Complete table with all fields including TCR4CAP comments.
| ID | Name | Type | Structure | Readability | Verifiability | URL | Awareness | Tamper Evidence | Binding | AI Attribution | Substantiation | Interoperability |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
bwf | Broadcast WAVE Format (BWF) | audio | binary-chunk | open | integrity-only | guidelines: https://www.digitizationguidelines.gov/guidelines/digitize-embedding.html | BWF is a well-established archival audio format. BEXT chunk provenance fields are widely understood in broadcast and archival workflows. C2PA embedding path is defined but not yet widely implemented in BWF-specific tooling. | BEXT chunk fields are informative and not integrity-protected. They can be silently overwritten, edited, added, or removed. C2PA RIFF chunk provides cryptographic tamper-evidence when present. | BEXT chunk is structurally embedded. C2PA RIFF chunk provides cryptographic hard binding to audio content when present. An md5 chunk may store the md5 hash of the audio content. | No purpose-built AI attribution fields in the BWF/BEXT specification. AI documentation requires C2PA assertions or repurposing of CodingHistory. | BEXT CodingHistory provides a readable transformation record. C2PA manifest store could preserve a full transformation history when present. | Open specification (EBU Tech 3285, FADGI). Widely implemented across broadcast, archival, and audio tools. |
flac | FLAC (Free Lossless Audio Codec) | audio | binary-block | open | integrity-only | — | C2PA-specific awareness in FLAC workflows is not yet common. The GEOB embedding path is defined but not widely recognized in tooling or policy. | Native MD5 (STREAMINFO) and per-frame CRCs (RFC 9639) provide structured format-level integrity of audio data. These do not cover metadata blocks; tamper-evidence of CAP data depends on the mechanism used. | The format defines discrete metadata blocks and a specified C2PA embedding location (ID3 GEOB). Binding strength depends on the mechanism used. | No purpose-built AI attribution fields in the FLAC or Vorbis Comment specification. Any AI documentation requires repurposing general fields or use of C2PA via GEOB. | FLAC metadata is open and readable. No formal mechanism for publishing transformation history or CAP policies at point of access at the format level. | Open specification (Xiph.org, RFC 9639). Widely implemented across tools and platforms. ID3 broadly supported. |
jpeg | JPEG | image | binary-segment | published-standard | signed | homepage: https://jpeg.org/ | JPEG is a widely deployed image format and has relatively extensive support with metadata processing tools. C2PA embedding in APP11 is a defined, published standard with broad industry adoption. | C2PA APP11 chunk provides cryptographic tamper-evidence via signed manifests and hard binding to image content. | C2PA hard binding via content hash provides cryptographic linkage between manifest and image content. | C2PA AI attribution assertions (c2pa.ai.generatedWith, c2pa.training-mining) and IPTC 2025.1 AI fields are both supported in JPEG. | C2PA manifest store preserves full transformation history. External trust anchors supported. Public verification via contentcredentials.org. | Universally implemented across cameras, phones, image editing tools, and repository systems. |
png | PNG (Portable Network Graphics) | image | binary-chunk | open | signed | — | PNG is a widely deployed image format. C2PA embedding in caBX chunk is a defined, published standard. | C2PA caBX chunk provides cryptographic tamper-evidence via signed manifests and hard binding to image content. | C2PA hard binding via content hash provides cryptographic linkage between manifest and image content. | C2PA AI attribution assertions and IPTC 2025.1 AI fields are both supported in PNG. | C2PA manifest store preserves full transformation history. External trust anchors supported. | Widely implemented across image editing tools, browsers, and repository systems. |
tiff | TIFF (Tagged Image File Format) | image | binary | open | signed | — | TIFF is a well-established archival format recommended by FADGI for digitization of cultural heritage materials. EXIF, IPTC, and XMP provenance fields are widely understood. C2PA embedding via JUMBF box in the IFD structure is defined in C2PA specification 2.4 but not yet widely implemented in TIFF-specific tooling. | EXIF, IPTC, and XMP metadata are informative and not integrity-protected. C2PA JUMBF embedding provides cryptographic tamper-evidence via signed manifests and hard binding to image content when present. | C2PA hard binding via content hash provides cryptographic linkage between manifest and image content when embedded. Sidecar binding is soft and depends on file management conventions. | C2PA AI attribution assertions (c2pa.ai.generatedWith, c2pa.training-mining) and IPTC 2025.1 AI fields (via XMP) are both supported in TIFF. | EXIF, IPTC, and XMP provide a readable provenance record. C2PA manifest store preserves full transformation history when present. PREMIS sidecar provides institutional transformation history. | Universally implemented across image editing tools, scanners, and repository systems. |
mp4-isobmff | MP4 / ISO Base Media File Format | moving image | binary-atom | published-standard | signed | — | MP4/ISOBMFF is the widely used video container format. C2PA embedding in uuid atom is a defined, published standard with growing industry adoption. | C2PA uuid atom provides cryptographic tamper-evidence via signed manifests and hard binding to video content. | C2PA hard binding via content hash provides cryptographic linkage between manifest and video content. | C2PA AI attribution assertions (c2pa.ai.generatedWith, c2pa.training-mining) are fully supported in MP4/ISOBMFF. | C2PA manifest store preserves full transformation history. External trust anchors supported. | Universally implemented across video tools, cameras, and repository systems. |
mkv | Matroska (MKV) | moving image | binary-ebml | open | none | — | Matroska is a well-known container format. No native C2PA embedding path is defined; C2PA awareness in MKV workflows is limited. | No native cryptographic signing. Tag and attachment metadata are advisory and not integrity-protected. C2PA sidecar provides tamper-evidence but can be separated from the asset. | No native C2PA embedding path. Sidecar binding is soft and depends on file management conventions. | No purpose-built AI attribution fields in the Matroska specification. AI documentation requires C2PA sidecar or repurposing of tag elements. | Tag elements provide a readable metadata record. No formal mechanism for publishing transformation history at the format level. | Open specification. Widely implemented across video tools and platforms. |
c2pa-manifest | C2PA Manifest (Content Credentials) | metadata | cbor-jumbf | published-standard | signed | — | C2PA Technical Specification is published by the Coalition for Content Provenance and Authenticity. Adopted by Adobe, Microsoft, Google, camera manufacturers, and news organizations. | Each manifest is cryptographically signed; any modification invalidates the signature. Hard binding means any modification to the asset content invalidates the active manifest. | Hard binding provides cryptographic linkage between manifest and asset content via content hash. Soft binding provides a defined alternative for non-embeddable assets. | C2PA defines purpose-built assertions for AI generative and training provenance: c2pa.ai.generatedWith, c2pa.training-mining, and related fields for model identity and generation parameters. | Manifest store preserves full transformation history. External trust anchors (credential issuers, TSA) are supported. Public verification is possible via the C2PA trust list. | Open published specification. Reference implementation (c2patool, c2pa-rs) available under open-source license. Adopted across image, video, and audio tools and camera manufacturers. |
xmp | XMP (Extensible Metadata Platform) | metadata | xml-rdf | published-standard | none | — | XMP is defined in ISO 16684. Implemented across all major creative, archival, and repository tools. xmpMM:History and xmpMM:DerivedFrom are recognized provenance fields. | XMP packets have no integrity protection. Properties can be silently overwritten or the entire packet stripped. | XMP is structurally embedded in host files but there is no cryptographic binding between XMP content and the primary media data. | IPTC 2025.1 AI fields (AiPrompt, AiSystemUsed, AiSystemVersion) are carried in XMP namespaces. No purpose-built AI attribution fields are defined in the core XMP specification. | xmpMM:History and xmpMM:DerivedFrom provide a readable provenance record. XMP sidecar files can be published independently. | ISO 16684. Implemented across all major creative, archival, and repository tools. |
exif | EXIF (Exchangeable Image File Format) | metadata | binary | open | none | — | EXIF is defined by CIPA DC-008. Universally implemented across cameras, phones, and image processing tools. Capture device identity and datetime fields are widely used as provenance indicators. | EXIF data has no integrity protection. Tags can be silently overwritten or stripped. | EXIF is structurally embedded in host files but there is no cryptographic binding between EXIF tag values and the image content. | No AI attribution fields are defined in the EXIF specification. Software (0x0131) can record processing tool identity but has no structured AI attribution vocabulary. | Capture datetime, GPS, and device fields provide a factual provenance record. No mechanism links EXIF fields to external policies or transformation histories. | CIPA DC-008. Universally implemented across cameras, phones, and image processing tools. |
iptc-photo | IPTC Photo Metadata Standard 2025.1 | metadata | xml-xmp | open | none | — | IPTC Photo Metadata Standard is published by IPTC. Version 2025.1 AI fields are defined in the specification. Widely implemented in photo editing, DAM, and publishing tools. | IPTC fields carried in XMP have no integrity protection. Fields can be silently overwritten or stripped. | IPTC fields are structurally embedded via XMP in host files but there is no cryptographic binding between field values and the image content. | Version 2025.1 defines AiPrompt, AiSystemUsed, AiSystemVersion, and DataMiningPermission as purpose-built, standardized AI attribution fields within the IPTC vocabulary. | IPTC fields provide a structured, readable provenance record. The standard is publicly documented. | Implemented in photo editing, DAM, and publishing tools including Adobe Photoshop, Lightroom, and Capture One. |
premis | PREMIS (Preservation Metadata) | metadata | xml | open | integrity-only | — | PREMIS Data Dictionary is published by the Library of Congress. Implemented in Archivematica, DSpace, Fedora, and other repository systems. | PREMIS XML has no integrity protection. Tamper-evidence depends on the repository or packaging layer. | Fixity values in objectCharacteristics/fixity link the PREMIS record to a specific file state. Binding is not cryptographically enforced within the PREMIS document itself. | No purpose-built AI attribution fields in the PREMIS Data Dictionary. Agent/agentType and eventType vocabularies could accommodate AI agents and events by convention. | PREMIS event records provide a structured, policy-driven transformation history. The PREMIS Data Dictionary is an open standard. Event records are auditable by repository administrators. | Published by the Library of Congress as an open standard. Implemented across major digital preservation systems and repository platforms. |
bagit | BagIt (RFC 8493) | metadata | text-manifest | open | integrity-only | — | BagIt is defined in IETF RFC 8493. Widely adopted in digital preservation, library, and archival transfer workflows. | Manifest checksums detect modification of any payload or tag file. No signing mechanism at the BagIt level. | Manifest entries bind each checksum to a specific file path within the bag. No cryptographic binding between the bag as a whole and an external identity or signing authority. | No AI attribution fields in the BagIt specification. bag-info.txt custom fields could carry AI processing notes by convention. | Manifest files provide a verifiable, reproducible integrity record for all payload and tag files. bag-info.txt carries descriptive provenance fields. | IETF RFC 8493. Implemented across digital preservation, library, and archival transfer tools and systems. |
mets | METS (Metadata Encoding and Transmission Standard) | metadata | xml | open | integrity-only | — | METS schema is published by the Library of Congress. Implemented in Archivematica, DSpace, and other repository systems. | METS XML has no integrity protection. Tamper-evidence depends on the repository or packaging layer. | METS fileSec references described files by path and can carry fixity values. Binding is not cryptographically enforced within the METS document itself. | No purpose-built AI attribution fields in the METS schema. PREMIS events in the amdSec could document AI processing actions by convention. | METS provides a structured, comprehensive metadata record for digital objects. Widely supported by repository systems. | Published by the Library of Congress as an open standard. Implemented across major digital preservation systems and repository platforms. |