If not, the result is No credentials.
C2PA Trust List
A trust list gives verifiers recognized trust anchors for evaluating the certificate chain behind a Content Credential.
Signature validity answers “was this credential signed correctly?” Trust evaluation asks the separate question “is this signing chain recognized here?”
How a verifier reaches a status
Trust is the last part of a sequence. A file can fail earlier, or it can pass cryptographic checks without reaching a recognized trust anchor.
Validate the signed relationship to the observed media.
Failed cryptographic checks can produce Invalid.
Evaluate the certificate against the active trust context.
Show Trusted or Signed but untrusted with details.
What a trust list says — and what it does not
A trust list is a technical input to certificate validation, not a universal endorsement of every statement inside a credential.
It can establish recognition
The verifier can determine whether the certificate path leads to a trust source accepted in the active ecosystem or policy.
- Recognized trust anchors
- Certificate-chain context
- A basis for a Trusted status
It does not establish truth
Recognition does not independently prove the scene is real, a caption is accurate or every declared action is complete.
- No fact-checking of the media
- No guarantee of author intent
- No replacement for editorial review
Public recognition and private policy
Organizations can make internal trust decisions, but those decisions should be described separately from ecosystem-level public trust.
Public ecosystem trust
The certificate chain is evaluated against recognized public trust infrastructure applicable to the verifier.
Publicly recognized contextPrivate organizational trust
A newsroom, brand or platform explicitly accepts an internal credential for a controlled workflow.
Private policy contextThree public lists with different roles
The Conformance Explorer separates product conformance from the trust anchors used for signing and time stamping.
Records products evaluated under the C2PA Conformance Program. It is not a certificate trust list.
Contains X.509 trust anchors for authorities that issue certificates to C2PA signers.
Contains separate trust anchors for Time Stamping Authorities.
The Interim Trust List is retired and frozen
The official C2PA Trust List replaced the temporary Interim Trust List. Legacy credentials may still need explicit handling, but new entries and updates are no longer added to the ITL.
Keep signature and trust separate
Clear labels prevent a technically valid signature from being mistaken for public recognition.
Evidence validates and the certificate chain is recognized in the current trust context.
Signed evidence exists, but its chain is not recognized by the active trust sources.
A validation failure prevents the credential from being treated as valid evidence.
No C2PA manifest was detected in the observed asset.
Show the reason behind the badge
ProvSeal presents a concise status, then lets users inspect the manifest, signature, certificate and chain details. This makes local tests, private signing and public trust easier to distinguish.
Common questions
These distinctions are essential when documenting trust decisions for users or internal teams.
Can a signature be valid but untrusted?
Yes. Cryptographic validity and recognition of the certificate chain are separate checks.
Can a company trust its own certificate?
Yes, inside a private policy. That does not automatically create public C2PA ecosystem trust.
Does Trusted mean the content is true?
No. It describes validated evidence and recognized signing context, not the factual accuracy of the media.