How it works
Four steps.
From shutter to verdict.
Verifact does not decide whether to trust a photo. It makes the photo carry evidence that removes the need to decide.
01
Capture
The photo is taken inside a Verifact app. GPS position and network-verified time are recorded at the instant of capture — not added later.
02
Sign
A C2PA manifest binds the pixels to the capture facts, signed with an Ed25519 key held in the phone's secure hardware. The key never leaves the device.
03
Timestamp
An independent RFC 3161 timestamp authority countersigns the proof, fixing the earliest moment the photo can have existed.
04
Verify
The verifier re-computes the entire chain in seconds. It either holds, or it visibly breaks.
05 — Tamper evidence
Editing is not detected. It is proven.
Classic fraud detection guesses: does this photo look edited? Verifact does not guess. The signature covers every byte of the image, so any change — a brightness tweak, a cropped corner, a swapped file — makes the mathematics fail.
Verified
The chain holds
The file is bit-for-bit what the device sealed, at the recorded place and time, on the attested device.
Failed
The chain breaks
The signature no longer matches the content. The verdict shows exactly which link failed — content, manifest, timestamp, or key.
No proof
Nothing to check
Files without a Verifact manifest are reported as unverifiable, not as genuine. Absence of proof is a result too.
06 — Independence
You do not have to trust Verifact either.
The proof format is open C2PA, the signatures are standard Ed25519, and the timestamps come from an authority we do not control. The evidence travels inside the file and can be checked by any conforming tool — ours is just the fastest way.
See it work on your claims.
Write to us and we will walk you through a live verification, end to end.