Beyond the Spec: Building Real Trust into C2PA
A Content Credential is only as good as its ability to survive the platforms you publish on
Dom Guinard of SSL.com and Tony Rodriguez of Digimarc on what breaks provenance in the real world, and what holds it together. Recorded 22 July 2026.
What the session covers
A signed C2PA manifest proves where an asset came from and whether it has changed. The difficulty is that a manifest is metadata, and metadata travels badly: some platforms strip it on upload, and an attacker can attach a legitimate manifest to content it was never issued for.
What Dom and Tony work through
A recovery path when metadata is stripped
Tony Rodriguez sets out the three components that give a signed asset a recovery path, including the Soft Binding Resolution API, which retrieves a manifest from the content itself.Where the C2PA trust list still needs to mature
Dom Guinard on the gaps that remain in the trust list and what has to close before wide reliance is reasonable.Whether a credential still verifies in twenty years
Both speakers on long-term durability, and the audience questions on watermark interoperability.SSL.com's part in it
SSL.com is a C2PA Trusted CA and issues the claim signing certificates and trusted timestamping behind durable Content Credentials.
Watch the full session
Roughly forty minutes, including the audience questions on watermark interoperability and long-term durability.
Related products
C2PA Certificates
Sign Content Credentials that travel with every asset you publish.
CAWG Certificates
Add verified identity attribution inside your C2PA manifest.