A photograph that leaves PHOTARCH carries four things inside it: what the object is, how large it is in millimetres, who stands behind the picture, and whether anyone has altered the file since. This page explains, as plainly as we can, how that works and what it is worth.
A SHA-256 checksum is a long line of digits worked out from every byte in a file. The same file always gives the same line. Change one pixel — or add a scrap of metadata — and the line becomes a completely different one.
It answers exactly one question: is this file the same one the archive published? Yes or no. It cannot tell you who made the picture, what it shows, or what changed. Only that something did.
A Content Credential — the C2PA standard — is a short letter carried inside the picture. It states things: photographed on this date, colour adjusted, cropped, published by PHOTARCH, one pixel is 0.0163 mm on the object. All of it is then signed with a private key, and countersigned by an independent authority that records when the signing happened.
Anyone can check the signature against our certificate. If someone edits the picture afterwards, the seal breaks and the viewer is told.
This is not an example we made up. It is the seal carried by Glass bead, KLM-39, as it is published in the archive today. Open the file in any Content Credentials viewer and this is what you see.
The measurement is the part worth pausing on. Because it is inside the seal, the scale cannot be quietly corrected, rounded or lost. It can only be broken — and then everyone can see that it was.
This is the question people ask first, and it deserves a straight answer: if the master is never altered, how can the file you download carry metadata?
Because they are two different files.
Nothing is baked into the original. It is baked into the copy — at the moment the copy is made, which is also the moment the seal is applied, so the seal covers the record as well as the picture.
A Content Credential is not a claim of ownership. It says who made the file and what was done to it. It exists so the picture can be trusted, not so anyone can charge for it, and it carries no licence of its own: the file travels under whatever rights the object and its holding institution carry.
It also does not expire when the picture is used. Copy it, publish it, print it — the seal keeps saying the same thing, which is the whole of its usefulness.
This confuses almost everyone, so it is worth separating them.
What others may do with the photograph — CC BY, all rights reserved, and so on.
Lives inthe file's XMP, and on the object's recordWhich parts of PHOTARCH Desktop are unlocked for you. Nothing whatever to do with the picture.
Lives onyour accountWhat anyone may do with ISM, the format the measurement is written in. It is published openly so that reading a PHOTARCH measurement never requires PHOTARCH.
Lives onthe specification · CC BY 4.0, reference library MITSigned and timestamped, carrying the record and the scale.
Each download is a new file, sealed at the moment it is made.
Signed on your own machine. The picture never leaves it — only a few hundred bytes of hashes travel to us and back.
On purpose. Its SHA-256 is its proof, and an unsealed TIFF opens in anything.
Until the C2PA Conformance Program has reviewed the product.
A viewer will say the issuer is unknown. Our certificate is our own until C2PA's Conformance Program has been through the product. What a validator reports today is a valid signature by an unidentified signer — the signature is real and the contents are correct; what is missing is a third party vouching for who we are. Everything else in the manifest is already right.
A sealed TIFF asks a little of strict readers. C2PA stores its seal in a directory of its own inside the TIFF, and a few strict libraries — libvips, and software built on it — treat that as an error and refuse to open the file. The picture is not damaged: libtiff reads it, macOS reads it, and libvips reads it too when told not to fail on a warning. Sealed JPEGs have no such trouble. If a tool of yours refuses a downloaded TIFF, that is why, and the file itself is intact.