This is an on-device structural scan (JUMBF / C2PA box markers). It tells you
whether Content Credentials are present; it does not perform full cryptographic validation of
the manifest chain - for that, the C2PA tooling or the Obsign SDK
(obsign c2pa-verify) is canonical. Nothing you drop here leaves your browser.
Obsign's re-runnable layer is also a proposed C2PA assertion -- c2pa.reproducible.operation, a vendor-neutral way to record re-executable edit provenance (reference implementation: Obsign). The aim: any C2PA tool can re-run the edit, not just log that one happened.