Fully managed C2PA and CAWG
Focus on your core proposition. We handle C2PA and CAWG. A fully managed REST API that creates, edits, and signs C2PA and CAWG manifests for your assets in a single API call.
Three ways to use the SSL Provenance API
Pick the signing model that matches how much of the identity you want to own. Each option below adds durable Content Credentials, with optional watermarking so the credential survives transformations that strip metadata.
SSL.com is the signing entity
SSL.com acts as the C2PA signing entity for your assets. Use this when you want provenance on your content without operating any signing infrastructure or holding a certificate of your own.
SSL.com is the signing entity, with your CAWG identity
SSL.com signs as the C2PA entity, and your organization's identity is asserted through a CAWG certificate compatible with Mozilla SMIME Root Store and the IPTC Verified News Publisher trust list. Use this when your brand needs to appear on the asset but you would rather not take on C2PA conformance.
Your own signing certificate
You sign with your own C2PA certificate, with CAWG identity as an option. This route requires C2PA conformance, and we can accelerate that process. Use this when you need full control of the signing identity.
Optional: durable Content Credentials.
Add watermarking so Content Credentials survive transformations that strip metadata. An imperceptible watermark lets the manifest be recovered even when the embedded metadata is gone.
A conformant CA, in production since 2025
Conformant since 2025
The first publicly trusted certificate authority on the C2PA conformance list, issuing production certificates since 2025.
C2PA Trust List CA
SSL.com's roots are included in the C2PA Trust List, so manifests signed under them validate in conformant viewers.
Dedicated C2PA team
A dedicated C2PA team active in both the C2PA and CAWG working groups.
Top-5 CA by volume
Among the five largest public certificate authorities by volume, issuing millions of certificates and signatures daily.
Built for the transparency deadline
Article 50 disclosure rules became enforceable on 2 August 2026, and the grace period for systems already on the market closes on 2 December 2026. The rules ask for AI output to be marked in a machine-readable format, for that marking to be robust and interoperable rather than reliant on any single method, and for disclosure to reach users at first exposure. Signed C2PA manifests layered with watermarking answer all three. See the EU AI Act guide
Start signing
Request access to the SSL Provenance API
Related products
C2PA Certificates
Sign your own C2PA manifests with a certificate of your own.
Explore C2PA CertificatesCAWG Certificates
Add verified identity attribution inside your C2PA manifest.
Explore CAWG CertificatesC2PA Timestamping
Trusted RFC 3161 timestamps for long-term manifest validation.
Explore Time Stamping