For platforms and enterprise

Verify the images you cannot vouch for

Platforms and enterprises handle images from people they do not control, and the rules now expect them to know which images are real. Lumethic checks a photo against its RAW file and records the result as a C2PA credential, over an API that handles the volumes a platform deals with.

What Lumethic is

How it fits into a platform

Lumethic runs as an API. You send a photo together with its RAW file, the service compares them, and it returns a result and a C2PA credential. Nothing runs on your side and nothing changes about how photos are taken, so it works with the cameras and RAW files your suppliers already use.

The check reads the sensor data in the RAW file and returns a clear result you can store and act on. That suits a pipeline that has to reach the same decision on every image it handles, at scale.

What you get

For high-volume pipelines

API integration

A REST API with authentication, webhooks, and client libraries. Verification runs inside your existing upload or moderation flow.

Verify, then sign

Each photo that passes gets a C2PA credential recording what was checked and when. The credential is interoperable, and any C2PA-compatible tool can read it.

Works with existing kit

It uses the RAW files cameras already record, so your suppliers and contributors need no new hardware and no special capture app.

Volume-based pricing

Pricing is based on volume and agreed directly, so it follows how your verification load actually grows.

Why it matters now

The rules take effect in August 2026

The EU AI Act brings transparency duties for AI-generated images, and the first obligations for organisations that publish or distribute content apply from 2 August 2026. The ESPR adds product-passport duties for marketplaces. Both mean a platform has to know which images are real at the point of upload, and penalties can reach 15 million euros or 3 percent of worldwide turnover. A verified credential gives a platform a record it can show a regulator, grounded in the camera file.

See the compliance overview and AI Act timeline

Integration and data handling

For a technical and procurement review

A review usually comes down to how verification integrates, where data is processed, and what happens to the files afterwards.

  • A REST API with authentication, webhooks, and client libraries, plus an MCP server for agent-based workflows.
  • RAW files are processed in memory and not stored, so the most sensitive input is short-lived.
  • Processing runs on infrastructure in the European Union, and deletion follows Article 17 of the GDPR.
  • A data processing agreement is available on request.

Talk to us about integration

Write to us with a few lines about your platform, what you need to verify, and the volumes involved. A real person reads it and replies. If you would rather look around first, the API documentation and pricing are public.