RedHub AIRedHub AI
Tool Gate · How it works

How the gate works

How the Content Provenance & C2PA Readiness gate works

This tool grades a signed asset for whether its C2PA credential survives your publish path to the viewer. It scores 5 weighted controls into a 0–100 number — then a gate that can only make the verdict worse.

The 5 weighted controls

01Credential attached at the sourcewt 26
02Signature validates & binds to the assetwt 24
03Signer is known & on a trust listwt 18
04AI / edit disclosure assertion presentwt 16
05Durability fallback (soft binding)gate · no fallbackwt 16
SIGNED
score 85+
GAPS
score 55+
UNVERIFIABLE
below floor
Stripping gate · worsen-only

If the publish path strips the credential — a CDN re-encode, a CMS resave, a social upload — and no durable fallback can recover it, the asset is UNVERIFIABLE regardless of the score. A downstream viewer sees an unsigned file, however cleanly it was signed at the source.

84/100
UNVERIFIABLE

Why: This newsroom photo is cleanly signed at the source — credential attached, signature valid, trusted signer, disclosure present — for a score of 84 that on its own reads GAPS. But the publish path (CDN re-encode, CMS resave) strips the embedded credential and there's no durable soft-binding fallback to recover it. The stripping gate fires: a downstream viewer sees an unsigned file, so it's UNVERIFIABLE, not GAPS.

Fix firstDurability fallback (soft binding) — add a soft binding, watermark, or fingerprint plus an external manifest so the credential can be recovered after your CDN strips the embedded manifest.

A high score didn’t save it. The score is context; the gate is the answer — and it names the one thing to fix first. Grades credential readiness — whether the provenance record is present, signed, and durable — not whether the content is real. Not a deepfake detector, and not legal advice; confirm any disclosure or transparency obligation with your compliance owner or counsel.