Rūpestėlis Vestigium

Sintetinės medijos įrodymų pasas · L2 Voluntary Club output

PASIRAŠYMAS GALIOJA

Passport ID
MP-UV5SICXEUEWZ
Sigillum seal
VESTIGIUM_EVIDENCE
Signer
rupestelis_holding_uab
Pasirašyta (UTC)
2026-06-14T15:43:47.155505+00:00
Verification mode
exact_canonical

Įrodymų analizė

Atvejis
SAMPLE B — C2PA-signed demo image (test certificate, non-sensitive)
MIME (deklaruota / aptikta)
image/jpeg / image/jpeg
SHA-256 (artifact)
603f505ca36ce74202575bf1e1a4bed3eca9d3bb8749ac865b197fb0807ff597
Failo dydis
35998 baitų
Metaduomenys nuvalyti?
ne
Laiko žymos suderinamumas
consistent
C2PA manifest
yra, bet pasirašytojas nepatikimas (nėra patvirtintos kilmės grandinės)
Signalų pakankamumas
80/100 — kiek nepriklausomų signalų rasta (įrodymų būsena), NE autentiškumo tikimybė
Įrodymų lygis
LOW
Karantino rekomendacija
ne (confidence: high)
Pagrindimas
  • C2PA manifest present but signature did not validate — possibly altered, or an untrusted/expired certificate (a possible, not confirmed, indicator)

Tier 1 operatoriaus sprendimas

Operator ID
Operator tier
Operator trust score
Galutinė rekomendacija
Operator pastabos
(jokių)

Bendraautoriai

Phase 1 apribojimai (skaidrumui)

Pilnas passport JSON (machine-readable)
{
  "document_id": "MP-UV5SICXEUEWZ",
  "timestamp": "2026-06-14T15:43:47.155505+00:00",
  "asset_type": "self_service_evidence_review",
  "sigillum_seal": "VESTIGIUM_EVIDENCE",
  "provenance_data": {
    "case_label": "SAMPLE B — C2PA-signed demo image (test certificate, non-sensitive)",
    "vestigium_id": "VST-HGMYN8NJXGWT",
    "portal": {
      "flow": "self_service_portal_v0.3",
      "mode": "legal",
      "operator_review": "NOT_PERFORMED_AUTOMATED_FLOW",
      "consent": {
        "confirmed": true,
        "purpose": "Technical evidence summary for professional review: what is known, what is uncertain, what cannot be concluded, and the system's own limitations.",
        "recorded_at": "2026-06-14T15:43:47.155505+00:00"
      }
    },
    "input_file": {
      "original_filename": "sample_b_signed.jpg",
      "size_bytes": 35998,
      "sha256": "603f505ca36ce74202575bf1e1a4bed3eca9d3bb8749ac865b197fb0807ff597",
      "declared_mime_type": "image/jpeg",
      "detected_mime_type": "image/jpeg"
    },
    "signals_extracted": {
      "sha256": "603f505ca36ce74202575bf1e1a4bed3eca9d3bb8749ac865b197fb0807ff597",
      "size_bytes": 35998,
      "mime_type": "image/jpeg",
      "declared_mime_type": "image/jpeg",
      "exif": {
        "DateTimeOriginal": "2026:06:12 11:30:00",
        "DateTimeDigitized": "2026:06:12 11:30:00",
        "ImageDescription": "Non-sensitive synthetic demo image for Vestigium Sample B",
        "Make": "ACME",
        "Model": "SampleCam 2 Pro",
        "Software": "ACME Firmware 4.1",
        "DateTime": "2026:06:12 11:30:00",
        "Copyright": "ACME Demo 2026",
        "Artist": "Demo Capture"
      },
      "ffprobe": null,
      "pdf_info": null,
      "c2pa_present": true,
      "c2pa_valid": false,
      "c2pa_manifest": {
        "active_manifest": "urn:c2pa:c3b133da-6707-4918-b643-a23b2bbc32f7",
        "manifests": {
          "urn:c2pa:c3b133da-6707-4918-b643-a23b2bbc32f7": {
            "claim_generator_info": [
              {
                "name": "c2patool",
                "version": "0.26.59",
                "org.contentauth.c2pa_rs": "0.84.1"
              }
            ],
            "title": "Vestigium Sample B demo image",
            "instance_id": "xmp:iid:05f55524-7889-4e2d-8553-3da8c361eb97",
            "thumbnail": {
              "format": "image/jpeg",
              "identifier": "self#jumbf=/c2pa/urn:c2pa:c3b133da-6707-4918-b643-a23b2bbc32f7/c2pa.assertions/c2pa.thumbnail.claim"
            },
            "assertions": [
              {
                "label": "c2pa.actions.v2",
                "data": {
                  "actions": [
                    {
                      "action": "c2pa.created"
                    }
                  ]
                }
              }
            ],
            "signature_info": {
              "alg": "Es256",
              "issuer": "C2PA Test Signing Cert",
              "common_name": "C2PA Signer",
              "cert_serial_number": "640229841392226413189608867977836244731148734950"
            },
            "label": "urn:c2pa:c3b133da-6707-4918-b643-a23b2bbc32f7",
            "claim_version": 2
          }
        },
        "validation_status": [
          {
            "code": "signingCredential.untrusted",
            "url": "self#jumbf=/c2pa/urn:c2pa:c3b133da-6707-4918-b643-a23b2bbc32f7/c2pa.signature",
            "explanation": "signing certificate untrusted"
          }
        ],
        "validation_results": {
          "activeManifest": {
            "success": [
              {
                "code": "claimSignature.insideValidity",
                "url": "self#jumbf=/c2pa/urn:c2pa:c3b133da-6707-4918-b643-a23b2bbc32f7/c2pa.signature",
                "explanation": "claim signature valid"
              },
              {
                "code": "claimSignature.validated",
                "url": "self#jumbf=/c2pa/urn:c2pa:c3b133da-6707-4918-b643-a23b2bbc32f7/c2pa.signature",
                "explanation": "claim signature valid"
              },
              {
                "code": "assertion.hashedURI.match",
                "url": "self#jumbf=/c2pa/urn:c2pa:c3b133da-6707-4918-b643-a23b2bbc32f7/c2pa.assertions/c2pa.hash.data",
                "explanation": "hashed uri matched: self#jumbf=c2pa.assertions/c2pa.hash.data"
              },
              {
                "code": "assertion.hashedURI.match",
                "url": "self#jumbf=/c2pa/urn:c2pa:c3b133da-6707-4918-b643-a23b2bbc32f7/c2pa.assertions/c2pa.thumbnail.claim",
                "explanation": "hashed uri matched: self#jumbf=c2pa.assertions/c2pa.thumbnail.claim"
              },
              {
                "code": "assertion.hashedURI.match",
                "url": "self#jumbf=/c2pa/urn:c2pa:c3b133da-6707-4918-b643-a23b2bbc32f7/c2pa.assertions/c2pa.actions.v2",
                "explanation": "hashed uri matched: self#jumbf=c2pa.assertions/c2pa.actions.v2"
              },
              {
                "code": "assertion.dataHash.match",
                "url": "self#jumbf=/c2pa/urn:c2pa:c3b133da-6707-4918-b643-a23b2bbc32f7/c2pa.assertions/c2pa.hash.data",
                "explanation": "data hash valid"
              }
            ],
            "informational": [],
            "failure": [
              {
                "code": "signingCredential.untrusted",
                "url": "self#jumbf=/c2pa/urn:c2pa:c3b133da-6707-4918-b643-a23b2bbc32f7/c2pa.signature",
                "explanation": "signing certificate untrusted"
              }
            ]
          }
        },
        "validation_state": "Valid"
      },
      "c2pa_manifest_present": true,
      "c2pa_signature_present": true,
      "c2pa_signature_parseable": true,
      "c2pa_signer_trusted": false,
      "c2pa_trust_chain_valid": false,
      "c2pa_validation_status": "C2PA_TEST_CERTIFICATE",
      "c2pa_signer_fingerprint": "640229841392226413189608867977836244731148734950",
      "c2pa_signer_subject": "C2PA Test Signing Cert",
      "c2pa_validation_limitations": [
        "C2PA presence is not proof of authenticity; a validated capture-chain status requires a trusted signer AND a valid trust chain.",
        "C2PA signer is not on the trusted allowlist — this signal does NOT establish trusted provenance and is not a validated capture-chain.",
        "C2PA signer appears to be a developer/test certificate. Test certificates are NOT trusted in production.",
        "C2PA cryptographic trust chain did not validate against a trusted root."
      ],
      "metadata_stripped": false,
      "timestamp_consistency": "consistent",
      "ml_detectors": null,
      "extraction_errors": []
    },
    "signal_sufficiency_score": 80,
    "evidence_level": "LOW",
    "quarantine_recommendation": {
      "recommend_quarantine": false,
      "rationale": [
        "C2PA manifest present but signature did not validate — possibly altered, or an untrusted/expired certificate (a possible, not confirmed, indicator)"
      ],
      "confidence": "high"
    },
    "counter_signals": [
      {
        "code": "C2PA_VALIDATION_FAILED",
        "severity": "material",
        "signal_class": "POSSIBLE_ALTERATION_INDICATOR",
        "detail": "A C2PA manifest is present but its signature did not validate — the manifest may be damaged, altered, or signed by an untrusted/expired certificate. This is a possible (not confirmed) alteration indicator."
      },
      {
        "code": "NO_ORIGINAL_CAPTURE_CHAIN",
        "severity": "material",
        "signal_class": "MISSING_PROVENANCE",
        "detail": "There is no verifiable chain from this file back to an original capture device. Vestigium documents the file as received — events before submission are outside what this passport can attest. This is missing provenance, not evidence of alteration."
      },
      {
        "code": "C2PA_UNTRUSTED_SIGNER",
        "severity": "material",
        "signal_class": "MISSING_PROVENANCE",
        "detail": "Counter-audit: a C2PA manifest is present but the signer is NOT trusted (status='C2PA_TEST_CERTIFICATE'). C2PA presence is not C2PA trust."
      },
      {
        "code": "C2PA_NOT_TRUSTED_FOR_CAPTURE_CHAIN",
        "severity": "material",
        "signal_class": "MISSING_PROVENANCE",
        "detail": "Counter-audit: this C2PA signer does not establish a validated capture-chain (not on the trusted allowlist), so it cannot raise the evidence level."
      }
    ],
    "caad_audit": {
      "layer": "VESTIGIUM_CAAD_v1",
      "framework": "ANTIMATERIJA",
      "domain": "vestigium.evidence",
      "runtime_dependency": false,
      "purpose": "Not to prove success — to prevent false success.",
      "audit_status": "DOWNGRADED",
      "review_required": false,
      "blocked_claims": [],
      "original_evidence_level": "MEDIUM",
      "final_evidence_level": "LOW",
      "counter_signals_added": [
        "C2PA_UNTRUSTED_SIGNER",
        "C2PA_NOT_TRUSTED_FOR_CAPTURE_CHAIN"
      ],
      "checks_run": [
        "R1_no_validated_capture_chain",
        "R2_c2pa_present_but_invalid_overcredit",
        "R2b_c2pa_untrusted_signer_not_capture_chain",
        "R3_missing_counter_signals",
        "R7_video_gap_no_frame_provenance",
        "R4_user_facing_overclaim",
        "R6_score_bounds_and_level_consistency"
      ],
      "findings": [
        {
          "code": "CAAD_R1_NO_VALIDATED_CAPTURE_CHAIN",
          "severity": "critical",
          "action": "DOWNGRADE",
          "rationale": "Evidence level 'MEDIUM' requires a validated original capture chain, but none is present (no C2PA manifest that validates against a trusted certificate). Capped at LOW to prevent false confidence."
        },
        {
          "code": "CAAD_R2B_C2PA_UNTRUSTED_SIGNER",
          "severity": "critical",
          "action": "ADD_COUNTER_SIGNAL",
          "rationale": "C2PA present but not a validated capture-chain (status=C2PA_TEST_CERTIFICATE); added untrusted-signer counter-signals."
        }
      ],
      "antimaterija_signals": [
        {
          "anti_signal_id": "CAAD_R1_NO_VALIDATED_CAPTURE_CHAIN",
          "framework": "ANTIMATERIJA",
          "domain": "vestigium.evidence",
          "severity": "critical",
          "action": "DOWNGRADE",
          "reason": "Evidence level 'MEDIUM' requires a validated original capture chain, but none is present (no C2PA manifest that validates against a trusted certificate). Capped at LOW to prevent false confidence.",
          "runtime_dependency": false,
          "from_level": "MEDIUM",
          "to_level": "LOW"
        },
        {
          "anti_signal_id": "CAAD_R2B_C2PA_UNTRUSTED_SIGNER",
          "framework": "ANTIMATERIJA",
          "domain": "vestigium.evidence",
          "severity": "critical",
          "action": "ADD_COUNTER_SIGNAL",
          "reason": "C2PA present but not a validated capture-chain (status=C2PA_TEST_CERTIFICATE); added untrusted-signer counter-signals.",
          "runtime_dependency": false
        }
      ]
    },
    "mode_guidance": {
      "mode": "legal",
      "label": "Legal",
      "framing": "Technical evidence summary for professional review: what is known, what is uncertain, what cannot be concluded, and the system's own limitations.",
      "signal_sufficiency_meaning": "Signal sufficiency is an evidence-state coverage figure — how many independent signals were present — NOT a probability or percentage that the content is authentic. A high number means rich metadata was found, not that the content is true or real.",
      "technical_evidence_summary": "Signal sufficiency 80/100 (evidence-state coverage — how many independent signals were present, NOT a probability the content is authentic). Evidence level LOW. 4 material counter-signal(s) recorded. Automated v0.3 processing — no operator judgment attached.",
      "what_is_known": [
        "File identity locked: SHA-256 603f505ca36ce74202575bf1e1a4bed3eca9d3bb8749ac865b197fb0807ff597.",
        "Detected file type: image/jpeg (declared by submitter: image/jpeg).",
        "File size: 35998 bytes.",
        "Embedded metadata: present and recorded.",
        "C2PA provenance manifest: present, but the signer is not trusted for validated capture-chain status (C2PA_TEST_CERTIFICATE)."
      ],
      "what_is_uncertain": [
        "Everything that happened to this file before submission is outside the recorded evidence state."
      ],
      "what_cannot_be_concluded": [
        "Whether the content is authentic or synthetic — Vestigium records signals, it does not issue verdicts.",
        "Who created the file, or with what intent.",
        "Whether the file was modified before it was submitted to the portal."
      ],
      "operator_and_system_limitations": "Automated portal flow: no human operator reviewed this case. Scoring is rules-based and inspectable line-by-line; it is one input to professional review, never a substitute for it.",
      "evidence_dossier_structure": [
        "1. Case summary (this passport, JSON + PDF)",
        "2. File identity (SHA-256 hash, size, MIME declared vs detected)",
        "3. Extracted signals (metadata, container, C2PA provenance)",
        "4. Counter-signals (what weakens any conclusion)",
        "5. Limitations (system scope, verbatim)",
        "6. Sigillum Ed25519 seal + verification route"
      ]
    },
    "limitations": [
      "Vestigium does not determine legal truth, does not replace forensic expert review, and does not guarantee court admissibility. It records technical signals, known limitations, and the current evidence state at the time of processing.",
      "This passport was generated by the automated v0.3 self-service portal. No human operator reviewed this case. Operator-reviewed dossiers (single, peer-reviewed, or senior-escalated) are a separate Vestigium service tier.",
      "Vestigium is not a substitute for legal judgment and does not assume the professional liability of a notary, lawyer, court, client, or any other decision-maker. The passport is an evidence document that may be attached to a case file or dossier.",
      "ML detector integration is optional and provider-pluggable; when not configured, this passport carries format-extractor signals only (metadata, container, C2PA provenance, hash identity).",
      "C2PA validation depends on the certificate authority trust chain at the moment of verification — revoked or expired chains may render historically valid signatures unverifiable.",
      "Format heuristics are calibrated for camera-originated media; fully synthetic artifacts may produce no red flags from format extractors alone.",
      "Admissibility of any evidence is always the court's decision."
    ],
    "co_creators": [
      {
        "name": "Claude (Anthropic)",
        "model": "claude-opus-4-7",
        "role": "Spec authorship + main code implementation + Sigillum adapter integration"
      },
      {
        "name": "DeepSeek",
        "model": "deepseek-v3",
        "role": "Constitutional governance gap answers (GAP_ANSWERS_v1.md) + AIST test cases (40 cases)"
      },
      {
        "name": "Grok (xAI)",
        "model": "grok-4",
        "role": "Cross-AI peer review (Concord v0.1) — adversarial scenario audit"
      },
      {
        "name": "GPT (OpenAI)",
        "model": "gpt-5",
        "role": "AIIS v0.9 working code coordination + Sigillum infrastructure cross-check"
      },
      {
        "name": "Tomas Margelis",
        "model": "human",
        "role": "Founding direction + Constitution v1.2 authorship + civic-tech framing + product decisions"
      }
    ],
    "evaluation": {
      "status": "trial",
      "trial": true,
      "credits_total": 3,
      "credits_used_including_this": 1
    }
  },
  "cryptographic_hash": "7732a5de6d0ae836c9fdd239a4b9e043aad1aec28b4c6d9b7329cbaa2afa9a8a",
  "ed25519_signature": "8s9AAoskTlTdzxHz0gJv6A/QRs62aVnqcgMRD16B3cQY3JYnfA7zEhfePGymJ24YdQEtceL4wEMnvtJIai3IDw==",
  "parent_seal_id": "",
  "signer_id": "rupestelis_holding_uab",
  "signed_at": "2026-06-14T15:43:47.155505+00:00",
  "key_id": "sigillum-752f5ab4ad8b3fac",
  "verification": {
    "api_verify_path": "/v1/vestigium/passport/MP-UV5SICXEUEWZ/verify",
    "public_verify_url": "https://verify.rupestelis.com/vestigium/MP-UV5SICXEUEWZ",
    "public_verify_status": "active"
  },
  "verification_url": "https://verify.rupestelis.com/vestigium/MP-UV5SICXEUEWZ"
}