Security
Named guarantees, and what proves them.
A proof is only worth something if you can verify the people who make it. Here is what we claim, and for each claim, what holds it up. No padlock icons.
- Hosted in France
- The servers, the database and the proof files are at OVHcloud, in France.
- What proves it: the public list of our sub-processors, with their role and, where it is established, the place of processing.
- Encrypted at rest
- The servers, the database and the proof files are encrypted at rest.
- What proves it: it is a written, binding commitment of our privacy policy.
- Non-extractable signing key, held in a KMS
- The key that signs proofs is held in a key management service: it never travels through our servers. We do not write “HSM”, because it is not one.
- What proves it: the key’s protection level is declared in our C2PA conformance file, and it conditions the assurance level we aim for.
- Device attestation
- On submission the app asks the device for an attestation, and the verification page states whether it was obtained, and at what level. On Android, that is the Play Integrity attestation. On iOS, App Attest, as soon as the app is released.
- What proves it: open the demonstration proof; the “Device and app” check is named there.
- Candidate to the C2PA conformance program
- For captures whose attestation is confirmed, a C2PA manifest, the open provenance standard, is signed and attached. We filed our admission request to the conformance program on 31 July 2026, aiming for level 1. Until it is granted, C2PA tools show our signer as “not listed”, and we do not display the official icon.
- What proves it: read the manifest of an attested proof with any C2PA tool.
- Independent timestamp, anchored in Bitcoin
- The sealing date is anchored in the Bitcoin blockchain through OpenTimestamps. It can be re-verified without us, with public tooling or your own node. We do not write “qualified timestamp”: no qualified timestamping authority is under contract today.
- What proves it: the OpenTimestamps file attached to every proof.
- What remains if we disappear
- The C2PA manifest (attested captures), the Bitcoin anchor and the self-contained PDF file, with the verdict, the items and the method to re-check everything. None of it needs our servers to be verified.
- What proves it: verify without taking our word, step by step.
- The verdict has no button
- No “approve” or “reject” in the dashboard, for anyone. An organisation marks a case as handled; it does not rewrite what the proof says. The verification page also refuses to be framed inside another site: what you see there comes from us.
- What proves it: the same verification page opens for the author, the recipient and the organisation. There are not two of them.
- Export and erasure at any time
- From the app for an individual, through the API for an organisation. Deleting an account erases the proof files from storage.
- What proves it: the public deletion procedure, and the privacy policy.
- No cookies, no third-party trackers
- This site sets no cookies and loads no third-party resource: fonts, images and styles come from our own domain. No advertising in the app.
- What proves it: your browser’s network tab. The rule is enforced by the server, not promised by a banner.
The question that comes with it
What happens to my data?
The servers, the database and the proof files are in France, encrypted at rest. The list of our sub-processors is public, with their role and, where it is established, the place of processing. You can export or erase your data at any time: from the app for an individual, through the API for an organisation. No advertising, no third-party trackers.
The detail, clause by clause: privacy policy, sub-processors, delete your account, mentions légales.
Check us on a real proof.
Everything written here can be read on the demonstration proof’s verification page, and in the items it carries.