Fully managed C2PA and CAWG
Focus on your core proposition. We handle C2PA and CAWG. A fully managed REST API that creates, edits, and signs C2PA and CAWG manifests for your assets in a single API call.
Try the sandboxThree ways to use the SSL Provenance API
Pick the signing model that matches how much of the identity you want to own.
SSL.com is the signing entity
SSL.com acts as the C2PA signing entity for your assets.
Use this when you want provenance on your content without operating any signing infrastructure or holding a certificate of your own.
SSL.com is the signing entity, with your CAWG identity
SSL.com signs as the C2PA entity, and your organization's identity is asserted through a CAWG certificate compatible with the IPTC Verified News Publisher trust list.
Use this when your brand needs to appear on the asset but you would rather not take on C2PA conformance.
Publisher: Your Company
Your own signing certificate
You sign with your own C2PA certificate, with CAWG identity as an option. This route requires C2PA conformance, and we can accelerate that process.
Use this when you need full control of the signing identity.
Publisher: Your Company
Optional: durable Content Credentials. Add watermarking so Content Credentials survive transformations that strip metadata. An imperceptible watermark lets the manifest be recovered even when the embedded metadata is gone.
A conformant CA, in production since 2025
The first publicly trusted certificate authority on the C2PA conformance list, issuing production certificates since 2025.
The first publicly available C2PA sandbox, so you can test signing before you commit to an integration.
A dedicated C2PA team active in both the C2PA and CAWG working groups.
Among the five largest public certificate authorities by volume, issuing millions of certificates and signatures daily.
Built for the transparency deadline
Article 50 disclosure rules became enforceable on 2 August 2026, and the grace period for systems already on the market closes on 2 December 2026. The rules ask for AI output to be marked in a machine-readable format, for that marking to be robust and interoperable rather than reliant on any single method, and for disclosure to reach users at first exposure. Signed C2PA manifests layered with watermarking answer all three.
See the EU AI Act guideStart signing
Test against the sandbox, or talk to our team about the route that fits your infrastructure.
Talk to our provenance teamRelated: C2PA Certificates | CAWG Certificates | C2PA Time Stamping