WaveSign Blog

How to Prove an Image Has Not Been Edited

Learn how tamper-evident image authentication works, what it can prove, and why signed files need matching verification metadata.

Try WaveSign →

How to Prove an Image Has Not Been Edited

When an image becomes evidence, a deliverable, or a record, the question is simple: can you show that the file being reviewed is the same file that was signed earlier?

WaveSign is built for that problem. It embeds an invisible authenticity signal into the image pixels and generates verification metadata. Later, the signed image can be checked with the matching sig.json file and the same secret key used at signing.

This is different from adding a visible watermark. The goal is not to make the image look branded. The goal is to make later changes detectable while keeping the signed image visually identical, or close to identical, to the original.

What "not edited" means

In practical workflows, proving an image has not been edited means proving that the signed file still matches the signed state.

For WaveSign, verification needs three things:

  1. the signed image file
  2. the sig.json verification file created during signing
  3. the same secret key used when the image was signed

If the file was modified after signing, verification should fail. If the wrong key or wrong metadata is used, verification should also fail.

Why metadata alone is not enough

Image metadata can be useful, but it is fragile. EXIF data, timestamps, filenames, and platform upload records can be stripped, rewritten, or separated from the file.

WaveSign takes a different approach. It adds an invisible signal to the pixels themselves, then stores verification metadata outside the image in sig.json. The signed media and metadata are meant to travel together as an authenticity package.

That distinction matters. The image alone is not enough to verify in the current WaveSign flow. The external verification file is mandatory.

A basic image authentication workflow

Use WaveSign before the image leaves your controlled workflow.

  1. Upload the image.
  2. Enter the signing key.
  3. Download the signed image and sig.json.
  4. Store or share both files together.
  5. Later, verify the signed image with the same key and matching sig.json.

For teams, the operational rule is simple: never separate the signed media from its verification file.

What WaveSign can help detect

WaveSign evaluation documents report strong detection on visible edits across tested scenarios, including overlays, cropping, brightness changes, compression, format roundtrips, blur, noise, and wrong-key checks.

The careful wording is important: these are observed evaluation results, not a formal security proof. Public claims should say "tamper-evident" rather than claiming the file cannot be altered.

What WaveSign does not replace

WaveSign does not replace chain-of-custody policy, secure storage, access control, or human review. It also does not prove who physically took a photo unless your workflow connects the signing key to a person or device.

It answers a narrower and useful question: does this signed image still verify against the metadata and key used when it was signed?

Best use cases

WaveSign fits workflows where images need to remain inspectable but later integrity matters:

  • insurance claim photos
  • field inspection photos
  • construction progress records
  • legal or investigation evidence images
  • scanned document images
  • before-and-after records

In each case, the value comes from signing early, storing the signed image and sig.json together, and verifying before relying on the file.

Bottom line

To prove an image has not been edited, do not rely only on filenames, timestamps, or platform records. Sign the image, keep the matching sig.json, and verify the signed file with the same key when authenticity matters.

Ready to authenticate your files?

Sign images and PDFs with an invisible authenticity signal. Verify later with the same key.

Sign a File Now →