Hashproof signs official media at the source, lets the public verify it against impersonation, and keeps an auditable record of what was signed. Built on C2PA, the open provenance standard, behind one HTTP API.
What is going wrong
Three failures in how public media is authenticated and retained.
Official media is impersonated
Fabricated statements attributed to officials, doctored footage of public events, and forged documents now spread during exactly the moments when accurate information matters most. Agencies have no native way to let the public confirm what is authentic.
The public record degrades in transit
A press release, a hearing recording, or a satellite image is copied, re-hosted, and excerpted across countless third-party sites. Each copy is severed from the issuing agency, and there is no way to point back to the canonical original.
Custody chains are hard to prove
Records retention statutes and evidentiary standards require a demonstrable chain of custody. Reconstructing one after the fact, across systems and decades, is slow and contestable when it is even possible.
What Hashproof brings
Four primitives, one HTTP API, with deployment controls for the public sector.
Sign at the source of record
Issue a C2PA manifest when a document, image, or recording is created or released. Hashproof stores a managed provenance record for each artifact, checkable through the public verify endpoint.
Resolve back to the canonical original
Soft-binding resolution matches a re-hosted excerpt or re-encoded copy against stored manifests and returns ranked candidate originals by perceptual similarity. The public, journalists, and reviewers can check a circulating asset against those candidates rather than starting from nothing — a similarity match, not a guaranteed identity.
Recorded batch-inclusion trail
Signed manifests can be batched into Merkle trees, with a manifest inclusion proof available from the API once its batch is anchored. A proof records that the manifest identifier and its content hash were included in a recorded batch root.
Built for long-horizon retention
Manifests follow the C2PA 2.x data model and are retrievable through the API. Stored records remain checkable through the public verify endpoint for as long as they are retained. Automated retention and expiry are not yet enforced.
Where it sits in the workflow
From issuance to retention. Existing records systems and portals stay in place.
01
Issue
Agency systems POST each official artifact to the signing endpoint at the moment of release. The manifest records the artifact hash and the signing timestamp.
02
Publish
Public-facing portals expose a verification badge. Anyone can check a circulating image or document against its stored provenance record through the public verify endpoint.
03
Verify
When a contested copy circulates, the verify endpoint checks it against the stored manifest. Resolution handles re-encoded image copies.
04
Retain
The compliance reporting endpoint produces structured JSON records for retention and discovery: per-manifest findings with specific issues, six summary counters, and a persisted report history with stable report IDs.
How Hashproof is different
Open where it has to be open, controlled where you need control.
An open standard, not a national silo
C2PA is a Linux Foundation specification. Manifests follow the C2PA 2.x data model, and stored records can be checked by partners, allied governments, and the press through the public verify endpoint.
Sovereignty and isolation where required
Enterprise deployments include a DPA and contractual data-handling terms. The neutrality of the format keeps your records portable.
Neutral substrate, accountable institutions
Hashproof signs and verifies. The authority of a record comes from the agency that issued it; the stored provenance record makes the released artifact checkable. We do not sit in the chain of authority, only in the recorded provenance behind it.
Compliance fit
One provenance layer across retention, recordkeeping, and transparency obligations.
Federal records retention
Provenance manifests serve as durable metadata your agency can retain alongside the artifacts it keeps under its own records schedules. Signing timestamps are recorded on each manifest. Automated retention and expiry are not yet enforced, so scheduled disposition stays with your existing records system.
Recorded batch-inclusion record
Merkle inclusion proofs record which manifests a batch root covered. Compliance reports cite each manifest by ID, so a reviewer can trace each recorded batch-inclusion entry back to the manifest it covers.
Public transparency mandates
The same provenance layer that protects against impersonation also lets the public check released media through the public verify endpoint, supporting open-government and disclosure obligations.