Trust is not invented from scratch.
Three mature layers already exist. What has been missing is someone applying them to the living web — to the external fact a machine actually consumed.
Existing rails, used as rails.
C2PA
The manifest envelope and the rails already read by Adobe, Microsoft and OpenAI. Observation fields travel inside their format.
W3C PROV
The academic and enterprise language of provenance. Every passport exports to PROV without a converter.
eIDAS / QTSP
A qualified timestamp is what turns a record into documentary evidence inside the EU.
C2PA was designed for a creator signing their own content, and we are an observer, not an author. So this is compatibility of form and rails, not certification. Tools that read manifests read ours — and for the purpose at hand that is enough.
Six layers answer six questions. The centre is empty.
C2PA certifies where content came from. Governance platforms watch the agent. Access infrastructure gets the bytes. Nobody certifies the external fact itself: what was observed, when, from where, and under which rights.
Schematic of adjacent categories, not an exhaustive market map.
| Layer | What it establishes | What it leaves open |
|---|---|---|
| C2PA | Where a piece of content came from. | What a machine observed, and under which rights. |
| W3C PROV | A vocabulary for describing provenance. | Who captured it at the moment of observation, and who signs for it. |
| eIDAS | That a timestamp has legal weight. | What exactly was timestamped, and from which vantage point. |
| Observability | What happened inside your system. | Anything about the external fact the system consumed. |
| Governance | What the agent did. | What the agent knew. |
| Identity | Who acted. | What they acted on. |
| LENTRA | What was observed, when, how, from where, and under which rights. | Your policy decision — that judgement stays with you. |