White paper WP-021
Beyond C2PA: ZK Content Provenance That Survives Metadata Stripping
When platforms strip C2PA tags, hash-bound proofs still tell you where content came from.
At a glance
- Paper
- WP-021
- Topic
- Beyond C2PA: ZK Content Provenance That Survives Metadata Stripping
- Format
- PDF + web summary
- Signatures
- ML-DSA-65 post-quantum (NIST FIPS 204)
- Sandbox
- Reproducible at affix-io.com/sandbox
- Company
- AffixIO, Wales, UK
Beyond C2PA: ZK Content Provenance That Survives Metadata Stripping is an AffixIO technical paper. When platforms strip C2PA tags, hash-bound proofs still tell you where content came from.
C2PA was meant to label synthetic media. Most uploads strip the credentials anyway. We bind provenance to content hashes with zero-knowledge proofs so labels survive compression, re-encoding, and deliberate metadata removal. Platforms verify origin without seeing your generation pipeline.
Summary
C2PA was meant to label synthetic media. Most uploads strip the credentials anyway. We bind provenance to content hashes with zero-knowledge proofs so labels survive compression, re-encoding, and deliberate metadata removal. Platforms verify origin without seeing your generation pipeline.
Download the full PDF for technical detail, diagrams, and reproduction steps. Public sandbox: affix-io.com/sandbox.
Related reading
Frequently asked questions
Why is C2PA not enough?
Social platforms and CDNs routinely strip or rewrite embedded metadata. Credentials attached to files disappear before users see the content.
How does hash-bound provenance work?
A proof commits to the perceptual and exact hashes of the content. Verification queries a public registry, not fragile file metadata.
Who needs this for compliance?
Publishers, platforms, and model providers facing EU AI Act Article 50 and DSA obligations on synthetic and manipulated media.