Signing origin
The file was signed in Lens with a key generated for this device.
Trust and Credentials
Lens attaches verifiable capture evidence to every signed photo and video, so viewers can understand where media came from and whether it changed.
A Content Credential tells people who captured the file, when it was captured, and whether its integrity still holds. It is your evidence trail, not just metadata.
Each signed capture carries a compact evidence chain. Verification tools can inspect this chain without relying on Lens-specific infrastructure.
The file was signed in Lens with a key generated for this device.
Edits or tampering become detectable through hash validation.
When available, a TSA timestamp anchors capture time externally.
Optional context such as location and app version supports audits.
Lens uses open standards and hardware-backed signing so credentials remain portable, inspectable, and tamper-evident.
Open provenance standard that packages capture evidence and assertions into an inspectable manifest.
Hardware-backed signing key generated and used on-device. The key is non-exportable and bound to your iPhone; the enrollment backend never receives it.
When online, Lens requests an external TSA timestamp to establish trusted capture time in the provenance chain.
Device time is checked against trusted network sources to prevent spoofed capture times.
Hash-based integrity checks make edits or tampering visible to verification tools.
Structured metadata container used to embed C2PA manifests directly in media files and generated PDF reports.
Lens keeps the capture signing boundary on your iPhone. Certificate issuance is a separate step.
When CA-signed enrollment is enabled, Secure Enclave generates and retains the non-exportable P-256 key, and Lens signs the certificate signing request locally. The enrollment backend proxies the CSR and limited enrollment metadata to the certificate authority, but it does not receive the private key or your photo/video.
After enrollment, Lens creates the C2PA claim and signs the media on the iPhone at capture. This differs from a remote server-side HSM model where a backend-held key signs uploaded media. An external timestamp authority, when used, provides a separate time signal.
Lens is publicly conformant under Conformance Program v0.2 for C2PA Specification v2.4, and production captures verify with a trusted signer and trusted timestamp. Reliability and enrollment testing continue throughout September 2026.
Product conformance is public and independently verifiable. Production captures verify against SSL.com as the primary TSA, with Trufo serving as the backend-controlled fallback under September testing. Captures verified against legacy trust anchors may temporarily show an Unrecognized Signer status.
Lens uses three levels of progressive disclosure so viewers can verify authenticity instantly and auditors can inspect complete forensic details when needed.

A clean status indicator in the camera view confirms that hardware signing, time checks, and location locks are active before you press the shutter.
Opening the file presents a clear summary card: key assertions, signer identity, hardware key binding, and trusted timestamp status at a glance.
Auditors and forensic tools can drill down into full JUMBF manifest trees, cert chain roots, hashes, and machine-readable cryptographic evidence.