◈ ABOUT VERIMAGO

Content provenance for a transparent internet.

Verimago builds the certificate infrastructure that gives every photo and video a clear, cryptographic label — Authentic, AI-Enhanced, AI-Generated, or Unverified — so audiences always know exactly what they're looking at.

Leadership

Founder & CEO
JC Collingwood

Founded Verimago to give publishers, creators, and audiences cryptographic proof of what media is — Authentic, AI-Enhanced, or AI-Generated — at the moment of capture.

Company
Verimago LLC

Official Certificate Authority for Content Credentials under the C2PA Conformance Program. Contact for partnership and press: [email protected].

linkedin.com/company/verimago →

Founded on a principle

Verimago was founded by JC Collingwood (Founder & CEO) on the belief that audiences deserve to know what they're looking at. As AI-generated and AI-enhanced media become indistinguishable from authentic footage, we set out to build the cryptographic infrastructure the information ecosystem was missing — not to restrict AI, but to label it clearly.

The technology

We use elliptic-curve cryptography with FIPS 140-3 Level 3 hardware security modules for certificate infrastructure, and your phone’s Secure Enclave (Apple) or StrongBox (Android) for capture-time signing. App Attest and Play Integrity prove the signing happened on a real, unmodified device. The result is an HSM-backed C2PA Content Credential embedded in every photo and video.

The registry

Every signed photo and video gets a manifest published to the Verimago registry — a permanent, publicly auditable record. Anyone can verify any piece of media in seconds by entering its SHA-384 hash at registry.verimago.io. The manifest includes the content classification so audiences see the full picture.

How Verimago certificates work

The same chain-of-trust model used by SSL certificates — applied to media authenticity.

Step 01
🏛️

Identity verification

We verify editorial independence, domain ownership, and jurisdiction — the same standard as Extended Validation SSL.

Step 02
🔑

Key ceremony

A witnessed ceremony generates signing keys. Private keys are sealed in FIPS 140-3 Level 3 hardware security modules and never exported.

Step 03
📷

Sign at capture

The Verimago app and signing tool create a cryptographic manifest the moment media is captured or published — before any edits.

Step 04
🔍

Verify anywhere

Anyone can verify any photo or video by entering its SHA-384 hash at registry.verimago.io. Verification is instant and free.

Four content classifications

Verimago is not anti-AI — it's pro-transparency. We support every type of content; we simply ensure audiences know what they're looking at.

Each certified piece of media carries one of these four states.

Authentic

Original, unaltered content. No AI modifications applied. A real recording of real events.

AI-Enhanced

Real content processed with AI tools — noise reduction, upscaling, color grading, background blur. The underlying event is real; AI processing was applied.

AI-Generated

Fully or substantially generated by AI. Not a recording of real events — generative AI, CGI, synthetic media, AI avatars.

Unverified

No Verimago certificate. Content origin and authenticity are unknown.

Security & credentials

Verimago certificates follow the same class of public-key infrastructure used for HTTPS on the web. Certificate Authority keys are generated in a witnessed ceremony and held in FIPS 140-3 Level 3 certified hardware security modules. Certificate status is published for public verification.

Verimago has been approved by the C2PA Conformance Program as an official Certificate Authority for Content Credentials. That approval is public: Verimago Root CA and Claim Signing Issuing CA appear on the official C2PA Trust List — the same registry used by DigiCert, SSL.com, Google, Adobe, and a short list of other authorities. We do not publish private conformance correspondence; the Trust List is the public record.

Official Certificate Authority
Approved under the C2PA Conformance Program — see the announcement and live Trust List
HSM-backed keys
FIPS 140-3 Level 3 hardware security modules for CA infrastructure; Secure Enclave / StrongBox for capture-time signing
C2PA Contributor Member
Official contributor member of the Coalition for Content Provenance and Authenticity
Public registry
registry.verimago.io — every manifest is permanently, publicly auditable

Helpful links

Standards, public trust lists, and Verimago resources. Partner and integration links will appear here as they launch.

Standards & trust

At Verimago

Ready to give your audience full transparency?

Apply for a certificate and let your audience see exactly what your content is — Authentic, AI-Enhanced, or AI-Generated — with cryptographic proof.

Get your credential →View pricing