Content Authenticity Initiative
  3. Digital watermarking for interoperable Content Credentials, Content Authenticity Initiative
  4. Invisible Watermarks: Attacks and Robustness, arXiv, Dec 2024
  5. Code of Practice on Transparency of AI-Generated Content, Cuatrecasas