Exchangeable Image File data
Technical fields commonly written by cameras and editing software. They are practical, broadly supported and normally editable.
- Camera, lens and exposure
- Capture date and time
- GPS and processing software
EXIF records how an image was captured. C2PA adds a signed provenance structure that a verifier can validate against the image.
EXIF can be useful evidence, but its presence alone does not establish who asserted it or whether it was changed.
One layer helps applications understand an image. The other helps verifiers inspect declared history and integrity.
Technical fields commonly written by cameras and editing software. They are practical, broadly supported and normally editable.
A structured manifest containing claims about provenance, signed and bound to the asset so validation can detect relevant changes.
C2PA does not make ordinary EXIF trustworthy by default. It makes clear which assertions are inside the signed structure.
| Question | EXIF | C2PA |
|---|---|---|
| Purpose | Describe capture and technical image properties. | Describe declared provenance and support integrity verification. |
| Typical data | Camera, exposure, timestamp, GPS and software. | Actions, ingredients, assertions, signature and certificate data. |
| Tamper resistance | Fields can usually be edited without a cryptographic warning. | Changes covered by the content binding can cause validation to fail. |
| Signer identity | EXIF does not normally establish a signing identity. | A certificate identifies the credential used to sign the manifest. |
| Survival | Frequently removed by platforms, exports and privacy tools. | Embedded credentials may also be removed or require durable recovery. |
| Verifier result | Read as ordinary metadata. | Evaluated for presence, integrity, signature and trust status. |
The answer depends on how the manifest was authored and which information the signer chose to assert.
The field is present in the image, but it remains ordinary editable metadata. Its value is not automatically a signed C2PA assertion.
Descriptive metadataThe selected information is part of the signed C2PA structure and can be evaluated within that declared context.
Signed contextA mature workflow reads technical metadata and verifies Content Credentials as separate evidence layers.
Inspect camera and time data, then check which details are actually declared and signed in the Content Credential.
Keep useful EXIF for search and production while preventing transformations from silently breaking provenance.
Distinguish “this field exists” from “this assertion is covered by the signed manifest.”
If GPS data is included in a signed assertion, verification can show that the assertion is intact. It does not independently prove that the original GPS value was accurate or that the scene is truthful.
These answers keep the technical distinction clear for reviewers and end users.
Yes. Most EXIF-bearing images have no C2PA manifest. ProvSeal may therefore show No credentials.
No. The manifest author decides which assertions to include, and implementations may handle metadata differently.
No. EXIF can support review and cataloging. It should be assessed alongside source checks, C2PA evidence and editorial context.