Information Integrity // Truth Forensics 02
Why Deepfake Detection Needs Chain of Custody
Desmond Otieno Odhiambo · ClearGlass Intelligence · Burlington, Ontario · 30 September 2026
A detector gives you an estimate, and the estimate ages as generators improve. A custody record gives you a fact you can show. Most synthetic-media programmes buy the first and skip the second.
Two different questions
Detection asks: does this content look generated or altered? Provenance asks: where did this file come from, and has it changed since? They fail in opposite ways.
| Detection | Provenance and custody | |
|---|---|---|
| Output | A likelihood or a set of indicators | A record: hashes, times, hands, transformations |
| Main weakness | Adversarial and time-sensitive; false positives on recompressed or edited-but-honest media | Says nothing about what happened before the first record; can be missing entirely |
| What absence means | “No indicators found” is not authenticity | No record is a gap, not proof of tampering |
NIST's AI 100-4, Reducing Risks Posed by Synthetic Content (November 2024) surveys provenance tracking, labelling and detection as complementary approaches, not substitutes. That is the right frame. Detection without custody gives you a finding you cannot anchor. Custody without detection gives you a well-documented file you have not examined.
What a hash proves, and what it does not
A SHA-256 taken when a file is received proves that the bytes examined later are the same bytes received. That is all. It does not prove the camera was where the metadata says, that the scene was staged, or that the file was not generated before it reached you. In the ClearGlass console this is stated on every hash comparison: cryptographic verification proves integrity relative to a known hash or signature; it does not prove that the content depicts what it claims to depict.
The value of the hash is that it makes everything after intake checkable. Without it, “the video we analysed” and “the video in the court bundle” are two claims about two files.
Content Credentials: useful, strippable, and not a verdict
The C2PA specification (Content Credentials) lets a capture device or editor attach a signed manifest to a file. It is stored as a JUMBF box in a JPEG's APP11 segments or a PNG's caBX chunk, and bound to the content by hash. A valid manifest tells you who signed which assertions about the file's history.
Three limits matter in practice:
- It can be removed. Re-encoding or a screenshot drops it. Absence proves nothing.
- Presence is not validity. Until the signature, certificate chain and hash binding are checked, a manifest is bytes. The ClearGlass engine detects manifest presence and says, explicitly, that it has not validated it.
- A valid manifest is the signer's statement. It is strong provenance for the file, not proof of the scene.
What Canadian evidence law asks for
Canadian courts do not ask whether a file “is real” in the abstract. Under section 31.1 of the Canada Evidence Act, the party offering an electronic document must prove it is what it purports to be, a threshold courts have described as low. Under section 31.2, the best evidence rule for electronic documents is met by proof of the integrity of the electronic documents system in which it was recorded or stored. Section 34.1 of Ontario's Evidence Act sets out comparable rules for electronic records.
The authentication threshold is low. That is exactly why system integrity matters. When a convincing synthetic file can clear a low threshold, the fight moves to integrity: who held it, what touched it, and whether you can show that. A detector score does not answer those questions. A custody record does. This is not legal advice; counsel decides how any record is used.
A custody chain that survives scrutiny
- Hash at intake, before anyone opens, edits or forwards the file. Record who received it, when and how.
- Keep custody receipts. When a file passes between people or systems, record its hash on the way. A later match to an earlier receipt is what lets integrity be verified rather than merely recorded.
- Never edit the original. Every crop, trim or export is a new item with its own hash and a recorded parent.
- Append, never overwrite. Chain the log so each entry carries the hash of the one before it; altering history breaks every link after it.
- Run detection on top. Indicators attach to a specific hash, with their method, confidence and limits.
- Record the human decision. The person who ran the analysis should not be the one who accepts it.
The ClearGlass Truth Forensics console implements this chain in your browser, on your own files or on a synthetic demonstration case. Nothing is uploaded. Companion pieces: Truth Is an Evidence Graph and When AI Cannot Determine the Truth.