Solutions

Verifiable provenance, rights, and AI transparency for the open web

Content on the web is published and shared at scale with no reliable provenance. There is no scalable way to establish trust in digital content – who created a work, what rights apply to it, or whether AI was involved. Social platforms strip metadata on upload, content is shared and distributed far from its source, and claims to the content are hard to verify.

Liccium addresses this by binding signed, verifiable declarations to the content itself. Each declaration is resolvable from the media through its content fingerprint (ISCC, ISO 24138), digitally signed by the creator or rightsholder, and published to open, federated registries. The declaration travels with the content, survives file format conversion and compression, stripping of context or metadata, and can be verified by anyone – without trusting a single platform or authority.

Digital signatures for content – the core innovation

Liccium lets creators and rightsholders digitally sign claims about their work and bind them to the content’s own fingerprint (ISO 24138). The signature ties a declaration to a verifiable identity, so attribution, provenance, and integrity can be checked independently. This is the foundation the other solutions build on – the trust component the web has been missing.

Signatures are backed by X.509 certificates from EU trust services, or by verifiable credentials issued by trusted providers. Whichever route is used, the declaration resolves to a source that can be verified without relying on any single platform.

Creator Credentials – identity you control

Creator Credentials brings decentralised digital identity to the cultural and creative industries. Through it, creators and rightsholders can request, hold, and manage their own verifiable credentials, keeping a decentralised, user-controlled identity that stays pseudonymous where preferred.

The issuing side sits with the organisations creators already belong to. Media organisations, membership associations, collective management organisations, and trust services can issue credentials to their members, acting as trust anchors for attribution and accountability across digital publishing.

FAIA – AI attribution logo

FAIA – AI attribution

As AI-generated media becomes hard to distinguish from human-made work, the web needs a reliable way to disclose how content was created. FAIA (FAIR AI Attribution) provides the vocabulary and registry for it: a signed, machine-readable flag – Human-Created, AI-Assisted, or AI-Generated – bound to the content fingerprint.

Because the flag is bound to the content fingerprint rather than to a file’s embedded metadata, anyone can regenerate the fingerprint from the file and resolve the flag – reliably, and even after the content has been shared or modified. This supports transparency and accountability across the content supply chain, and helps meet disclosure requirements such as Article 50 of the EU AI Act.

TDM·AI – AI opt-out logo

TDM·AI – AI opt-out

Rightsholders can reserve their content from AI training. TDM·AI binds a machine-readable opt-out preference to the asset’s content fingerprint, so the reservation survives distribution, manipulation, and metadata removal.

That binding to the asset is the crucial difference. Current approaches – the W3C TDM Reservation Protocol (TDMRep) and the emerging IETF AI Preferences (AIPREF) – express preferences at the level of domains and servers, unsigned and unattributable.

Binding the preference to the fingerprint and signing it is the most robust method: the reservation is provable, verifiable, and cannot be silently detached from the work. It builds on Article 4(3) of the EU CDSM Copyright Directive (2019/790).

Federated registries – the infrastructure

Declarations are published to open, federated registries – a network of independently operated directories rather than one central database. The registries hold the declarations, not the media itself, and index each entry by its content fingerprint. Anyone who generates the ISCC from a file can query a registry and retrieve the declaration bound to it – regardless of where the content is hosted or how it has been shared. Rights, provenance, and metadata live in the registry rather than embedded in the file, so they cannot be stripped along with a file’s metadata.

Registries are run independently – by creator groups, collecting societies, standards bodies, or compliance platforms – and synchronise over a peer-to-peer network using a shared schema, so they work as one globally searchable system that scales to billions of assets. The public index carries only what is needed to confirm a declaration’s rights status; access to the full declaration data can be governed by policy. No single authority controls the system, which is what makes it usable as shared infrastructure rather than another platform.

See how it fits your workflow

Book a demo, or explore the products for creators and organisations.