AURA — Open Technical Specification for Verifiable Origin Declarations and Asset Integrity
Signed origin declarations, asset integrity and independent verification across digital content types
AURA-STANDARD v1.2.1 — published open technical specification for review, interoperability work and controlled pilots
What is AURA?
AURA is an open technical specification for digital assets. It defines signed origin declarations, asset-integrity evidence, issuer-declared issuance times, rights-reservation signals and independently verifiable evidence packages.
AURA can establish technical facts such as asset integrity and signature validity. It does not establish the truth of a declared origin, the real-world identity or authority of an issuer, authorship, ownership, originality, infringement, liability or actual AI use. Legal qualification remains for institutions, auditors, regulators or courts.
Specification, Pilot and Verifier
- AURA is the open technical specification.
- AUTHENTICA / LockDNA is the first pilot implementation.
- AURA-VERIFIER is the independent verifier.
AUTHENTICA is a pilot implementation and is not the AURA specification itself.
Official References and Links
Scope & Principles
- Signed origin declaration: an issuer can declare an origin in a signed evidence object
- Cryptographic guarantees: verifiable asset integrity and manifest-signature validity
- Time boundary:
issued_at is issuer-declared unless separate trusted timestamp evidence is supplied
- Open architecture: separation between the AURA specification and independent implementations
- Tool-agnostic design: no proprietary platform, vendor, model provider, repository host or software assistant is required
- Privacy by design: no mandatory civil identity, account, verification telemetry or remote resolver
- European workflows: support for evidentiary processes involving copyright, AI transparency and TDM reservation
AURA is non-intrusive. A manifest may remain detached and does not need to modify the digital asset.
What AURA Does (and Does Not Do)
AURA Does
- Define a structured, machine-readable AURA Manifest for signed declarations, rights-reservation signals and integrity evidence
- Enable independent checks of asset integrity, canonical signed payloads and Ed25519 signatures
- Distinguish issuer-declared issuance time from independent trusted timestamp evidence
- Support local and offline verification when evidence and trust material are supplied locally
- Allow optional links to external identifiers and prior evidence
AURA Does Not
- perform content recognition or fingerprinting
- maintain any fingerprinting database
- embed code, watermarking or DRM inside files
- analyse the content of the work
- make decisions about licensing or remuneration
- decide legal ownership, infringement or liability
- prove civil identity, authorship, authority or the truth of a signed declaration
- prove hidden usage by an AI model, grounding, citation or usage completeness
- require verification-event logging or a central registry
AURA provides a verifiable technical artefact. Law, audit, regulator or court decide legal qualification.
Canonical schemas
- AURA manifest v1.0.0 — frozen canonical schema
- AURA manifest v1.1.0 —
reference_anchor and prior_evidence evolution
- v0.1 material is retained as legacy / superseded public draft
AURA supports detached and fileless evidence. Asset bytes are required only when checking an asset-integrity claim.
Privacy and Offline Verification
- AURA cryptographic validity does not require publication of a natural person's civil identity.
- Verification-event logging, analytics and telemetry are not AURA conformance requirements.
- When the manifest, asset where applicable, public key and trust material are local, cryptographic verification can complete without an external network request.
- Stable issuer identifiers and keys improve continuity but can increase cross-manifest linkability; scoped or rotated identifiers remain an explicit deployment choice.
- Remote convenience loading is optional and may create ordinary access logs at the contacted server.
See the privacy principles,
the conformance requirements
and the privacy and offline-verification note.
Governance
AURA is published as an open technical specification (AURA-STANDARD v1.2.1).
Future governance may evolve toward an open, transparent and multi-stakeholder process inspired by recognized open standardization practices.
Key principles:
- No single company owns or controls AURA
- No single platform, vendor, institution, model provider or repository host controls AURA
- Implementations remain independent if they comply with the published specification
- Discussions occur in writing and transparently
- The Charter of Independence prevails over any future governance model
AURA is designed for long-term institutional governance without capture by a single actor.
AURA currently has no independent certification or enforcement body. Public requirements and tests make conformance claims reviewable but cannot sanction an abusive deployment.
Why an Open Evidentiary Layer Matters
The European Union has a strategic mandate to protect:
- cultural diversity
- copyright and authorship
- transparency of rights management
- lawful use of works in the AI era
With generative AI, large-scale datasets and automated transformations, portable and reviewable evidence has become a foundational issue.
AURA provides:
- signed origin declarations for human, hybrid and AI-generated works
- machine-readable transparency and rights-reservation declarations
- cross border interoperability between platforms, CMOs and institutions
- technical traceability that can support institutional and regulatory workflows
AURA does not replace existing regulations or determine compliance; it can support evidentiary workflows within them.
Interoperability
AURA complements, but does not replace:
- ISRC / ISWC
- DDEX metadata frameworks
- C2PA (content authenticity)
- National copyright registries
AURA focuses on origin declaration, manifest integrity and rights-reservation signals. It complements content-authenticity systems without replacing them.
License
The public materials are released under the Apache License 2.0, a permissive license suitable for institutional, industrial and public sector review and adoption.
Intellectual Property Position
This published open technical specification reflects an independently conceived and publicly documented specification.
It was developed prior to, and separately from, any external confidential collaboration.
The AURA specification contains no confidential or proprietary information from any partner, institution or private entity.
All concepts and structures described herein are published openly for public review through a documented change process.
The AURA specification is released under the Apache License 2.0.
No additional rights or claims are granted or implied beyond those explicitly set forth by this license.
Get Involved
The development of AURA is iterative and open. Feedback is welcome from:
- creators
- collecting societies
- digital platforms
- AI labs
- public institutions
- researchers and standardization bodies
Participate:
© 2026 — AURA — AURA-STANDARD v1.2.1 · Open technical specification