Provenance that travels with the work.
Inverity Provenance binds consent, origin, and ownership to the asset itself so your images carry their own terms wherever they’re copied, recompressed, or scraped. Three layers, built on open standards.
The default is flipping from scrape-freely to consent-by-choice.
For two years the working assumption was that once an image is online, it’s fair game to train on. Standards, law, and platform behavior are now moving the other way and the teams that can prove consent and origin are the ones who’ll be able to license, defend, and trust their libraries.
- 5.9B
- image–text pairs in LAION-5B, gathered with no consent sought
- 96%
- of authors say their consent should be required first
- Aug 2025
- EU AI Act mandates disclosure of training-data sources
- ~$1.5B
- Anthropic settlement: pirated training data carries liability
Figures and rulings from the Inverity thesis, Protecting your images from AI training
Three layers, one asset.
Consent, origin, and ownership are separate problems with separate proofs. Provenance gives each its own layer and each layer states plainly what it does and doesn’t guarantee.
- C2PA training-mining assertion
The do-not-train choice, embedded in the file itself.
- IPTC Data Mining property
A standards-based rights reservation crawlers already parse.
- robots.txt + TDM reservation
The same declaration published at the web layer.
- Signed registry entry
A dated, signed reservation anyone can verify, the difference between “please don’t” and evidence.
AttestSigned provenance
Prove where a file came from and that no one has altered it since.
Explore Attest- C2PA Content Credentials
Cryptographically signed origin, bound to the asset.
- Tamper-evident by design
Any edit after signing breaks the seal, visibly.
- SHA-256 registry + verify page
A public fingerprint check for the exact file.
- Travels on export
The credential leaves the Inverity library with the asset.
SignetForensic watermark
Recognize your image after it has been through the real world.
Explore Signet- Invisible mark
Carried inside Inverity’s own Epiron neural-codec latent.
- Survives redistribution
≈0.99 recovery through JPEG, WebP, resize, screenshot, and social re-encode.
- Survives neural re-encode
0.958 recovery through a full round-trip of Inverity’s codec.
- Single-axis geometry
0.84 through cropping, ≈1.0 through rotation via a blind rotation search on held-out Kodak.
Measured, not asserted.
Every number below is Signet’s forensic recovery on held-out images, the recoverability of the mark, not a claim that anything is prevented.
0.99
Recovery through redistribution
jpeg · webp · resize · screenshot · social
0.025
LPIPS distance
Below the human-visible threshold
0.958
Through a neural-codec round-trip
Survives Inverity’s own Epiron pass
0.84
Crop recovery, single-axis
Rotation recovers to ≈1.0 with search
Measured on the held-out Kodak corpus with BCH-5 recovery. Figures describe forensic recovery, not prevention.
What Provenance proves
- Origin and integrity, cryptographically signed
- Your stated terms: dated, signed, and machine-readable
- Ownership after recompression, resize, screenshot, social, and neural re-encode
- Single-axis crop or rotation survival
What it doesn’t claim
- To stop a model from training on your work
- To poison or corrupt a model that ignores your terms
- To survive deliberate diffusion purification
- To survive simultaneous crop-and-rotate
We’d rather under-promise a shield than sell one that fails when it matters. “A detector that cries wolf is worse than none.”
And a detector that fails safe.
Provenance also ships a membership-inference check: given a model, it estimates whether your image was in its training data. It is designed to fail safe it returns detectable, undetectable, or pending, never a confident false yes.
Provenance is an attribute of the file, not a separate tool.
Every asset in the Inverity library can carry all three layers from the moment it’s uploaded, evaluated continuously, and traveling with the file on every export and delivery.
Questions worth answering straight.
Does Aegis stop AI from training on my images?
No and we won’t pretend otherwise. A do-not-train signal is declarative: it states your terms in the formats crawlers and models are built to read. What makes it matter is that the standards, the cameras, and the courts are converging on honoring it, and a signed, dated reservation turns a scrape into a documented choice to ignore your terms.
Is the Signet watermark visible?
No. It sits at LPIPS 0.025 - below the threshold at which the human eye distinguishes the marked image from the original. It rides inside Inverity’s neural codec rather than being painted on top of the pixels.
Can the watermark be removed?
Ordinary sharing won’t remove it, that’s the whole point, and we measured it. A determined adversary running diffusion purification can strip it, and a simultaneous crop-and-rotate can desynchronize it.
What are Content Credentials (C2PA)?
An open, signed, tamper-evident standard for provenance metadata - now shipping in cameras from Leica, Nikon, and Sony and in tools like DALL·E 3. Attest writes and verifies these credentials for the assets in your library.
Do I have to use the Inverity library?
Aegis and Attest are standards-based and travel with the file wherever it goes. Signet is strongest through Inverity’s own codec path, because that’s where the mark lives - so the forensic layer is best paired with the Inverity library and delivery.
Give your work its terms.
Consent, origin, and ownership - provable and portable