How puit.is keeps origin checkable after transformation
puit.is combines imperceptible watermarking, tamper-evident public anchoring, and confidence-graded verification to preserve a checkable origin link across editing, compression, migration, reposting, and reuse.
Only a commitment derived from the identifier is published. The media file itself is never written to a public record.
Technology for provenance that has to survive real distribution.

Original


With embedded UID
The first two images are visually identical under normal viewing. The third shows the difference between them, amplified so it becomes visible at all.
Workflow overview
provenance that can survive real distribution paths.
Embed at source
At or near the point of origin, an imperceptible UID is embedded into the image signal and connects the media to an external provenance record.
Anchor the claim
A UID-derived commitment is anchored publicly. Media and metadata remain off-chain. Today's hosted verifier is puit.is-operated; independently operated verification remains a planned validation path.
Verify later
The signal is recovered and matched against the record. The result is a verification status with a confidence score and match distances, so it stays useful after compression, reformatting, or degradation.
Core components
Media UID embedding & recovery
Imperceptible, edit-tolerant embedding designed for distribution paths where metadata can be stripped and exact-file hashes no longer apply.

Public anchoring layer
Tamper-evident commitments support re-checks across institutions, systems, and time.

Verification toolset
Reviewers see how strongly a file still links back to its claimed origin: a status, a confidence score, and the measured distance to the stored record.

Designed for auditability, review, and regulatory alignment
Reproducible evidence
Runbooks, manifests, per-item results, and integrity hashes support independent re-checks and later review.
Vendor-neutral verification
Evidence is structured for re-checks beyond one closed platform. Today's hosted verifier remains puit.is-operated.
Privacy-aware provenance
Origin can be verified without unnecessary exposure of sensitive data.
Policy-aware architecture
GDPR: data minimisation
GDPR — Article 5(1)(c): data minimisation.
puit.is can keep media and descriptive metadata out of the public anchor. The current public anchor contains only a UID-derived commitment.GDPR: data minimisation
Read official sourceGDPR — Article 5(1)(c): data minimisation.
puit.is can keep media and descriptive metadata out of the public anchor. The current public anchor contains only a UID-derived commitment.GDPR: data protection by design
GDPR — Article 25: data protection by design and by default.
Whether a deployment meets Article 25 depends on the controller and use case. puit.is can keep media and descriptive metadata out of the public anchor.GDPR: data protection by design
Read official sourceGDPR — Article 25: data protection by design and by default.
Whether a deployment meets Article 25 depends on the controller and use case. puit.is can keep media and descriptive metadata out of the public anchor.eIDAS 2: electronic ledgers
eIDAS 2, electronic ledgers: Article 45k recognises electronic ledgers and gives qualified electronic ledgers presumptions regarding chronological ordering and integrity.
puit.is is designed with an adapter path toward qualified trust-service components. The current Bitcoin/OpenTimestamps anchor is not a qualified trust service.eIDAS 2: electronic ledgers
Read official sourceeIDAS 2, electronic ledgers: Article 45k recognises electronic ledgers and gives qualified electronic ledgers presumptions regarding chronological ordering and integrity.
puit.is is designed with an adapter path toward qualified trust-service components. The current Bitcoin/OpenTimestamps anchor is not a qualified trust service.NIS2: cybersecurity risk management
NIS2, Article 21: sets cybersecurity risk-management measures for essential and important entities, including incident handling, business continuity and supply-chain security.
puit.is could support the evidence and record-keeping side of such measures where media provenance is in scope.NIS2: cybersecurity risk management
Read official sourceNIS2, Article 21: sets cybersecurity risk-management measures for essential and important entities, including incident handling, business continuity and supply-chain security.
puit.is could support the evidence and record-keeping side of such measures where media provenance is in scope.DSA: systemic-risk mitigation
DSA, Articles 34 and 35: require very large online platforms and search engines to assess and mitigate systemic risks.
The DSA does not prescribe any particular provenance method; puit.is could support origin evidence where a provider chooses to use it as part of its own mitigation measures.DSA: systemic-risk mitigation
Read official sourceDSA, Articles 34 and 35: require very large online platforms and search engines to assess and mitigate systemic risks.
The DSA does not prescribe any particular provenance method; puit.is could support origin evidence where a provider chooses to use it as part of its own mitigation measures.DSM Directive: rights reservation
DSM Directive, Article 4: allows rightholders to reserve text and data mining rights through appropriate means, including machine-readable means for content made publicly available online.
puit.is could carry and resolve such a reservation alongside the provenance record.DSM Directive: rights reservation
Read official sourceDSM Directive, Article 4: allows rightholders to reserve text and data mining rights through appropriate means, including machine-readable means for content made publicly available online.
puit.is could carry and resolve such a reservation alongside the provenance record.
Comparison with existing approaches
puit.is does not ask whether media looks manipulated.
It preserves the link needed to check where it came from.
| Approach | What it gives you | Failure behaviour | Why puit.is matters |
|---|---|---|---|
| Detection | What it gives youA manipulation-risk signal | Failure behaviourReactive, probabilistic, and adversarially fragile | Why puit.is mattersAdds source-linked continuity before later doubt begins |
| Metadata credentials | What it gives youDeclared provenance in controlled workflows | Failure behaviourOften stripped, detached, or lost in distribution | Why puit.is mattersKeeps origin linkage meaningful after transformation |
| Hash-only anchoring | What it gives youProof that an exact file existed | Failure behaviourBreaks on benign edits, compression, and format changes | Why puit.is mattersSupports verification beyond exact-file matching |
| puit.is | What it gives youSource-linked origin and continuity evidence | Failure behaviourRecovery confidence degrades under sufficiently severe or adversarial transformations; performance depends on media type, configuration, and transformation path. | Why puit.is mattersSupports later re-checks across systems and time |
Built to evolve without replacing the trust model
puit.is is designed as a modular provenance stack. Watermarking, anchoring, verification, and deployment can improve as formats, attacks, and institutional workflows change without rebuilding the entire trust model.
New formats
Roadmap from images toward audio, video, 3D, and complex heritage objects.
Modular upgrades
Watermarking, anchoring, and verification layers can be strengthened without rebuilding the whole system.
Operational resilience
EU-hosted, reproducible deployment supports auditability, continuity, and institutional scale.