Tool Gate · How it works
How the Content Provenance & C2PA Readiness Gate gate works
How the Content Provenance & C2PA Readiness Gate scores an asset's provenance record on completeness — then a durability gate forces UNVERIFIABLE when the publish path strips the credential and no fallback can recover it, so a file cleanly signed at the source still reaches viewers unsigned.
How the gate works
This tool grades a signed asset for whether its C2PA credential survives your publish path to the viewer. Each control is marked from your own evidence and weighted into a 0–100 score — and then the score is run past a gate that can only make the verdict worse.
The 5 weighted controls
| Signal | Weight |
|---|---|
| Credential attached at the source | 26 |
| Signature validates & binds to the asset | 24 |
| Signer is known & on a trust list | 18 |
| AI / edit disclosure assertion present | 16 |
| Durability fallback (soft binding) | 16 |
| Total | 100 |
The verdict bands
If the publish path strips the credential — a CDN re-encode, a CMS resave, a social upload — and no durable fallback can recover it, the asset is UNVERIFIABLE regardless of the score. A downstream viewer sees an unsigned file, however cleanly it was signed at the source.
In the worked sample it scores 84 out of 100 and still reads UNVERIFIABLE — This newsroom photo is cleanly signed at the source — credential attached, signature valid, trusted signer, disclosure present — for a score of 84 that on its own reads GAPS. But the publish path (CDN re-encode, CMS resave) strips the embedded credential and there's no durable soft-binding fallback to recover it. The stripping gate fires: a downstream viewer sees an unsigned file, so it's UNVERIFIABLE, not GAPS. The one thing to fix first: Durability fallback (soft binding) — add a soft binding, watermark, or fingerprint plus an external manifest so the credential can be recovered after your CDN strips the embedded manifest..
Common questions
Can something score well on the How the Content Provenance & C2PA Readiness gate works and still fail?
Yes. The weighted score is run past a worsen-only gate — the Stripping gate — that can only make the verdict worse. In the worked sample it scores 84 out of 100 and still reads UNVERIFIABLE, because this newsroom photo is cleanly signed at the source — credential attached, signature valid, trusted signer, disclosure present — for a score of 84 that on its own reads GAPS. But the publish path (CDN re-encode, CMS resave) strips the embedded credential and there's no durable soft-binding fallback to recover it. The stripping gate fires: a downstream viewer sees an unsigned file, so it's UNVERIFIABLE, not GAPS.
What is a worsen-only gate?
A dispositive rule that can only lower a verdict, never raise it. One fatal flaw overrides an otherwise-good score, because a single disqualifying gap shouldn't hide behind a high average. The tool also names the one thing to fix first — here, "Durability fallback (soft binding) — add a soft binding, watermark, or fingerprint plus an external manifest so the credential can be recovered after your CDN strips the embedded manifest.".
Grades credential readiness — whether the provenance record is present, signed, and durable — not whether the content is real. Not a deepfake detector, and not legal advice; confirm any disclosure or transparency obligation with your compliance owner or counsel.
Embed this diagram
Free to share and embed with attribution (CC BY 4.0) — keep the link to redhub.ai.
Interactive — renders the live diagram
<iframe src="https://redhub.ai/visuals/tool/content-provenance-c2pa-readiness-gate.html" title="How the Content Provenance & C2PA Readiness Gate gate works — RedHub AI" width="760" height="1796" loading="lazy" style="border:0;width:100%;max-width:760px"></iframe>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai/visuals/tool/content-provenance-c2pa-readiness-gate">How the Content Provenance & C2PA Readiness Gate gate works</a> — by <a href="https://redhub.ai">RedHub AI</a>, the AI that tells you when to doubt it.</p>Image + link — a static picture for any blog
<a href="https://redhub.ai/visuals/tool/content-provenance-c2pa-readiness-gate"><img src="https://redhub.ai/visuals/tool/content-provenance-c2pa-readiness-gate-share.png" alt="Diagram of the Content Provenance & C2PA Readiness Gate: a provenance record scored to 0-100 and a durability gate forcing UNVERIFIABLE when the publish path strips the credential." width="760" loading="lazy" style="max-width:100%;height:auto;border-radius:16px"></a>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai">RedHub AI</a> — the AI that tells you when to doubt it.</p>This is how Content Provenance & C2PA Readiness Gate works. More diagrams in the Visual Field Guide.