01

What EXIF is for

EXIF commonly describes camera settings, time, orientation and GPS. It is useful for photography and file organization, but ordinary EXIF fields do not provide cryptographic tamper evidence.

Key points
  • Camera and lens
  • Exposure settings
  • Capture time
  • Orientation
  • Optional GPS
02

What C2PA adds

C2PA can bind signed claims and assertions to an asset. A manifest may describe actions, ingredients, the claim generator and digital source type, while validation checks linked data and signatures.

Key points
  • Signed claim
  • Validation status
  • Actions and ingredients
  • Signer and trust context
  • Possible remote manifest references
03

How to use both

Start with ordinary metadata for practical file and privacy facts. Check Content Credentials when provenance matters. Keep the results separate: valid credentials do not prove the visible event, and missing credentials do not make an image fake.

04

Know which layer can answer your question

Use EXIF for camera model, exposure, capture time, orientation and optional GPS. Use C2PA for signed provenance claims, actions, ingredients and validation status. Both may be present, either may be absent, and their data can describe different moments in the asset’s history.

A signed claim can include or reference ordinary metadata, but that does not turn every EXIF field everywhere into cryptographically protected evidence.

Key points
  • EXIF: descriptive and editable
  • C2PA: signed claim and assertions
  • Hash: byte identity
  • Context: meaning outside the file
05

What the six combinations reveal

The test varied the layers independently so the interface could not assume that a file with EXIF has credentials or that verified credentials require visible EXIF. Invalid credentials also remained separate from ordinary metadata findings.

The final combination is important: a later signed claim can describe an edited derivative without proving what happened before that history began. Read the actions and ingredients rather than treating the presence of a signature as a complete biography.

06

Build an evidence bundle instead of a verdict

For a serious review, keep the original file, calculate its hash, export the C2PA validation report and record relevant EXIF fields with their raw paths. Note the source and acquisition time outside the file.

For ordinary users, the simpler rule is enough: inspect privacy fields with the metadata viewer, inspect credentials with the C2PA checker, and read the limitations shown by each tool before drawing a conclusion.

What this does not prove

A metadata result describes the fields and structures that the supported parser could read. It does not, by itself, prove authenticity, intent, authorship or the truth of the visible scene.

Sources