HTTPS everywhere with HSTS to block plaintext downgrades.
More · site security
Site securityScan
See the TLS and security-header posture of c2pa.xenlook.com on one page. We read live response headers and you can re-check on Mozilla Observatory.
- Can: upload → 5-stage pipeline → certificate, PDF, public serial verify
- Cannot: Trust List CA listing · legal forensics · public mainnet finality
- Grades: PipelineScore(A+) ≠ TrustLevel(pilot · NOT LISTED)
Engines: XenLook Observatory SSOT (@xenlook/config), StartupGuard header checklist, Mozilla Observatory API — not a homemade rubric.
Terms: watermark=invisible mark · C2PA=content credentials · closed-chain=permissioned hash chain (not mainnet)
Apply for provenance certificate
Upload → 5-stage pipeline (watermark→forensic→fingerprint→C2PA→closed chain) → view certificate and save PDF — all on this page.
- 1Select image
- 2Run pipeline
- 3Receive certificate
Drag-and-drop · mobile camera · min side 256px
View sample A+ certificate · Sample PDF · Verify serial · Agency checklist · Demo · /xmse-demo · Adobe Inspect
Glossary
- Watermark
- Invisible ownership mark; may survive mild recompression.
- C2PA
- Content Credentials standard. This pipeline sign is pilot — not Trust List CA.
- Closed chain
- XenLook permissioned hash chain — not ETH/XRP/SOL mainnet finality.
- PipelineScore
- 5-stage pass grade — not external trust listing.
- TrustLevel
- Currently pilot (NOT LISTED on Trust List CA).
Can / Cannot (vs market)
| Item | XMSE | Top-tier Credentials |
|---|---|---|
| 5-stage issue+PDF | Yes | Yes |
| Public serial verify | Yes | Yes |
| Trust List CA | No (pilot) | Vendor-dependent |
| Public mainnet finality | No (closed chain) | Vendor-dependent |
| Adobe Inspect trust | Limited (pilot) | Strong |
Security strengths
Defense layers on the public portal surface — while the CA itself remains a disclosed pilot.
Content-Security-Policy constrains script and frame origins.
MIME sniffing, Referrer, and Permissions policies shrink browser-side risk.
Anyone can re-verify independently on Mozilla Observatory.
This portal (c2pa.xenlook.com) header probe
Observatory header checklist for this CA portal origin — separate from the domain scanner above.
HSTS
Strict-Transport-Security keeps browsers from falling back to HTTP.
…
Content-Security-Policy
Limits which origins may load scripts and other resources.
…
X-Content-Type-Options
nosniff blocks MIME-confusion execution.
…
X-Frame-Options
SAMEORIGIN blocks clickjacking frames.
…
Referrer-Policy
Reduces referrer URL leakage to third parties.
…
Permissions-Policy
Restricts default exposure of sensitive browser APIs.
…
How this relates to the CA
Site security asks how hardened this website is. Certificate issuance, revocation, and Trust List status are published separately on Transparency and Practices.