Skip to main content

Open source · Apache 2.0

The evidence engine, out in the open.

An open-source C2PA and metadata evidence engine, the reusable core Provenance Radar is built on. Read what a file actually declares about its own provenance, the machine-readable signal EU AI Act Article 50 is about, as typed, honestly-labeled evidence, never a collapsed score.

CI status for the evidence engine

What's in the repo

Three packages, one contract.

A caller never depends on the underlying library (c2pa-node, exiftool-vendored) directly, only on the shared contract. That's what lets a new provider plug in without touching anything that consumes evidence.

@provenanceradar/evidence-core

The EvidenceItem / EvidenceStatus / EvidenceProvider contract every adapter implements. Zero dependencies beyond Node itself.

@provenanceradar/evidence-adapter-c2pa

Reads C2PA Content Credentials manifests, signature validity, issuer trust against the official conformance trust list, claim generator, digital source type.

@provenanceradar/evidence-adapter-metadata

Reads embedded EXIF, XMP, and IPTC metadata for provenance-relevant fields, including declared digital source type.

Evidence, not a verdict

Every fact carries an honest status.

Absence of a signal is never evidence of anything. A file with no C2PA manifest and no watermark comes back UNKNOWN, never "verified human."

VERIFIEDCryptographically or structurally verified against a trust anchor
DECLAREDSelf-asserted by an actor or tool, not independently verified
DETECTEDProduced by an algorithmic detector we ran, with confidence
INFERREDOur own conclusion, derived from combining other evidence
INCONCLUSIVECollection attempted, result ambiguous or contradictory
UNKNOWNThis evidence type is absent or not applicable to this asset
INVALIDEvidence present but failed validation or tampering detected

FAQ: Article 50 & this engine

The full FAQ, plus the code, lives in the repo. Open an issue there if yours isn't covered.

No, and no library can honestly claim that for you. Article 50 requires disclosure, providers marking AI-generated output in a machine-readable format, deployers labeling deepfakes, and so on. Whether a specific piece of evidence satisfies that for your use case is a legal judgment for your team. What this engine does is read the machine-readable signals Article 50 is actually about, C2PA Content Credentials and embedded metadata, and expose them as typed, honestly-labeled evidence relevant to that judgment.

Read the code, not just the pitch.

Star it, fork it, open an issue, or add a provider for a signal we don't cover yet.