PROVENANCE-GATED DELIVERY

Every AI asset ships with a Birth Certificate— or it doesn't ship at all.

FIREMARK binds AI images and AI voice to signed provenance, immutable custody, and a clear verification decision before a private byte is released.

Open verification · Private evidence stays private

SEALED MEDIAIMAGE + AUDIO
9f2a ··· 7c81
FMBIRTH CERTIFICATE
● ACTIVE
SOURCE HASHBOUND
SIGNATUREVALID
CUSTODYLOCKED

TRUST IS NOT A LABEL

Evidence must travel with the asset.

FIREMARK connects what was generated, what was sealed, who signed it, where its private evidence is retained, and whether the bytes presented now are the bytes certified then.

THREE CAPABILITIES

One controlled path from creation to release.

No dashboard sprawl. Each capability closes a specific gap in the chain of trust.

Generate & Seal

Generate AI images with OpenAI or Gemini, or AI voice with ElevenLabs, then certify the bytes.

Source hash → provenance → sealed hash

Birth Certificate

Publish the identity, signature, and safe provenance needed to assess one asset.

Public proof without private prompts

Verify Gate

Inspect images or hash audio locally, then release only when every backend trust layer passes.

Zero-upload media check → verification → delivery
GENERATE & SEAL

A chain that is understandable — and inspectable.

Each boundary produces a different kind of proof. No single badge stands in for all of them.

  1. 01

    Generate

    The provider output is hashed before anything is embedded.

  2. 02

    Prove

    Private canonical provenance records how the asset came to exist.

  3. 03

    Seal

    A public capsule is embedded and the final distributed bytes are hashed.

  4. 04

    Retain

    Source evidence and the private manifest enter immutable custody.

  5. 05

    Sign

    An Ed25519 signature binds identity, hashes, custody references, and time.

  6. 06

    Verify

    Delivery opens only when the certificate and presented hash agree.

PUBLIC BIRTH CERTIFICATE

A compact public record of what can be proven.

A certificate names the sealed asset, its provenance record, its signer, and its current status. It intentionally omits prompts, private parameters, storage coordinates, and custody internals.

  • 01
    Source hash

    Identifies the untouched generated output.

  • 02
    Sealed hash

    Identifies the exact file intended for delivery.

  • 03
    Provenance

    Binds the asset to a canonical creation record.

  • 04
    Signature

    Detects changes to the signed evidence envelope.

VERIFY GATE

Delivery is a decision, not a link.

FIREMARK Lens reads PNG capsules locally, while audio verification hashes MP3 bytes locally against an entered certificate ID. Only the certificate ID and hash reach Verify Gate, where status, signature, custody references, and byte identity determine delivery.

Open FIREMARK Lens
TRUST ARCHITECTURE

Public confidence. Private evidence. Explicit boundaries.

PUBLIC

Certificate plane

Allowlisted identity, hashes, signature material, status, and public capsule.

CONTROLLED

Verification plane

Deterministic checks and auditable decisions without revealing private storage.

PRIVATE

Custody plane

Canonical provenance and source evidence held under immutable retention.

EVIDENCE BEFORE DELIVERY

Know exactly what you are about to trust.

Verify a sealed image or AI voice recording locally. Your media never leaves the browser.

Verify without uploading