Creators and contributors
Nobody can say afterwards which contributor touched an artifact, what they put into it, or whether they held the rights — and an organisation cannot impose a process on people it does not employ.
Authenticity, provenance, and identity in a unified gateway. Turnkey assurance across media, software, and agentic workloads.
Enterprise-grade multi-tenant SaaS, deployed in the US and EU for data sovereignty.
Workflow history
Illustrative result. The history shown is this team's workflow, step by step, each contribution attested.
A key member of the growing momentum behind C2PA
Just as SSL and digital certificates became table stakes for internet commerce, digital integrity will be the price of entry to the Internet of Authenticity.
Governing digital integrity across teams, pipelines and partners is the challenge.
Proving the authenticity of a single asset has long been straightforward. What is needed now is provable workflows: the processes an artifact passed through, the people, software and systems that touched it, and the authority behind each one.
Nobody can say afterwards which contributor touched an artifact, what they put into it, or whether they held the rights — and an organisation cannot impose a process on people it does not employ.
The tools that create artifacts — editing suites, build systems, render farms, review platforms — were never built to embed provenance. Keys become secrets in whatever runs the step, approvals happen in chat, and the pipeline that made the artifact is the least protected part of it.
Software has a security toolchain — scanners, attestations, policy gates in the pipeline. Media and content supply chains are further behind — inventory, gates and visibility into what was attested are still catching up.
AI-generated content and unlicensed IP seep into business processes, where copyright infringement carries severe legal exposure. By the time it matters, nobody can say what went into the work or under what terms.
C2PA defines common, interoperable formats for exchanging trustworthy artifacts. It does not define how applications and infrastructure construct those artifacts, or how people manage the workflows, teams and processes that produce them.
C2PA
Not covered
Wire services, broadcasters and newsrooms attesting at publication, so syndication partners and platforms can confirm a story or photograph came from the newsroom and has not been altered.
Integrity checks inside the production pipeline rather than a review at the end. Render-farm scale across Perforce and existing pipelines, every pass attributed, with no change to delivery times.
Provenance for containers, packages and binaries generated inside existing pipelines, and checked before anything reaches production.
Turn content and AI policy into a control that can be evidenced. One set of evidence that product, legal, security and risk teams can all read.
Attest notices, records and public communications in the name of the issuing authority, so anyone can confirm what was published and whether a word has changed.
An attested claim tells an agent what was asserted. It does not tell it whether to believe the asserter. Machine-readable trust is the difference.
In force in the EU and California, with platform duties landing in 2027.
Content and AI disclosure obligations are already operative in California, the European Union and China, and more dates land in 2027. Noosphere produces the machine-readable provenance each of these regimes asks for.
California
Applying nowSB 942, as amended by AB 853
European Union
Applying nowRegulation (EU) 2024/1689
China
In forceLabelling of AI-generated synthetic content
A tamper-evident set of content credentials attached to a file that says who published it, when, and what was done to it along the way. It is cryptographically bound, so any change to the file or the credentials themselves is detectable. Think of it as a label that cannot be quietly rewritten.
A specification defines what a valid content credential looks like. It does not decide who inside an organisation may attest, under what policy, with which credential, or whose attestations its systems should accept — and it does not rotate keys or leave an audit trail. That governance layer is the product, and it spans every specification an organisation ends up needing rather than one.
No, and C2PA is where most of our customers start — it has the regulatory deadlines behind it. What tends to happen next is that the same questions come back for things C2PA does not cover: the software an organisation ships, the AI workloads it runs, the partner claims it has to judge. Starting with C2PA on the governance layer means those are configuration later rather than a second procurement.
No, and that is the point. Attestation happens inside the systems already in use — publishing tools, version control, build pipelines — driven by policy rather than by a toolkit someone has to integrate. Provenance emerges from the workflows as they run; nobody learns a new one, and delivery times do not move.
The public validator is live now and reads content credentials from any vendor. Attestation on the platform is opening in stages, so access to that runs through the waitlist. Enterprise rollouts are a direct conversation.
Anyone with the file. That is the point of building on open standards: verification does not depend on the recipient being our customer, or on us being available.
Noosphere is enterprise-grade multi-tenant SaaS, deployed in the US and the EU so content and credentials can stay in the jurisdiction the obligations require. Certificate issuance, rotation, revocation and hardware-backed key storage are handled by the platform.
Do not take our word for it. Validate an artifact.
Drop any image, video or document into our validator and read what comes back: which identities contributed, when, which workflow steps it passed through, and whether the provenance still holds.
Tell us what the workflows look like and where the work travels, and we will show how they get instrumented and secured without changing how anyone works.