The material we produce is signed. Embedded inside every file — a video, an image, an audio piece — is a content credential stating who made it, when, and whether it has been altered since. It is an open standard called C2PA Content Credentials, used by Adobe, Leica, Sony and OpenAI among others.
This page explains what that content carries, how you can check it yourself without relying on us, and who to write to if something does not add up.
For two reasons that reinforce each other.
The first is yours: when you publish a piece of ours, you can demonstrate where it came from. If someone crops it, alters it or attributes it to another party, the credential stops adding up — and that is verifiable.
The second is legal. Article 50 of the European Union’s AI Act requires content that has been generated or manipulated with AI to be identified as such. Our deliveries declare whether they were generated with AI, whether they are a hybrid of AI and real material, and whether they were edited afterwards. Not in a separate document: inside the file itself.
You do not need to ask us, or take our word for it. That is precisely the point.
It works with any C2PA-compatible verifier, not only that one. And it works without us: no Arteria server is consulted behind the scenes.
Worth knowing exactly, because it travels inside the file you are going to publish and anyone who downloads it can read it.
| Who signs | Medios en Red Digital Agency S.L. (Arteria) and somosarteria.es |
|---|---|
| Client and project | The name by which we identify the work internally. If you would rather it did not appear, or appeared differently, tell us before delivery |
| Responsible party | The role and initials of the signer. Never an individual’s full name |
| Content origin | Whether it is AI-generated, hybrid, and whether it was edited after generation |
| Intended channels | What medium it was produced for: social, paid campaign, television, web, print |
| Timestamp | The date and time of signing, certified by an independent authority |
| File fingerprint | A cryptographic digest that changes if any part of the content is altered |
| Thumbnail | A reduced preview, so the original is recognisable |
What it does not contain: no employee full names, no contact details, no information about you beyond the project name, no location, and nothing about your systems or ours. There is no tracking and no analytics: the credential is static data inside the file and calls no server.
When we start from material that already carried its creator’s signature — a stock image, a piece from an AI tool — we do not erase that signature: we preserve it inside ours, chained. So you can follow the trail all the way back to the origin, not only as far as us.
Alongside the signed files we provide a PDF detailing the certification: the cryptographic fingerprint of each piece, the certificate used, and instructions for verifying it.
That PDF is not the proof. The file is the proof. The document only describes what the file already demonstrates by itself, and gives you the details to check it.
We sign with our own tool, Arteria Sign. If you find a security flaw, a conformance problem with the C2PA standard, or a signature of ours that does not validate as it should, we want to hear about it.
This address is monitored during business hours and we acknowledge receipt within 5 working days. It helps if you tell us which file is involved — the file itself, or its SHA-256 fingerprint, which appears on the delivery record — and what you expected versus what you saw.
If the problem affects the tool’s conformance with the standard, we also notify the C2PA Conformance Program.