01 · pick images
Choose what to protect — a sample, or your own photos (multiple at once). This is your AI content entering the system.
⚙ in the product: every publish arrives here automatically
02 · mark
Two proofs are embedded in the image — a signed C2PA credential plus an invisible watermark — and the event is written to the register.
⚙ in the product: automatic on every publish
Marked — as your app would serve it
Attacked — after the internet touches it
Every mark just landed in the compliance register — view the events →
03 · push it through a platformunlocks after 02
The stress test: each button re-encodes the last marked image exactly the way that platform does. Watch the C2PA credential die — and the watermark hold.
demo-only — out there, the internet does this step for real
→ The platform stripped the C2PA credential — but the watermark survived, and its ID recovered the full provenance the platform destroyed. That's a durable content credential — the layer under the register.
04 · the evidence packunlocks after 02
The payoff: a PDF a regulator or client would accept — every marked asset, hashes, soft-binding IDs, tamper-evident digest. The full-history version lives in the register.
one click, whenever proof is needed
05 · disclosure — the visible layerunlocks after 02
The mark is invisible (Art 50(2)). Some duties also need a disclosure a person can see — a deepfake label (50(4)) or a chatbot notice (50(1)).
⚙ in the product: applied automatically where the rules require it
With visible disclosure · Art 50(4)
compliance check · optional
Describe your AI in a sentence — see which Article 50 obligations apply and which RegisterWell covers.
your role: