Verification

What verstag reads out of a file — and what a result does not mean.

Verification means reading the provenance record embedded in the file: the signature, the certificate chain against a list of recognised issuers, the timestamp. From that follows who signed the file, when that happened, and whether it has been altered since.

The file is read, not the picture.

The signed-in product is in German, so its wording is quoted in German here, with the English rendering in italics.

„Prüfen“ (Verify) is the first entry in the sidebar, and that page is also where the app starts.

What a result does not mean

It is not an AI detector. The picture itself is not assessed. verstag does not work out whether an image was generated by AI — it reads what the file records about that.

„Keine Content Credentials gefunden“ (No Content Credentials found) does not mean „gefälscht“ (forged). The vast majority of files in circulation simply carry none. If Content Credentials are there, they say something; if they are absent, their absence says nothing.

„Strukturell gültig“ (structurally valid) is not proof of trust. It means the signature is intact and the record well formed — a self-signed manifest satisfies that. The question of trust is answered by a second pass against the list of recognised issuers.

Verification is a technical tool, not editorial approval. Whether a marking is required is your decision — verstag applies it and records that it did.

The pages in this group