Blog

Provenance and digital integrity.

Standards, regulation, trust models, and the practical problems of governing provenance at scale.

Why C2PA Needs Policy-Based Governance

The SDK signs a file. It does not decide who was allowed to sign, under which policy, with which credential, or whose signatures your systems should accept — and those are the questions that decide whether provenance means anything.

Andrew Brown · Sep 2, 2026

You Cannot Sign a File by Changing It

Embedded provenance has a circular dependency at its core, and the exclusion range is the workaround. A formal analysis of C2PA shows what the workaround costs — and why provenance that modifies the canonical artifact is the wrong default.

Jeff Hantin · Aug 31, 2026

On the Internet of Authenticity, who makes the trust decisions?

The cryptography is finished. What nobody has settled is who decides a signer deserves belief — and the standards say so outright, leaving every verifier to keep its own list.

Andrew Brown · Aug 24, 2026

A Mark Is Not a Signature

Invisible watermarks are becoming the default answer for text provenance. A mark can be robust or it can be binding, never both — and the trust question underneath is the one SSL left unanswered for twenty years.

Jeff Hantin · Aug 17, 2026

Is Provenance Rediscovering XML Signature?

Every hard problem in content provenance — signing text, signing an excerpt, multi-party workflows, selective disclosure — was solved once, then deliberately thrown away. The industry is rebuilding those primitives without the scar tissue that came with them.

Jeff Hantin · Aug 10, 2026

What a Signed Article Actually Proves

A plain guide to content provenance: hashes, signatures, certificates, C2PA manifests, CAWG identity, DIDs and credentials — what each one is, why it exists, and what each one honestly does not tell you.

Andrew Brown · Aug 3, 2026

SLMA: A Modest Proposal for Supply-chain Levels for Media Artifacts

Applying the lessons of software supply chain security to the digital content supply chain

Andrew Brown · May 18, 2026

When Newsrooms Go Dark: Journalism in the Age of Skynet

Skynet is here; it's just not evenly distributed.

Andrew Brown · May 13, 2026

The State of DID Adoption for Software Supply Chain Trust

We surveyed major software foundations and standards bodies to see who's publishing DID documents. The results reveal both a gap and an opportunity.

Andrew Brown · Mar 21, 2026

The Internet of Authenticity

The dead internet feels inevitable. But we have the technology to build something better. The infrastructure exists. Adoption is the challenge.

Andrew Brown · Mar 12, 2026

Why We're Building Noosphere

We built the first trust layer for browsers. We built the first trust layer for web services. We built API security infrastructure. Now we're building the trust layer for agents.

Andrew Brown · Mar 8, 2026

Agent Context: The New Attack Surface

A2A defines how agents exchange messages. It doesn't define how to verify them. Context poisoning exploits this gap.

Andrew Brown · Mar 2, 2026

Applications Need Software Integrity. Agents Need Context Integrity.

Context is becoming infrastructure. But nobody's talking about integrity for the knowledge layer agents reason over.

Andrew Brown · Mar 2, 2026

Trust Agility: The Design Principle Agent Platforms Are Missing

The Web PKI failed not because cryptography is hard, but because it eliminated trust agility. Agent platforms are repeating the mistake.

Andrew Brown · Feb 20, 2026

Why Content Authenticity Helps Agents Even More Than Humans

The internet is awash in misinformation. For humans, this creates confusion. For AI agents, it creates broken workflows. Content authenticity is the key to reliable agent execution.

Andrew Brown · Dec 1, 2025

From Content Authenticity to Context Authenticity: Why Autonomous Systems Need Agentic Trust

If humans can't tell what's real anymore, how can we expect autonomous agents to?...

Andrew Brown · Nov 25, 2025

Agentic Trust: Designing for Integrity in Autonomous Systems

As artificial intelligence agents become more capable and more autonomous, a foundational question is emerging in both technical and ethical terms:...

Andrew Brown · Nov 2, 2025

The Nuts and Bolts of Mechanical Trust

How machines make trust decisions: the critical distinction between human trust (oxytocin) and mechanical trust (cryptography)

Andrew Brown · Oct 15, 2025

Hierarchy, Democracy, Anarchy? Choose Your Trust Model

Exploring three fundamental approaches to digital trust: PKI hierarchies, PGP anarchy, and democratic trust anchors in the Noosphere ecosystem

Andrew Brown · Aug 29, 2025

A Technology Solution for the Trust Crisis in Digital Media

Revisiting the intersection of AI-generated content, digital authenticity, and trust infrastructure in light of recent developments in AI and culture

Andrew Brown · Aug 28, 2025

Making Trust Deterministic: How Cedar Policies, in-toto, SLSA, SPIFFE, and C2PA Might Converge

Building a foundation for deterministic trust decisions with verifiable metadata standards and policy engines

Daniel Zellmer · Aug 18, 2025

Content Authenticity: Vitamin, Aspirin, or Something Else Entirely?

Everyone agrees content authenticity matters, but unlike software supply chain security, it hasn't had its SolarWinds moment. Is it a vitamin, an aspirin, or perhaps a gold standard?

Andrew Brown · Aug 16, 2025

Anthropic's Latest Releases: Innovation Meets Quota Confusion

Anthropic just dropped Opus 4.1, and alongside it, the new Claude Code agents feature — and honestly, the whole thing feels like a case study in mixed signals....

Jeff Hantin · Aug 12, 2025

Why Digital Integrity is Critical Infrastructure for Trustworthy Publishing

How cryptographic proofs and verifiable trust are becoming essential infrastructure for publishers in the digital age

Andrew Brown · Jul 10, 2025

Digital Integrity: What Is It?

Understanding digital integrity as the foundation of trust in the digital world through cryptographic proofs and verifiable processes

Andrew Brown · Jun 1, 2025

Beyond SEO: How JSON‑LD Can Prove Authenticity, Preserve History, and Travel with Your Content

From search visibility to verifiable trust, signed JSON‑LD turns your blog posts into portable, archival, and agent-ready content.

Daniel Zellmer · May 18, 2025

Rethinking Agentic Trust: Why "Delegation" Might Be the Wrong Model

In today's conversations about AI agents, the prevailing paradigm is delegation. But this framing is misleading. Agents are autonomous, and we need to design trust accordingly.

Andrew Brown · Apr 5, 2025

What I Learned About Protocol Design While Waiting for Luggage in Vegas

How the Model Context Protocol is falling into the same complexity trap as SOAP, and why SSH is the simple solution we already have

Jeff Hantin · Feb 22, 2025

Building Trust Infrastructure for the Decentralized Web

As we continue to develop Noosphere's trust infrastructure, we've been thinking deeply about what it means to build truly decentralized systems. The web was originally designed to be decentralized, bu...

Daniel Zellmer · Jan 10, 2025

Thoughts on Digital Trust in the Age of AI

While much of the focus on media today is about mainstream versus social platforms, digital journalism is quietly undergoing a transformation. Local journalism, in particular, is showing remarkable re...

Andrew Brown · Oct 15, 2024

Rhizomatic Trust: Why Deleuze and Guattari Were Right About Decentralized Systems

Trust infrastructure has always been arborescent—hierarchical, brittle, and prone to capture. What if we built it like a rhizome instead? Deleuze and Guattari's 'A Thousand Plateaus' offers a blueprint for truly decentralized trust.

Andrew Brown · Jan 1, 2024