The trust-signal assessment
Two different questions. Two different kinds of answer.
Every TrustCapture verification answers two separate things: is this file provably unaltered and from a genuine device, and what do we know about the conditions it was captured under? The first is a cryptographic proof. The second is a heuristic assessment. This page explains the difference — and why we refuse to blend them into one number.
The two questions
One is math. The other is a judgment call.
The proof
What the signature guarantees
At the moment of capture, TrustCapture signs a manifest — the media's hash, a timestamp, and device attributes — with a key generated and held inside the device's secure hardware (Apple Secure Enclave, Android StrongBox). That key never leaves the chip.
A valid signature is cryptographic proof that this exact file is unaltered since capture and came from a specific, genuine, attested device. It either verifies or it doesn't — there's no in-between, and no version of it that's "mostly true."
The assessment
What the assessment adds
Separately, TrustCapture computes a heuristic summary of the device and environment signals available at capture time — things like whether the device's own integrity checks passed, and whether the capturing app was recognized. It's context about the conditions of capture.
Unlike the signature, this is a judgment built from signals, not a mathematical certainty. It's calibrated by us, it evolves as those signals improve, and it's presented as exactly that — an assessment, never a proof.
What the assessment is not
A lower assessment does not mean a capture is fake. A high one does not mean its content is true. The assessment is not a guarantee, not a fraud verdict, and not a measure of whether the photo shows something real.
The assessment describes the conditions of capture — device and environment signals — never the truth of the content. A perfectly genuine device can capture a staged scene; a real, honest photo can come from a device with a degraded assessment. That question — is the content itself truthful — is not one TrustCapture, or any signal-based system, can answer. Only the cryptographic proof's narrower claim (unaltered, from this device) is something we can actually stand behind with certainty.
Why we keep them apart
Blending them would let a guess borrow a proof's authority.
The signature is math: fixed rules, a definite answer, verifiable by anyone independently of us. The assessment is a heuristic: our best current read of signals that will keep improving, on a scale that reflects a judgment, not a fact. If we combined them into one "trust score," the heuristic half would quietly borrow the authority of the proof — a reader would have no way to tell which part of the number they could rely on with certainty and which part was our best guess. Keeping them visibly separate is what makes both parts honest.
Why assessments vary by device
Different platforms expose different signals.
iOS and Android give apps different levels of insight into device and environment integrity — that's a platform design choice, not a TrustCapture one. An assessment reflects whatever signals that specific device and platform can actually provide. A signal a platform simply doesn't expose is treated as neutral, never as a mark against the capture — absence of information is not evidence of a problem.
Where this is headed
More transparency over time.
We'd like verifiers to eventually see not just that an assessment exists, but exactly which signals contributed to it and why — the same "show the evidence, not a verdict" idea behind the cryptographic proof, extended to the assessment too. That's a direction we're building toward, not a feature that exists today.
See it on a real verification page.
The proof and the assessment appear together — clearly separated — on every TrustCapture verification page.