Prove a photo is real, instead of guessing.
Generated and edited images now look exactly like real ones. VCAP seals a photo or video the moment it is taken, in the phone's secure hardware, so any later change, by AI or by hand, breaks the seal.
Yes — this file is what it says it is.
- Sealed in hardwareThe key never leaves the phone.
- Checked in the browserThe file is never uploaded.
- No account neededTo capture or to verify.
- Open formatPublic specification, MIT.
Detectors guess. A seal does not.
An AI detector looks at pixels and returns a probability, and every new model makes it less sure. VCAP turns the question around: real captures carry proof of where they came from, so nobody has to judge the pixels.
A valid seal proves
- These exact bytes came from a camera app on a phone.
- They were signed with a key inside its secure hardware.
- Nothing changed since: no filter, no retouch, no generative edit.
It does not claim
- That the scene was real: a sealed photo of a screen is a sealed photo of a screen.
- Who was holding the phone.
- That a file without a seal is fake. It is not accused of anything.
Three steps on the device, before the file goes anywhere.
Signed at capture
The file's hash is signed with a key generated inside the phone's secure hardware. The proof travels inside the file itself.
Marked in the pixels
An invisible watermark carries the capture's identifier. When a platform strips the proof and recompresses the file, the mark can still point back to the original.
Checked by anyone
Drop the file on the verifier. Everything runs in the browser, and the answer comes back in plain words.
A clear answer, in plain words.
Each answer is a word from the specification with one sentence beside it, exactly as the verifier prints them.
Yes — this file is what it says it is.
In part — these are signed frames of a longer recording.
No — this file changed after it was sealed.
This file carries no proof.
A seal checks out with no request to us: the verifier and the format specification are public and MIT licensed. When the proof was stripped, the verifier may still read the invisible mark, and says plainly that a mark alone is not a verdict of authenticity.
For anyone who has to rely on a photo taken by someone else.
Insurers, newsrooms, inspectors. Your devices capture with VCAP, and the console adds evidence on top of the seal, each piece labelled with where it comes from.
Devices
Registered to your organization, with keys you can revoke.
Trusted time
From an RFC 3161 timestamp authority, checked by the verifier on its own.
Transparency log
Every registered capture, anchored on a public chain.
Encrypted vault
Originals stored with keys that belong to you, not to us.
Captures and cases
One console, with a verifier that also reads your records.
SDKs
Android, iOS, React Native and the web, to seal inside your own app.
Access is by invitation while VCAP is in development.