Why New Technology Doesn’t Replace a Website Audit
Published 7 September 2026
You may have heard about new technologies designed to help prove the origin of digital images. One of the most prominent technologies is C2PA (Coalition for Content Provenance and Authenticity), a technical standard that lets cameras, editing tools and other systems attach a tamper-evident record of an image’s origin and editing history.
Along with perceptual fingerprinting and invisible watermarking, C2PA promises to make image provenance more reliable. That’s useful, but it doesn’t offer bulletproof protection against copyright claims, particularly for businesses with years of images already published online.
Many company websites contain stock photos, agency uploads, employee contributions and other images with little or no surviving paperwork. Those files may have been renamed, resized, compressed, cropped and moved between content management systems. Some arrived before anyone thought to record their source. Others came from agencies that no longer exist or employees whose purchase receipts disappeared with an old email account.
It can’t travel back in time and validate an existing website image library.
New provenance technology can help preserve information about images going forward. What it can’t do is travel back in time and validate an existing website image library.
It can’t confirm that your company bought the right license. It can’t determine whether an editorial-use image was placed on a commercial page. And it can’t tell you which images on your website have no supporting records.
That still requires an audit.
Why Traditional Metadata Is Not Enough
Digital images can contain several forms of metadata. EXIF (Exchangeable Image File Format) data commonly records technical details such as the camera, lens and capture date.
IPTC (International Press Telecommunications Council) fields can contain creator names, copyright notices and credit information.
XMP (Extensible Metadata Platform) can store descriptive, administrative and licensing information.
The problem is that this information doesn’t always survive over time. An image may pass through editing software, a stock library, a shared drive, a designer’s computer, an image compressor, a content management system and a content delivery network before appearing on a website. Along the way, systems may create thumbnails, convert JPEGs to WebP, crop files or otherwise produce new versions. All of these may systematically strip metadata from the image.
Once the metadata is stripped away, a business may discover that nothing else connects the published image to its source or license.
Depending on the software and settings involved, some or all of the embedded metadata may be stripped away. That doesn’t automatically create a copyright violation, but it can certainly contribute to it. The risk comes when a site owner relies on embedded metadata as though it were the company’s complete licensing record. Once the metadata is stripped away as outlined above, a business may discover that nothing else connects the published image to its source or license.
What C2PA Improves — and What It Doesn’t
The Coalition for Content Provenance and Authenticity created an open standard for recording the origin and history of digital content. Its consumer-facing implementation is commonly known as Content Credentials.
Think of a Content Credential as a digital history card attached to an image. A supported camera, application or service can record information about how the image was created or edited. Cryptographic signatures then make it possible to detect whether that recorded information has been altered.
That’s an important improvement over ordinary metadata, but Content Credentials don’t determine whether the statements recorded inside them are legally correct. A credential may show that a particular source made a claim and that the claim hasn’t changed. It doesn’t independently prove who owns the copyright, whether your company purchased a valid license or whether the license covers the way the image is being used.
Cryptography may protect a record, but it can’t make an inaccurate record accurate. Nor can it create a missing record for an image uploaded years ago.
Content Credentials are valid, but offer no protection for existing site images.
Even with stock libraries such as Adobe Stock or Shutterstock, businesses shouldn’t assume that every downloaded image carries useful Content Credentials. Older images may predate the technology, credentials may never have been added, or parts of the provenance trail may disappear during downloading, conversion or publishing.
Identification Is Not Permission
Other technologies help solve different parts of the problem.
Perceptual fingerprinting creates a mathematical representation of an image that can remain similar even after resizing, recompression, format conversion or moderate cropping. That allows matching systems to recognize altered versions of the same underlying picture.
Invisible watermarking embeds a machine-readable signal into an image while keeping it effectively invisible to viewers. Depending on the technology, the signal may survive ordinary changes such as resizing or recompression.
Together, these tools can make images easier to identify and trace. But identification is not the same as permission.
Digital fingerprinting and watermarking are both valid techniques, but they don’t ensure the safety of the images currently on your site.
A match may reveal that a photograph came from a particular stock provider. You still need to establish whether your organization purchased it, who holds the license and whether that license allows the image to be used as it currently appears.
Was it licensed for commercial use? Was it restricted to editorial use? Does the license belong to your company or a former agency? Can the image be modified? Does permission continue after a subscription ends?
No fingerprint, watermark or Content Credential can answer those questions without supporting records.
Technology may be able to locate the picture, but compliance still requires someone to locate the “paperwork.”
Why a Website Image Audit Still Matters
A website image audit starts with a more practical question: What images are actually published on your website right now?
That can be surprisingly difficult to answer across hundreds or thousands of pages. Images may appear in blog posts, landing pages, product listings, archived campaigns, staff profiles, downloadable files and forgotten sections left over from previous redesigns.
Without an inventory, it’s almost impossible for a business to know which images need further documentation.
That’s where ImageVerifier fits in. ImageVerifier can scan a website, locate published images, flag assets that may require further verification and help teams connect images with available licensing records. It can also help identify possible stock-provider matches.
Once you know what’s actually online, you can begin determining whether each image is properly documented, or whether it needs to be licensed, replaced or removed before it becomes the basis for a legal claim.
Building a More Reliable Compliance Process
The strongest approach combines newer provenance technology with better internal records.
Preserve invoices, license agreements, download histories and usage terms rather than assuming they will remain available in a stock account forever. Maintain a record connecting each published image with its source, license holder, permitted use and location on the website.
It’s also worth testing your publishing pipeline. Upload an image containing known metadata, then inspect the versions produced by your content management system (CMS), plugins and content delivery network, all of which create multiple versions of images to optimize loading speeds across different devices and screen sizes. You may discover that important information is stripped away before the image reaches the public site.
Use Content Credentials when supported, but treat them as evidence of provenance rather than a substitute for a license.
Most importantly, audit what’s already online. Older assets may actually present the greatest uncertainty because employees, suppliers, platforms and record-keeping practices have changed over time. Old website images don’t become low-risk simply because nobody on the current team remembers where they came from or just because they are old. (Copyrights are protected for a lot longer than most people think.)
Better Provenance Does Not Eliminate Existing Risk
C2PA, perceptual fingerprinting and invisible watermarking are meaningful advances. They can give digital images a more durable history and make altered copies easier to recognize.
But they don’t grant copyright ownership. They don’t confirm that your organization purchased the correct license. And they don’t inspect your website to identify every image whose documentation may be incomplete.
For website teams, the practical answer is to use both approaches: adopt stronger provenance tools for new assets, preserve licensing records and audit the images already online.
Someone uploaded a picture, nobody recorded where it came from and everyone assumed someone else had checked.
ImageVerifier helps teams find the images in use, identify those requiring investigation and begin building a clearer compliance record before uncertainty turns into a claim.
The future of image provenance may be cryptographic. But the risk sitting on many websites today is much more ordinary: Someone uploaded a picture, nobody recorded where it came from and everyone assumed someone else had checked.
That’s the problem an ImageVerifier audit can help solve.
Disclaimer: This content is for general informational purposes only and is not legal advice or a substitute for advice from a licensed copyright attorney. It does not create an attorney-client relationship. The authors are not responsible for inadvertent errors or omissions. Laws may change over time and vary by jurisdiction, so consult a qualified attorney regarding your specific circumstances.
Welcome to the Anti-Troll Tribe!
Thanks for exploring ImageVerifier. You’ll be the first to know once we go live. We’ll send you an email notification as soon as we’re ready. Please fill out the form below to join the waitlist.
"*" indicates required fields

