What are content credentials, in plain terms?
A tamper-evident set of content credentials attached to a file that says who published it, when, and what was done to it along the way. It is cryptographically bound, so any change to the file or the credentials themselves is detectable. Think of it as a label that cannot be quietly rewritten.
The standards are open. Why would we need Noosphere?
A specification defines what a valid content credential looks like. It does not decide who inside an organisation may attest, under what policy, with which credential, or whose attestations its systems should accept — and it does not rotate keys or leave an audit trail. That governance layer is the product, and it spans every specification an organisation ends up needing rather than one. Certificate authorities sell the components individually and leave the integration to the customer. Because everything is written to published specs, content credentials stay verifiable after the relationship ends.
We only need C2PA right now. Is the rest overkill?
No, and C2PA is where most of our customers start — it has the regulatory deadlines behind it. What tends to happen next is that the same questions come back for things C2PA does not cover: the software an organisation ships, the AI workloads it runs, the partner claims it has to judge. Starting with C2PA on the governance layer means those are configuration later rather than a second procurement.
Does this mean changing how our teams work?
No, and that is the point. Attestation happens inside the systems already in use — publishing tools, version control, build pipelines — driven by policy rather than by a toolkit someone has to integrate. Provenance comes out of existing workflows; nobody learns a new one, and delivery times do not move.
Can we try it today?
The public validator is live now and reads content credentials from any vendor. Attestation on the platform is opening in stages, so access to that runs through the waitlist. Enterprise rollouts are a direct conversation.
Who can verify our content, and what does it cost them?
Anyone with the file. That is the point of building on open standards: verification does not depend on the recipient being our customer, or on us being available.
Where does it run?
Noosphere is enterprise-grade multi-tenant SaaS, deployed in the US and the EU so content and credentials can stay in the jurisdiction the obligations require. Certificate issuance, rotation, revocation and hardware-backed key storage are handled by the platform.