Can you verify where this asset came from?
Custody is the public name for Chain of Custody: how completely and coherently a file's origin, editing history, and rights are documented through its own embedded metadata, not through what anyone claims about it after the fact.
What it reads
Only the file's own metadata: EXIF camera data, XMP editorial fields, IPTC copyright fields, and a C2PA manifest if one exists. A field that is not present is scored as missing.
How many of the expected provenance fields are populated with meaningful values, versus present but left blank.
Whether the populated fields tell a consistent story: capture date matches GPS timestamp, camera model matches image properties.
How clearly copyright holder, creator identity, usage license, and expiry are expressed in the embedded fields.
Whether a cryptographic or institutional trust anchor exists, a C2PA manifest, an IPTC digital fingerprint, a watermark signature, to verify the claimed origin.
What it doesn't do
Handles missing C2PA data appropriately
C2PA adoption is still uneven. A file that predates it, or comes from a source that hasn't implemented it, scores custody verifiability at a neutral midpoint, not a hard fail.
Does not fill in missing metadata
Only what is embedded in the file counts. A gap in the metadata shows up as exactly that: a gap.
Works across standard metadata formats
EXIF, XMP, IPTC, and C2PA are each read on their own terms, whichever combination the file carries.
Where it shows up
Legal and compliance
Custody feeds directly into the C2PA and rights-clarity clauses in the compliance record.
See the compliance record
How Custody's four dimensions map onto the 24-clause regulatory check.
See the full formula
How Custody combines with the other four signals into the single IQ Score.
Find out what your file's own metadata can prove
EXIF, XMP, IPTC, and any C2PA manifest, read directly and scored.
Get early access