About 0byte
Proof of origin that outlives the file.
Every existing way of proving where content came from is carried inside the file — and the internet takes the file apart. We put the proof somewhere it can survive.
# right after your model returns result = client.stamp( image_bytes, provider="acme-ai", model="imagen-x", )
Measured loopback, excluding network. 53 ms at p99.
No account, no key, no rate card. Anyone can check anything.
Append-only and publicly auditable. Entries are added, never edited.
What we believe
The file is not a safe place to keep proof.
Platforms re-encode on upload because it saves bandwidth, and re-encoding does not preserve what it does not understand. Nothing here is an implementation bug — it is how the internet moves pictures.
So the proof has to live outside the file.
A fingerprint derived from what the content looks like, recorded in a public append-only log. It has to be findable from the picture alone, because the picture is all that survives.
Evidence, never a probability.
Absence of evidence is reported as absence of evidence. We finish C2PA and watermarks where they break — we don't guess where they fall silent.
Why now
The marking duty is arriving. The marks don't survive.
Regulation is about to require machine-readable provenance on generated content, and most of the tooling that exists writes it into the one place the internet reliably destroys. Every figure here links to its source.
Where we fit
We finish the other approaches. We don't replace them.
C2PA and watermarking each solve a real part of this. We build for the part of the journey where they come apart — and we report their signals when they survive.
Signed metadata written inside the file.
Stripped the moment a platform re-encodes on upload.
A signal embedded in the pixels themselves.
Covers one vendor's own models, and degrades under re-encoding.
A fingerprint derived from the content, recorded outside the file.
Survives stripping and re-encoding — and reports a C2PA manifest alongside the match when one does live through.
What we don't do
The boundaries we hold by design.
A trust product is defined as much by what it refuses to touch as by what it ships.
We don't store your content
Only the derived fingerprint and the proof metadata. The fingerprint cannot be reversed back into your image.
We don't store prompts
Nothing in the API asks for one — a stamp records the model, the moment and the brand, not the words behind the picture. Neither do we ask for any personal data about the people in your content.
We don't modify your file
Registry stamping derives a fingerprint and leaves the bytes alone. Nothing is injected into the pixels.
We don't guess
Absence of evidence is reported as absence of evidence. A classifier estimate exists in the API, opt-in and never part of a verdict.
Every AI generation should be traceable to its origin.
Not by regulation alone, and not by voluntary pledges — by infrastructure boring enough that using it is the path of least resistance.
