c2pa-route-marker:site-security

More · site security

Site securityScan

See the TLS and security-header posture of c2pa.xenlook.com on one page. We read live response headers and you can re-check on Mozilla Observatory.

  • Can: upload → 5-stage pipeline → certificate, PDF, public serial verify
  • Cannot: Trust List CA listing · legal forensics · public mainnet finality
  • Grades: PipelineScore(A+) ≠ TrustLevel(pilot · NOT LISTED)

Engines: XenLook Observatory SSOT (@xenlook/config), StartupGuard header checklist, Mozilla Observatory API — not a homemade rubric.

Terms: watermark=invisible mark · C2PA=content credentials · closed-chain=permissioned hash chain (not mainnet)

This page is an edge web check (HTTPS + HTTP headers). It is not a C2PA Trust List, WebTrust, or CA issuance audit.

Unified demo · /xmse-demo

Apply for provenance certificate

Upload → 5-stage pipeline (watermark→forensic→fingerprint→C2PA→closed chain) → view certificate and save PDF — all on this page.

  1. 1Select image
  2. 2Run pipeline
  3. 3Receive certificate

Drag-and-drop · mobile camera · min side 256px

View sample A+ certificate · Sample PDF · Verify serial · Agency checklist · Demo · /xmse-demo · Adobe Inspect

Glossary

Watermark
Invisible ownership mark; may survive mild recompression.
C2PA
Content Credentials standard. This pipeline sign is pilot — not Trust List CA.
Closed chain
XenLook permissioned hash chain — not ETH/XRP/SOL mainnet finality.
PipelineScore
5-stage pass grade — not external trust listing.
TrustLevel
Currently pilot (NOT LISTED on Trust List CA).

Can / Cannot (vs market)

ItemXMSETop-tier Credentials
5-stage issue+PDFYesYes
Public serial verifyYesYes
Trust List CANo (pilot)Vendor-dependent
Public mainnet finalityNo (closed chain)Vendor-dependent
Adobe Inspect trustLimited (pilot)Strong

Security strengths

Defense layers on the public portal surface — while the CA itself remains a disclosed pilot.

HTTPS everywhere with HSTS to block plaintext downgrades.

Content-Security-Policy constrains script and frame origins.

MIME sniffing, Referrer, and Permissions policies shrink browser-side risk.

Anyone can re-verify independently on Mozilla Observatory.

This portal (c2pa.xenlook.com) header probe

Observatory header checklist for this CA portal origin — separate from the domain scanner above.

Gap

HSTS

Strict-Transport-Security keeps browsers from falling back to HTTP.

Gap

Content-Security-Policy

Limits which origins may load scripts and other resources.

Gap

X-Content-Type-Options

nosniff blocks MIME-confusion execution.

Gap

X-Frame-Options

SAMEORIGIN blocks clickjacking frames.

Gap

Referrer-Policy

Reduces referrer URL leakage to third parties.

Gap

Permissions-Policy

Restricts default exposure of sensitive browser APIs.