Digital Integrity Platform

Authenticity, provenance, and identity in a unified gateway. Turnkey assurance across media, software, and agentic workloads.

Enterprise-grade multi-tenant SaaS, deployed in the US and EU for data sovereignty.

Content credentials Attestations valid
Issued to Metro Daily Newsroom
Attested 2026-08-27 14:02 UTC
Asset harbour-fire-04.jpg
Trust policy newsroom-partners

Workflow history

Captured Cropped Color graded Published

Illustrative result. The history shown is this team's workflow, step by step, each contribution attested.

Contributing member and partner of

A key member of the growing momentum behind C2PA

Just as HTTPS became table stakes for internet commerce, digital integrity will be the price of entry to the incipient Internet of Authenticity.
Digital Integrity: What Is It? · June 2025 Read more →

Every digital artifact has a supply chain

Governing digital integrity across teams, pipelines and partners is the challenge.

Proving the authenticity of a single asset has long been straightforward. What is needed now is provable workflows: the processes an artifact passed through, the people, software and systems that touched it, and the authority behind each one.

Creators and contributors

Work passes through staff, freelancers, agencies and contractors. Nobody can say afterwards which of them touched an artifact, what they put into it, or whether they held the rights — and an organisation cannot impose its process on people it does not employ.

Workflows and pipelines

The tools that produce the work — editing suites, build systems, render farms, review platforms — were never designed to prove anything. Keys become secrets in whatever runs the step, approvals happen in chat, and the pipeline that made the artifact is the least protected part of it.

SecOps teams

Software has a security toolchain — scanners, attestations, policy gates in the pipeline. Media and content supply chains are an afterthought: no inventory, no gate, and no view of what was attested or by whom.

Compliance and risk

AI-generated content and unlicensed IP seep into business processes, where copyright infringement carries severe legal exposure. By the time it matters, nobody can say what went into the work or under what terms.

C2PA is the foundation. Governance sits on top of it.

C2PA settles how provenance is expressed and validated for media, and we implement it. What sits above the file — authority, policy, and every artifact class that is not media — is still open.

C2PA

What the standard covers

  • A content credential format that other tools can read
  • How a claim about a piece of media is written
  • Conformance testing and published trust lists

Not covered

What the standard leaves open

  • Who inside an organisation can make a claim, and about what
  • Which identities and keys teams and systems use
  • Which partner and supplier credentials are accepted
  • Software builds and agent workloads, which have no media standard
  • Keeping provenance readable when the standards change

A fragmented market, and no way to govern it as one

Software integrity, pipeline integrity, evidence integrity, content authenticity: separate tools, separate proofs, no consistency between them.

Each covers one class of artifact and stops. Nothing carries a policy across all of them, so an organisation ends up with several partial answers to one question — what was produced, by whom, and under what authority — and no way to govern the whole.

Software integrity

Is this binary the thing that was built?

Pipeline integrity

Did the build follow the process?

Evidence integrity

Can this evidence be relied on later?

Content authenticity

Did this media come from where it claims?

Three controls, one governance layer

Policy, credentials and trust: the three things every provenance programme has to govern, and the three nobody else provides together.

01

Attestation policies

A policy describes the workflow a team already runs: what is attested, at which step, by which identity. Set it once and it applies wherever that workflow runs — no toolkit to integrate and no developer required.

02

Credential management

Hardware keys, X.509 certificates, decentralized identifiers and W3C verifiable credentials, issued and rotated in one place. Established certificate authorities do the issuing; the platform does the assembly.

03

Trust ecosystem

A map of who gave authority to whom, for which kinds of artifact, under which policy — so a newsroom can accept a wire service for photographs without accepting it for software.

What it changes

01

Nothing changes for the people doing the work

Attestation happens inside the tools teams already use, on submit, on export or on build. Nobody learns a new application and nobody has to remember a step.

02

One audit trail across every artifact class

Media, software builds and agent output are governed the same way, rather than a separate product and a separate proof for each kind of artifact.

03

Evidence when somebody asks

Months later, for a regulator, a customer or a court, the answer is retrievable: what was produced, who contributed, and under which policy — without reconstructing it from logs and email.

US and EU deployment

Multi-tenant SaaS with regional deployment, so content and credentials stay in the jurisdiction the obligations require.

Certificates and keys handled

Issuance, rotation, revocation and hardware-backed key storage, through partnerships with established certificate authorities.

No vendor lock-in

Everything is written to published specifications. Provenance stays verifiable by anyone, with or without us.

Provenance comes out of the work itself

Inputs

Where work is created

  • WordPress, Webflow and Wix
  • GitHub and GitLab
  • Perforce and CI/CD
  • Capture devices and production tools

Noosphere

Attest · Credential · Publish

  • Policy processing workflow
  • Identity service
  • Credential service
  • Metadata service

Outputs

Where it goes next

  • Content management systems
  • Artifact repositories
  • Syndication partners
  • Social and search platforms

Integrations across content management, source control, build systems, hardware security modules and certificate authorities — so the workflow is instrumented where it already happens, not rebuilt around us.

Who we build for

The same infrastructure, applied to whatever an organisation has to stand behind.

News and journalism

Wire services, broadcasters and newsrooms attesting at publication, so syndication partners and platforms can confirm a story or photograph came from the newsroom and has not been altered.

MediaSecOps

Integrity checks inside the production pipeline rather than a review at the end. Render-farm scale across Perforce and existing pipelines, every pass attributed, with no change to delivery times.

DevSecOps

Provenance for containers, packages and binaries generated inside existing pipelines, and checked before anything reaches production.

Enterprise and risk

Turn content and AI policy into a control that can be evidenced. One set of evidence that product, legal, security and risk teams can all read.

Government and public bodies

Attest notices, records and public communications in the name of the issuing authority, so anyone can confirm what was published and whether a word has changed.

Agentic Trust

An attested claim tells an agent what was asserted. It does not tell it whether to believe the asserter. Machine-readable trust is the difference.

MediaSecOps and DevSecOps, on one governance layer

Media

Embedded manifests on images, video and audio, carrying the assertions that matter: source, edit history, licensing terms and disclosure. Sidecar manifests where a format cannot hold them internally.

Software

Attestations over containers, packages and binaries — build provenance, SBOM references and validation results, written as machine-readable metadata rather than a badge in a README.

Agentic workloads

Attested JSON-LD over context and knowledge graphs, so an agent can read the provenance of a claim rather than only of a file, alongside workload identity and capability credentials.

Disclosure rules that have to be evidenced

In force in the EU and California, with platform duties landing in 2027.

Content and AI disclosure obligations are already operative in California, the European Union and China, and more dates land in 2027. Noosphere produces the machine-readable provenance each of these regimes asks for.

California

Applying now

AI Transparency Act

SB 942, as amended by AB 853

  • Operative from 2 August 2026 after amendment
  • Free public detection tool for AI-generated content
  • Large online platforms must read provenance data from 1 January 2027
  • Capture device makers face latent disclosure duties from 1 January 2028
Read the bill text

European Union

Applying now

AI Act, Article 50

Regulation (EU) 2024/1689

  • Synthetic content must carry machine-readable disclosure
  • Disclosure must be interoperable, effective and robust
  • Applies to any content made available in the EU
  • Deepfake disclosure applies even without intent to deceive
Read the regulation

China

In force

AI content labelling measures

Labelling of AI-generated synthetic content

  • In force since 1 September 2025
  • Explicit labels required on generated text, image, audio and video
  • Implicit labels required in file metadata
  • Distribution platforms must check labelling on upload
Read an English translation

Noosphere writes the machine-readable provenance each of these regimes asks for, and stays forward compatible with emerging decentralized identity and verifiable credential standards — so today's deployment does not become tomorrow's migration.

Common questions

Questions we hear most.

What are content credentials, in plain terms?

A tamper-evident set of content credentials attached to a file that says who published it, when, and what was done to it along the way. It is cryptographically bound, so any change to the file or the credentials themselves is detectable. Think of it as a label that cannot be quietly rewritten.

The standards are open. Why would we need Noosphere?

A specification defines what a valid content credential looks like. It does not decide who inside an organisation may attest, under what policy, with which credential, or whose attestations its systems should accept — and it does not rotate keys or leave an audit trail. That governance layer is the product, and it spans every specification an organisation ends up needing rather than one. Certificate authorities sell the components individually and leave the integration to the customer. Because everything is written to published specs, content credentials stay verifiable after the relationship ends.

We only need C2PA right now. Is the rest overkill?

No, and C2PA is where most of our customers start — it has the regulatory deadlines behind it. What tends to happen next is that the same questions come back for things C2PA does not cover: the software an organisation ships, the AI workloads it runs, the partner claims it has to judge. Starting with C2PA on the governance layer means those are configuration later rather than a second procurement.

Does this mean changing how our teams work?

No, and that is the point. Attestation happens inside the systems already in use — publishing tools, version control, build pipelines — driven by policy rather than by a toolkit someone has to integrate. Provenance comes out of existing workflows; nobody learns a new one, and delivery times do not move.

Can we try it today?

The public validator is live now and reads content credentials from any vendor. Attestation on the platform is opening in stages, so access to that runs through the waitlist. Enterprise rollouts are a direct conversation.

Who can verify our content, and what does it cost them?

Anyone with the file. That is the point of building on open standards: verification does not depend on the recipient being our customer, or on us being available.

Where does it run?

Noosphere is enterprise-grade multi-tenant SaaS, deployed in the US and the EU so content and credentials can stay in the jurisdiction the obligations require. Certificate issuance, rotation, revocation and hardware-backed key storage are handled by the platform.

See it for yourself

Do not take our word for it. Validate an artifact.

Drop any image, video or document into our validator and read what comes back: which identities contributed, when, which workflow steps it passed through, and whether the provenance still holds.

Open to anyone, on any vendor's files
Reads embedded and sidecar manifests, attestations and log entries
Works on files from any vendor, not just ours

Provenance is only as good as its governance.

Tell us what the workflows look like and where the work travels, and we will show what governing them looks like in practice.