Information Integrity // Truth Forensics 02

Why Deepfake Detection Needs Chain of Custody

Desmond Otieno Odhiambo · ClearGlass Intelligence · Burlington, Ontario · 30 September 2026

A detector gives you an estimate, and the estimate ages as generators improve. A custody record gives you a fact you can show. Most synthetic-media programmes buy the first and skip the second.

Two different questions

Detection asks: does this content look generated or altered? Provenance asks: where did this file come from, and has it changed since? They fail in opposite ways.

DetectionProvenance and custody
OutputA likelihood or a set of indicatorsA record: hashes, times, hands, transformations
Main weaknessAdversarial and time-sensitive; false positives on recompressed or edited-but-honest mediaSays nothing about what happened before the first record; can be missing entirely
What absence means“No indicators found” is not authenticityNo record is a gap, not proof of tampering

NIST's AI 100-4, Reducing Risks Posed by Synthetic Content (November 2024) surveys provenance tracking, labelling and detection as complementary approaches, not substitutes. That is the right frame. Detection without custody gives you a finding you cannot anchor. Custody without detection gives you a well-documented file you have not examined.

What a hash proves, and what it does not

A SHA-256 taken when a file is received proves that the bytes examined later are the same bytes received. That is all. It does not prove the camera was where the metadata says, that the scene was staged, or that the file was not generated before it reached you. In the ClearGlass console this is stated on every hash comparison: cryptographic verification proves integrity relative to a known hash or signature; it does not prove that the content depicts what it claims to depict.

The value of the hash is that it makes everything after intake checkable. Without it, “the video we analysed” and “the video in the court bundle” are two claims about two files.

Content Credentials: useful, strippable, and not a verdict

The C2PA specification (Content Credentials) lets a capture device or editor attach a signed manifest to a file. It is stored as a JUMBF box in a JPEG's APP11 segments or a PNG's caBX chunk, and bound to the content by hash. A valid manifest tells you who signed which assertions about the file's history.

Three limits matter in practice:

What Canadian evidence law asks for

Canadian courts do not ask whether a file “is real” in the abstract. Under section 31.1 of the Canada Evidence Act, the party offering an electronic document must prove it is what it purports to be, a threshold courts have described as low. Under section 31.2, the best evidence rule for electronic documents is met by proof of the integrity of the electronic documents system in which it was recorded or stored. Section 34.1 of Ontario's Evidence Act sets out comparable rules for electronic records.

The authentication threshold is low. That is exactly why system integrity matters. When a convincing synthetic file can clear a low threshold, the fight moves to integrity: who held it, what touched it, and whether you can show that. A detector score does not answer those questions. A custody record does. This is not legal advice; counsel decides how any record is used.

A custody chain that survives scrutiny

  1. Hash at intake, before anyone opens, edits or forwards the file. Record who received it, when and how.
  2. Keep custody receipts. When a file passes between people or systems, record its hash on the way. A later match to an earlier receipt is what lets integrity be verified rather than merely recorded.
  3. Never edit the original. Every crop, trim or export is a new item with its own hash and a recorded parent.
  4. Append, never overwrite. Chain the log so each entry carries the hash of the one before it; altering history breaks every link after it.
  5. Run detection on top. Indicators attach to a specific hash, with their method, confidence and limits.
  6. Record the human decision. The person who ran the analysis should not be the one who accepts it.

The ClearGlass Truth Forensics console implements this chain in your browser, on your own files or on a synthetic demonstration case. Nothing is uploaded. Companion pieces: Truth Is an Evidence Graph and When AI Cannot Determine the Truth.

Claim boundary. Statutes and standards are summarised, not interpreted; read the linked sources and take legal advice for any real matter. The ClearGlass Truth Forensics system provides analytical indicators and provenance analysis. It does not independently establish the truth of real-world events and should not replace qualified forensic, legal, investigative, or evidentiary review.