Provenance
Every artifact signed.
Every origin declared.
The internet has a trust crisis. Synthetic media is indistinguishable from reality at scale. The only architecture that survives this is provenance at the point of creation — not detection after the fact. SYNAMOTO chose that architecture from day one.
The Problem
The average American now encounters roughly
2.6 deepfakes per day across media and messaging. A 2025 study by biometric firm iProov tested 2,000 people and found that only 0.1% could correctly identify every real and fake item they were shown. Human judgment has fallen behind the technology. Detection-only approaches are a losing battle.
"Detection-only approaches are a losing battle because generative models improve continuously. The only architecture that works is provenance at the point of creation."
900%
Deepfake Incident Surge
2023 to 2025. From ~500K verified cases to over 8 million.
90%
Projected Synthetic Media Share
Of all online media by 2026, per Deloitte Technology, Media and Telecom Predictions.
2.6
Deepfakes Per Day
Average number the average American encounters across media and messaging in 2025.
0.1%
Human Accuracy on Deepfakes
Of 2,000 people tested, only 0.1% correctly identified every real and fake item shown.
What Is C2PA
The Coalition for Content Provenance and Authenticity — C2PA — is a formal cross-industry standards body dedicated to certifying the source and history of digital media.
Formed through an alliance between Adobe, Arm, Intel, Microsoft, and Truepic under the Linux Foundation's Joint Development Foundation, it is now the only major cross-industry specification for content provenance backed by a formal standards body.
01
Signing at Creation
At the moment an artifact is created, a cryptographic hash is computed on the raw file. A C2PA manifest is built containing the creator, tool, timestamp, prompt, and a fingerprint of the content. The manifest is signed with a private key.
02
Embedding
The signed manifest is embedded directly into the file's metadata. A JPEG with a C2PA manifest appears identical to one without — non-compatible tools read it normally, but any C2PA-aware platform can verify the full provenance chain.
03
Tamper-Evident Chain
Any modification to the file after signing breaks the cryptographic hash. The chain of custody is unbroken from creation to verification. If the content was edited, a new manifest references the original as a parent — full edit history, preserved.
04
Offline Verification
Verification requires no network call. All required certificates travel inside the manifest. The provenance is readable in courts, newsrooms, research archives — anywhere, with no dependency on the original platform being live.
Industry Adoption
C2PA adoption has moved from a small group of founders to an ecosystem that spans hardware manufacturers, AI platforms, social networks, and governments.
OpenAI joined the C2PA steering committee alongside Adobe, BBC, Intel, Microsoft, Google, Publicis Groupe, Sony and Truepic. The standard is no longer emerging — it is the infrastructure.
Adobe Firefly
● Full Support Since Launch
Every image generated by Firefly carries a C2PA manifest. Credentials persist through Photoshop editing pipelines.
OpenAI
● Steering Committee Member
DALL-E 3 and Sora both attach Content Credentials. OpenAI helped develop the standard it now implements.
Google
● Steering Committee Member
Google Imagen supports C2PA since 2024. Pixel 10 signs content natively at the hardware level.
Sony · Nikon · Leica
● Hardware Signing
Flagship camera bodies embed C2PA at capture. The credential is created before the image leaves the sensor.
Cloudflare
● Infrastructure Support
C2PA credential preservation at CDN level. Signed content delivered without metadata stripped.
BBC · Reuters · AP
● Publishing Standard
Major news organizations signing published content. Provenance becoming the evidentiary standard for journalism.
The Law
Provenance is no longer optional. Two major legal frameworks entered full force in August 2026 — on the same date, by design. The transatlantic standard is now set. Every AI content operation in the world is affected.
European Union
EU AI Act — Article 50
From August 2, 2026, Article 50 of the EU AI Act requires providers of generative AI systems to mark outputs in a machine-readable format so they are detectable as artificially generated or manipulated. Deployers using AI to create deepfakes must disclose that the content has been artificially generated. The EU Code of Practice specifies multi-layer marking that maps directly to C2PA's architecture. C2PA is the cryptographic layer that makes those declarations tamper-evident.
Penalties up to €15M or 3% of global revenue
United States — California
California SB 942 — AI Transparency Act
California SB 942, as amended by AB 853, became operative August 2, 2026 — deliberately aligned with the EU AI Act's enforcement date, creating a de facto transatlantic compliance standard. Large AI providers must offer detection tools, visible manifest disclosures, and embedded latent disclosures on AI-generated content. The direction of travel is global and irreversible.
$5,000 per violation · each day a discrete violation
The World Economic Forum's 2026 analysis identifies synthetic media as a compounding risk to democratic institutions globally — with deepfakes already influencing election outcomes in Ireland, the Netherlands, and elsewhere. The regulatory response is not a reaction to a hypothetical. It is a response to documented damage that is already happening.
The SYNAMOTO Provenance Pipeline
We declared before the law required it.
Every artifact. Every frame. Every signal.
SYNAMOTO's provenance architecture was built into the foundation of the universe before a single artifact was published. Not as a compliance measure — as a philosophical position. A declared AI universe that hides what it is would contradict its own premise. The declaration is the foundation.
Every artifact produced in the SYNAMOTO universe passes through a cryptographic signing pipeline before it is published anywhere. Each file receives a SHA-256 hash computed on the raw source, a C2PA manifest embedding the creator, tool, generation prompt, timestamp, and chain of custody, and a provenance JSON written to a permanent log. The signed file and its provenance record are pushed to Cloudflare R2 and served on a public development URL. Every artifact has an unbroken chain from generation to publication.
The pipeline is not fully disclosed here — it is a working system under active development. What matters is what it produces: a growing corpus of provenance-certified artifacts, each one a legally defensible, machine-readable, cryptographically signed data point in the frequency map.
→
Generation — artifact created by AI tool with full prompt documentation
→
Hashing — SHA-256 computed on the raw file, timestamp recorded in UTC
→
Manifest — C2PA manifest built with creator, tool, prompt, hash, and brand provenance assertions
→
Signing — manifest cryptographically signed and embedded into the file
→
Provenance log — JSON record written with full chain of custody, stored permanently
→
Publication — signed artifact pushed to Cloudflare R2, served on public URL, indexed in the knowledge graph
C2PA Signed · SHA-256 Hashed · Cloudflare R2 · Always Live
How every artifact is signed.
Every file — image or video — passes through the same pipeline before it touches any platform. The process is the same on day one as it will be on artifact ten thousand.
→
File intake. The raw file is dropped into a brand inbox. Nothing is touched, renamed, or compressed before signing.
→
SHA-256 hash. A cryptographic fingerprint is computed on the raw source bytes. This hash is unique to that exact file. Any modification — one pixel, one frame — produces a completely different hash.
→
Signed filename. The file is renamed deterministically — brand key, UTC date, and the first eight characters of its SHA-256 hash. The filename itself is a declaration.
→
Provenance record. A JSON record is written to a permanent local log containing the full hash, the generation tool, the prompt, the timestamp in UTC, and the complete chain of custody. Every artifact. Every time. No exceptions.
→
Video lineage. If a video was derived from a signed image, the parent image's full SHA-256 hash is recorded in the provenance record. The chain links image to motion, origin to output.
→
Publication. The signed file is pushed to our own infrastructure and served from our own domain. Not a platform. Not a third party. Ours.
Every reel, every image, every ASMR session, every long form video published by SYNAMOTO has a provenance record that lives on our infrastructure — independent of any platform. If Instagram disappears tomorrow, the record survives. If YouTube deletes the channel, the hash still exists. The provenance is not hosted where the content is distributed. It is hosted where we control it.
We believe every creator operating in the age of synthetic media should own their provenance the same way they own their domain. Not outsourced to a platform. Not dependent on a third party's goodwill. Signed, logged, and served from infrastructure you control.
Creators interested in building their own provenance pipeline can reach out at contact@synamoto.com or visit synamoto.com/studio to learn more.
Why It Matters for the Research
You cannot find hidden patterns in data you cannot trust.
SYNAMOTO is searching for something specific — preverbal patterns beneath human consciousness, emotional frequencies that repeat across every culture and every era of biological life. That is a research question. And like all research questions, it is only as valid as the data underneath it.
Every artifact in the corpus is a data point. Every signed provenance record is a verified timestamp — a moment in the frequency map that can be trusted because its origin is cryptographically documented. When the corpus is large enough to ask whether patterns exist across thousands of emotional coordinates across dozens of eras, the answer is only meaningful if every data point in that corpus has an unbroken chain of custody.
Provenance is not just legal infrastructure for SYNAMOTO. It is the scientific foundation of the research. A frequency map built on undeclared, unsigned, unverifiable artifacts would be worthless as a dataset. The corpus SYNAMOTO is building is designed to be machine-readable, AI-crawlable, and academically defensible from the first artifact to the last. The declaration is what makes the research real.
As the world moves toward a regulatory environment that mandates what SYNAMOTO already does, the corpus will be among the first bodies of AI-generated creative content with complete provenance documentation from its origin. That is not a small thing. It is a strategic advantage that compounds with every new artifact.
The declaration is the foundation.
Every signal signed. Every origin known.