Cryptographic trust for AI-generated content
Certivu attaches machine-readable, cryptographically verifiable provenance to AI output — the technical disclosure measure the EU AI Act expects. Signed with post-quantum ML-DSA (NIST FIPS 204), watermarked, and verifiable by anyone in seconds, for free.
Aug 2026EU AI Act Article 50 takes effect. Providers must mark AI-generated content in a machine-readable form. Certivu is that technical measure. Get compliant →See it in action →Free tier includes 500 signatures/month · No credit card required
Built for the post-AI era
Every design decision prioritises cryptographic correctness and honest positioning.
ML-DSA Signatures
NIST FIPS 204Post-quantum Dilithium signatures on every piece of content — immune to future quantum attacks. RSA and ECC are never used, anywhere in the stack.
Spread Spectrum Watermark
DCT frequency domainAn invisible watermark spread across 4 independent frequency coefficients per block. Survives JPEG recompression, resizing, and social media upload.
Neural Watermarking
survives social & re-encodeOptional TrustMark (image) and WavMark (audio) neural marks survive the regimes where frequency-domain watermarks fail — screenshot re-capture, heavy recompression, MP3 transcode, and full video re-encodes. A neural match returns high-confidence provenance even after a Twitter/TikTok round-trip.
Images, Audio, Text & Video
multi-formatSign JPEG/PNG/WebP images, MP3/FLAC/WAV audio, PDF/HTML/plain-text documents, and MP4/MOV/MKV/WebM video. Format detected from magic bytes — no guesswork. Each format gets a native token container and a resilient watermark.
Free Public Verification
no account neededAnyone can verify provenance without an account. Upload an image, get a cryptographic verdict in under a second. Unlimited and always free.
No Content Storage
privacy-preservingOnly hashes and signed records are stored — content never touches Certivu servers beyond the verification request.
Tamper Detection
SHA-3 hashingA single changed pixel changes the hash, fails the ML-DSA signature, and returns tampered: true immediately.
Generator Revocation
instant revocationRevoke a compromised generator and all its signatures become invalid across every past and future verification — no migration needed.
Signing Key Rotation
zero-downtimeRotate a generator's signing key on demand. New content is signed with the fresh key while everything signed earlier stays fully verifiable — refresh keys on a schedule without disrupting past provenance.
Post-Quantum C2PA
ML-DSA-signed manifestsWrites real, embeddable C2PA manifests into JPEG and PNG — signed with ML-DSA instead of the classical RSA/ECC the ecosystem uses today. Structurally interoperable with Content Credentials, with quantum-resistant signatures only Certivu provides. Also reads third-party C2PA manifests on verification.
Perceptual Fingerprinting
pHash + Hamming64-bit pHash fuzzy lookup via Hamming distance recovers provenance even when watermarks are destroyed by resize, reformat, or heavy recompression.
No-Code Web Signer
drag, drop, downloadSign content straight from the dashboard — drag in a file, pick a generator, download the signed copy. Every format supported, no SDK or API code required.
Embeddable Verify Badge
<certivu-badge>Drop a live 'Verified by Certivu' badge onto any page with one line of HTML. Self-updates from the public status endpoint, themable, and works embedded anywhere.
CI & Sandbox
CLI verify + test keysVerify AI assets in CI with one CLI step and fail builds that lack provenance. Build against a free sandbox with isolated data and test keys that never consume quota.
Branded Certificates
your logo + colorsShare a public, org-branded verification certificate for any signed asset — your logo, accent color, and name on a page anyone can open. Powered by the public status endpoint, no login required. Growth plan and above.
EU AI Act Disclosure
Article 50 · Aug 2026Machine-readable, cryptographically verifiable provenance — the technical disclosure measure the EU AI Act expects, on every plan. Certivu provides the infrastructure; compliance remains your responsibility, and this is not legal advice.
Verification Analytics
Per-record verification counts, daily trend charts, authentic rate, and tamper detection dashboard.
Tamper alert emails fire the moment a hash mismatch is detected. Free tier: 7-day window. Starter+: 30–90 day full history with per-record drill-down.
Monthly Intelligence Digest
Automatic monthly email with signing stats, total public verifications, tamper event count, and quota status.
Delivered from [email protected] on the 1st of each month. Includes an upgrade nudge if you're approaching your plan limit. Available on Starter and above.
Webhook Events
Real-time HTTP callbacks for every signing, verification, tamper, quota, revocation, and key-rotation event.
HMAC-SHA256 signed with replay protection (5-minute tolerance). Auto-disabled after 5 consecutive failures. 30-day delivery log with per-delivery retry. Growth+ only. 7 event types: record.created, verify.attempted, verify.tamper_detected, quota.warning, quota.limit, generator.revoked, generator.key_rotated.
Compliance Attestation
Export a regulator-ready attestation mapping your signing activity to EU AI Act Article 50 transparency obligations.
Available as JSON or a printable HTML document over a chosen reporting period, via API, SDK, or the CLI. A factual record of cryptographic provenance activity — not a certification or legal opinion. Enterprise plan.
From generation to verification
End-to-end provenance in three steps — from generation to public verification.
Sign at generation time
Your AI system calls Certivu when generating content. Content is hashed with SHA-3 and signed with an ML-DSA (Dilithium) keypair — a NIST FIPS 204 post-quantum signature that stays valid against future quantum attacks.
Embed the provenance token
Certivu embeds an invisible watermark in the content — neural marks (TrustMark for images, WavMark for audio) backed by DCT spread-spectrum, ZWC steganography for text, and a container atom/trailer for video — and stores the ctv_ token in format-native metadata. For JPEG and PNG it can also embed a real, ML-DSA-signed C2PA manifest. Neural marks survive heavy recompression, resizing, and social-media re-encode.
Verify — free, for anyone
Anyone uploads the content to certivu.ai or calls POST /v1/verify. Certivu auto-detects the format from magic bytes, extracts the token, re-hashes the content, verifies the ML-DSA signature, and returns a cryptographic confidence verdict.
Simple pricing
Signing is paid. Verification is always free.
Save 20% with annual billing
All plans include unlimited verifications · No credit card required for Free