ProvSeal Security

Security & Trust

How ProvSeal handles files, certificates, page content and trust decisions. Designed for local-first provenance and integrity workflows.

Local-first by design

Verification and signing workflows are designed to run locally, without uploading your files to a ProvSeal backend.

Local processing

ProvSeal processes supported media files directly in the local extension environment.

No backend upload

Verification and signing workflows are designed to run locally, without uploading your files to a ProvSeal backend.

Explicit actions only

The extension may read selected local files, visible media on the current tab, and signing material that you explicitly import or generate.

Zero data exfiltration by design

Selected media stays in the browser context for the requested verify, inspect or sign action.

File handling

When you select or drop a file into the extension, the file is used only for the requested action: verify, inspect, or sign.

ProvSeal does not use your files for advertising, profiling, training, or unrelated analytics.

Certificates and private keys

C2PA signing requires a certificate and private key. ProvSeal supports test certificates for development and demo workflows, and may support imported signing material such as .p12 or .pfx files.

Test certificates are not public trust

A test certificate is useful for learning, demos and internal validation. It can show how a C2PA signing workflow works, but it does not mean the signature is publicly trusted.

For production trust, organizations should use certificates issued through the C2PA trust ecosystem.

How trust status is displayed

Status labels explain available evidence in the extension UI. They are not truth verdicts.

Trusted

The media contains valid Content Credentials and the certificate chain is recognized by the configured trust sources.

Signed but untrusted

The media contains a cryptographically valid signature, but the certificate is not recognized as publicly trusted.

Invalid

The media contains C2PA data, but integrity or signature validation failed.

No credentials

No C2PA evidence was detected. This does not mean the content is fake.

Extension permissions

ProvSeal requests only the permissions needed to provide its core features: file verification, local signing, page media scan, context menu actions, download of signed files, and local settings.

Page Scan File Download Local Storage Context Menu

Permissions are not used for advertising, tracking, profiling, or unrelated browsing history collection.

Limited Use disclosure

The use of information received from extension permissions adheres to applicable store User Data Policy requirements, including Limited Use.

User data is used only to provide and improve the extension's single purpose: local C2PA Content Credentials signing, verification and page media analysis.

Compliance verified

Content Authenticity Initiative

ProvSeal is a member of the Content Authenticity Initiative (CAI), a community supporting digital content provenance and transparency. This membership is separate from the C2PA Conformance Program and does not constitute certification of ProvSeal.

Next steps

Install the free extension, explore Enterprise local signing, or read the full documentation.