back
1 comments
The popular removal tools are explicit that they can't confirm their own work, one of which states plainly that "until vendors ship public detectors and keys, no tool can honestly certify 'this fails the official check.'"

That's true for pixel watermarks and keyed text watermarks. It is not true for the file-metadata layer. C2PA manifests are cryptographically signed, so whether one survived an operation is decidable, byte by byte.

So this measures that layer, for two opposite users. If you stripped a file, it tells you whether the manifest is genuinely gone- the verifier's answer, not the remover's claim and it tells you exactly which part remains unknowable. If you wanted the credential kept, it shows you what your export pipeline destroyed: macOS sips (the engine behind Preview › Export) removes a C2PA manifest completely, while a byte-identical copy verifies fine.

Structural carrier parsing for PNG caBX, JPEG APP11 JUMBF, BMFF UUID, TIFF 0xCD41, GIF app extensions, PDF associated files, HTML, and the C2PA 2.4 text carriers. Design constraint: a partial or structurally incomplete scan can never return a clean result & the JSON schema rejects a document claiming VALID alongside ABSENT.