Inverity

Provenance that travels with the work.

Inverity Provenance binds consent, origin, and ownership to the asset itself so your images carry their own terms wherever they’re copied, recompressed, or scraped. Three layers, built on open standards.

The default is flipping from scrape-freely to consent-by-choice.

For two years the working assumption was that once an image is online, it’s fair game to train on. Standards, law, and platform behavior are now moving the other way and the teams that can prove consent and origin are the ones who’ll be able to license, defend, and trust their libraries.

5.9B
image–text pairs in LAION-5B, gathered with no consent sought
96%
of authors say their consent should be required first
Aug 2025
EU AI Act mandates disclosure of training-data sources
~$1.5B
Anthropic settlement: pirated training data carries liability

Figures and rulings from the Inverity thesis, Protecting your images from AI training

Three layers, one asset.

Consent, origin, and ownership are separate problems with separate proofs. Provenance gives each its own layer and each layer states plainly what it does and doesn’t guarantee.

AegisDo-not-train signal

State your terms in a way machines are built to read.

Explore Aegis
  • C2PA training-mining assertion

    The do-not-train choice, embedded in the file itself.

  • IPTC Data Mining property

    A standards-based rights reservation crawlers already parse.

  • robots.txt + TDM reservation

    The same declaration published at the web layer.

  • Signed registry entry

    A dated, signed reservation anyone can verify, the difference between “please don’t” and evidence.

AttestSigned provenance

Prove where a file came from and that no one has altered it since.

Explore Attest
  • C2PA Content Credentials

    Cryptographically signed origin, bound to the asset.

  • Tamper-evident by design

    Any edit after signing breaks the seal, visibly.

  • SHA-256 registry + verify page

    A public fingerprint check for the exact file.

  • Travels on export

    The credential leaves the Inverity library with the asset.

SignetForensic watermark

Recognize your image after it has been through the real world.

Explore Signet
  • Invisible mark

    Carried inside Inverity’s own Epiron neural-codec latent.

  • Survives redistribution

    ≈0.99 recovery through JPEG, WebP, resize, screenshot, and social re-encode.

  • Survives neural re-encode

    0.958 recovery through a full round-trip of Inverity’s codec.

  • Single-axis geometry

    0.84 through cropping, ≈1.0 through rotation via a blind rotation search on held-out Kodak.

Illustration. Signet spreads a redundant payload across the frame, so cropping or resizing removes some copies but not all. The delivered image looks identical to the original at LPIPS 0.025, below the human-visible threshold.

Measured, not asserted.

Every number below is Signet’s forensic recovery on held-out images, the recoverability of the mark, not a claim that anything is prevented.

0.99

Recovery through redistribution

jpeg · webp · resize · screenshot · social

0.025

LPIPS distance

Below the human-visible threshold

0.958

Through a neural-codec round-trip

Survives Inverity’s own Epiron pass

0.84

Crop recovery, single-axis

Rotation recovers to ≈1.0 with search

Measured on the held-out Kodak corpus with BCH-5 recovery. Figures describe forensic recovery, not prevention.

What Provenance proves

  • Origin and integrity, cryptographically signed
  • Your stated terms: dated, signed, and machine-readable
  • Ownership after recompression, resize, screenshot, social, and neural re-encode
  • Single-axis crop or rotation survival

What it doesn’t claim

  • To stop a model from training on your work
  • To poison or corrupt a model that ignores your terms
  • To survive deliberate diffusion purification
  • To survive simultaneous crop-and-rotate

We’d rather under-promise a shield than sell one that fails when it matters. “A detector that cries wolf is worse than none.”

And a detector that fails safe.

Provenance also ships a membership-inference check: given a model, it estimates whether your image was in its training data. It is designed to fail safe it returns detectable, undetectable, or pending, never a confident false yes.

detectableundetectablepending

Provenance is an attribute of the file, not a separate tool.

Every asset in the Inverity library can carry all three layers from the moment it’s uploaded, evaluated continuously, and traveling with the file on every export and delivery.

Questions worth answering straight.

Does Aegis stop AI from training on my images?

No and we won’t pretend otherwise. A do-not-train signal is declarative: it states your terms in the formats crawlers and models are built to read. What makes it matter is that the standards, the cameras, and the courts are converging on honoring it, and a signed, dated reservation turns a scrape into a documented choice to ignore your terms.

Is the Signet watermark visible?

No. It sits at LPIPS 0.025 - below the threshold at which the human eye distinguishes the marked image from the original. It rides inside Inverity’s neural codec rather than being painted on top of the pixels.

Can the watermark be removed?

Ordinary sharing won’t remove it, that’s the whole point, and we measured it. A determined adversary running diffusion purification can strip it, and a simultaneous crop-and-rotate can desynchronize it.

What are Content Credentials (C2PA)?

An open, signed, tamper-evident standard for provenance metadata - now shipping in cameras from Leica, Nikon, and Sony and in tools like DALL·E 3. Attest writes and verifies these credentials for the assets in your library.

Do I have to use the Inverity library?

Aegis and Attest are standards-based and travel with the file wherever it goes. Signet is strongest through Inverity’s own codec path, because that’s where the mark lives - so the forensic layer is best paired with the Inverity library and delivery.

Give your work its terms.

Consent, origin, and ownership - provable and portable