Skip to content
WatermarkAudit

Pipeline audit

Find the step that destroys it.

Knowing that provenance was lost is not useful. Knowing where it was lost is, because that names the system to go and fix. Drop the same asset as it appears at each stage of your workflow — as submitted, after conversion, as published — and this shows you exactly which step rewrites the file.

1

Drop this stage's file

or

2

Drop this stage's file

or

3

Drop this stage's file

or

The problem this exists for

Regulation is pushing AI providers to mark their output, and cameras and editors increasingly sign theirs. All of that effort lands upstream of you. Then it reaches a content management system that resizes on upload, or an optimiser that recompresses, and every credential is destroyed before a single reader sees the file.

Nobody gets told when this happens. There is no error, no warning, and the image looks identical. The only way to find out is to check a file at each stage and compare — which is what this does.

How to gather the files

Save the asset as the contributor sent it, as it sits in your asset manager or after conversion, and as your live site actually serves it — right-click and save from the published page, not from your own drafts.

What you'll learn

Which stage strips credentials, which strips metadata and GPS, and whether anything is resized or recompressed along the way. Each break names one system.

What to do about it

A stage that rewrites files cannot be argued out of it, but it can often be configured — disabling automatic resizing, or signing after conversion rather than before.