Verify — Content Credentials
Validates the C2PA manifest store of a file with the open verifier, inside this tab, offline. A valid manifest says who signed what and when; it does not say the picture is true.
Verify a signed analysis report (.pvm)
Drop the .pvm exported from /report — and, to check it belongs to a picture, the original file alongside it. The signature is checked with the public key carried in the manifest (Rev E §6.1: integrity since signing, not identity).
Trust list: Content Authenticity Initiative interim anchors (frozen) — a signer outside it is reported as an unknown signer, not as a forgery. Remote manifests and revocation are not fetched. Verifier source: packages/silicoveritas-verify (Apache-2.0).