We build three layers of security into every photo, and check originality in two independent ways.
Triple security — three secret keys
The OriPics certification process applies three key values that can never be known from outside.
① Digital fingerprint (steganography)
At the moment of certification, an invisible watermark is embedded into the image pixels themselves. It's not a tag attached to the file — it's a signature woven into the picture, so changing even a single pixel is instantly detected. (Dual-hash structure, patent pending)
② Server signature
The capture/certification time, GPS coordinates, and resolution are signed and recorded by the OriPics server. They cannot be altered afterwards — unlike EXIF metadata, which anyone can edit.
③ Device verification (Verified)
For mobile camera certification, iOS App Attest / Android Play Integrity let Apple and Google confirm that a genuine app on a real device certified the photo at capture time. A hardware-key seal at the shutter moment also catches file swaps between capture and certification.
Dual certification — two independent layers of protection
Every OriPics-certified image carries two verification systems built on different principles.
Pixel-level
OriPics native certification
• The fingerprint lives inside the pixels — it survives format conversion and metadata stripping
• As long as the pixels are intact it stays verifiable — even a 1-pixel change is detected
• Time and GPS are fixed by the server signature
International standard · file-level
C2PA Content Credentials
• The content-provenance standard led by Adobe, Microsoft and Sony (ISO/IEC 21617)
• Signs the whole file — provenance can be checked in any standards-compliant tool
• Seals metadata too — tampering leaves standard, visible traces
Each layer covers for the other
✓ If someone re-saves the file and breaks the C2PA signature — the pixels still verify as original through OriPics.
✓ If you need verification inside the standards ecosystem (Adobe etc.) — the C2PA credential does that job.
✓ If EXIF is manipulated — time and location rest on signed records, so they can't be faked. OriPics still confirms originality from the pixels, and C2PA detects that the file itself was altered.
Anyone can verify, in 3 seconds
1
Open the public link — no app, no sign-up required
2
Capture time, location and originality are shown instantly
3
Got the file directly? Drag it onto ori.pics for instant verification
An internationally validated approach
✓ OriPics is a C2PA Conformant product — listed on the official conforming-products list alongside Google and Qualcomm, and the only consumer (B2C) service from Korea.
✓ The core verification algorithm (dual-hash steganography) is patent pending.
✓ The Verified tier runs on hardware-backed attestation from Apple (App Attest) and Google (Play Integrity).