Microsoft: C2PA may not survive a crop, transcode or compression

Microsoft's provenance page lists the edits that can drop credentials and watermarks. Which of them a Sume trim, filter or caption job could be, and a check.

4 min readSume
All posts

Microsoft is blunt about where provenance fails. In the limitations section of its Foundry provenance page, read on 2026-10-05, it says provenance does not prove trustworthiness or authorship, and that credentials and watermarks may not survive cropping, resizing, filters, format conversion, transcoding or compression.

Every one of those is a normal step in an ad workflow. So the practical question is not whether the generator marked the file; it is whether the file you upload still carries the mark.

Mapping Microsoft's list to Sume jobs

Microsoft's listed risks vs documented Sume behaviour (read 2026-10-05)
Edit Microsoft listsSume job that could do itWhat the Sume docs say
TranscodingVideo trim, exactRe-encodes with libx264, yuv420p; kept audio as AAC
No re-encodeVideo trim, keyframeStream copy; the cut can start a GOP early
Filters, croppingVideo filterffmpeg ops such as dim and crop
Burned-in changesVideo captionsRenders captions onto the video

Read the table carefully

The Sume column is what the trim docs and captions docs say about how the job works. They do not say what happens to C2PA data or an invisible watermark in the input. A stream copy is a different operation from a re-encode, but I cannot claim either preserves or drops credentials, because the Sume docs are silent on it.

The safe reading is to treat any Sume edit as capable of changing the file's embedded data, and to test it.

A before-and-after test

Run this on the generator's file and on the Sume output. It shows container and stream changes. It cannot validate C2PA, so also run a C2PA verifier on both, and compare the results.

ffprobe -v error -show_format -show_streams before.mp4 > before.txt
ffprobe -v error -show_format -show_streams after.mp4 > after.txt
diff before.txt after.txt

Order of operations

If you need a mark to stay on the final file, do edits first and generate or sign last, where you control it. If you cannot, plan disclosure that does not depend on the file: the platform's AI toggle, a caption line, or burned-in text. Sume's docs describe a metadata field on video, image and music jobs that Sume stores on the job and does not send to the provider. I found nothing in the docs about Sume adding, keeping or removing C2PA credentials, watermarks or platform labels, so treat that as undocumented and check the delivered file.

Also test the last step you control. Many ad platforms re-encode every upload for their own delivery, so even a perfect file may lose credentials after you hand it over. That is outside your control and outside Sume's, which is one more reason to put the disclosure in a place that survives re-encoding: the platform's AI setting, your caption, or text burned into the frames.

Sources

Related posts

More in Media tools

All Media tools posts

Written by Sume