Drop a StateNull sealed photo, scan or PDF — or a proof bundle. Everything is checked in this page with pure cryptography: the content hash, the device signature, the certificate chain to StateNull's root, and the transparency log. Nothing is uploaded. There is no server. You don't trust StateNull — you check the math.
💻 Prefer a sovereign desktop app? Download the offline Windows verifier — runs on your own machine, no install beyond built-in Microsoft Edge.
The proof travels inside the file. This page recomputes its hash, verifies the device's signature, and validates the certificate chain to StateNull's root — proving it's a genuine, unaltered capture, entirely offline.
The transparency-log proof: the record commits to the hash, hashes to the exact Merkle leaf, the RFC-6962 path rebuilds the signed root, and the tree head is signed by the log's key. Portable — it still verifies years from now.
C2PA is the open industry standard — Adobe, Google, Microsoft, OpenAI, Sony, the BBC and more — that attaches a signed “who · what · when” label to a file at creation. It's powerful, but it lives in metadata a screenshot or re-upload can strip, and it proves origin, not truth. StateNull can embed a real C2PA 1.3 credential of its own into the JPEG on export — an opt-in setting — signed by a StateNull claim-signer certificate that is not on the public C2PA trust list and holds no conformance listing, so stock validators report the manifest as valid but from an unknown source — and StateNull adds this independent, offline-provable registry, so your provenance survives even when the label is gone. How StateNull closes the C2PA gap → · ▶ Watch the explainer →