Pilot · KR Mar 2027 · JP Jun 2027

In the age of generative AI,
what's real
we prove

Check if a photo, video, audio, or document is real — and where it came from. No install.

Content Credentials (C2PA) are a source sticker inside photo and video files. XenLook is the CA portal that issues and verifies them.

C2PA Trust List & Generator under review — pilot until listed · KR→JP.

New here?

You don’t need to know C2PA

An open standard for attaching a provenance record inside AI images, video, music, and documents—like an ingredients label. Inspect that record below; companies can apply for signing certificates.

  • Everyone: upload a file above to check for missing or broken provenance
  • Companies/developers: apply for a certificate used to sign content (pilot · manual review)
  • Important: we are a pre–Trust List pilot. Some tools (e.g. Adobe) may show untrusted—that is expected before listing.

Who it's for

Provenance by industry

News, AI, broadcast, platforms, K/J — SSL.com use cases, Asia-first CA.

Right now · Evidence

Verify the file and read the manifest

Drop a file to see whether a provenance record exists and whether the file changed. Next to it is the manifest—the ingredients label inside the file.

Drop a file to check

or click to browse

JPEG · PNG · WebP · MP4 · MP3 · M4A · PDF

Try with XenLook samples

How · Samples

From provenance sticker to real signatures

① Attach a record ② Seal with a certificate ③ Anyone can inspect. You don’t need the jargon—just the flow.

01

1. Think of a digital source sticker

C2PA-saved files carry a small record. Compatible apps can read who made it, AI use, and who signed. Experts call that record a manifest.

02

2. Why a certificate?

Anyone could type a claim without a seal. A certificate is the signer’s ID. With a XenLook-issued ID, generators can attach a trustworthy label.

03

3. Never send your private key

Keys stay on your machine. You only send a request (CSR). If a key is stolen, tell us — we can revoke the certificate.

Photo

Signed still (WebP)

Generator conformance still — a source record is embedded. WebP is not ‘just a picture’.

Verify
Video

Signed video clip (MP4)

Landing-preview H.264 with an embedded source record. Play it, then inspect it.

Verify
Audio

Signed soundtrack (M4A)

Same path as chronicle OST audio — stickers aren’t only for images.

Verify
PDF →Document

Signed PDF gate document

The same standard applies to documents — contracts, releases, reports.

Verify

Status · Experts

Where we are — honestly

Honestly: XenLook is a Korea pilot CA. We are not yet on the official C2PA Trust List. Signing and verify here work for learning/pilot; global ‘trusted’ display (e.g. Adobe) comes after listing.

  • Korea pilot CA — C2PA Trust List review in progress
  • CPS v1.0 published · Republic of Korea governing law
  • 12-market locale support
  • APAC KR (Mar 2027) · JP (Jun 2027) roadmap

SSL.com 12-pattern check

  • Mission headline
  • Hero + CR pin
  • Drag-drop verify
  • Four media
  • Use cases + wizard
  • Trust List (gap)
Compare with SSL.com

Experts & operations (optional)

Issuance, transparency, programs — skip if you only want to check a file

CA pilot

Generator

Composite trust score

CRL

Portal actions

C2PA Trust List & Generator under review — pilot until listed · KR→JP.

Two programs on this site

XenLook runs both a Certificate Authority (issues signing IDs) and a Generator product (signs media). This section shows live status for each.

CA Program

C2PA Certification Authority

Issues claim-signing certificates so tools can attach Content Credentials to files.

Agreement executed
Phase
Trust List
Not listed (intake pending)
Generator Program

XMSE

Signs AI-generated media in production (XMSE) and supplies conformance evidence to C2PA.

RFI submitted
Assurance
AL1 ·

XenLook operates C2PA Certification Authority and Generator Product programs under executed agreements (2026-06-13). Trust List and CPL listing are not claimed until C2PA confirms.

Pre–Trust List operations. Tests validate issuance, revocation, and signing pipelines. Public marketing must not claim Trust List membership until C2PA confirms listing.