Skip to content
SoluBack to the network
Content authenticityProvenance and transparencyA walk through in five parts

Proof travels
with the media.

When software and AI agents can act on media at runtime, everyone with a stake needs to know what actually happened.

  1. 01

    The gap

    Why runtime matters

  2. 02

    Authority

    Before execution

  3. 03

    Governed runtime

    During execution

  4. 04

    Proof

    After execution

  5. 05

    Where we stand

    The guardrail

Chapter 01Why runtime mattersThe gap

Nobody could see
the moment.

Media used to be one fixed thing, produced once and sent identically to everyone. It is now assembled at runtime, in the moment a person experiences it, by software and agents making decisions.

Provenance and protection were built for the things around that moment: the file, the stream, the device. The moment itself was left unaccounted for. That is the gap this page walks through, and how it closes.

Then
One fixed experience
Now
Assembled per moment
Decided by
Software and agents
Accounted for
Until now, not at all
Chapter 02Before executionAuthority

Nothing runs without
permission.

The rights owner states what is permitted, on which terms and in which contexts, and that statement is machine readable.

Authority is resolved ahead of execution, not argued about afterwards. If a request cannot be resolved against it, the execution does not happen.

Declared by
Rights owner
Resolved against
Rights, policy, context, economics
Machine readable
Yes, carried by Aava
Default
No authority, no execution
Chapter 03During executionGoverned runtime

The Session can be
governed.

Step through a Session. At every step the runtime writes down what it did and what can be checked afterwards.

SessionSES-ED84-23A1-38E5
Opening
BeforeStep 1 of 6

Authority resolved

The request meets the rights owner's terms before anything is assembled.

Recorded
  • Rights reference and version
  • Permitted contexts
  • Commercial terms
Verified
  • The terms were in force at this moment
  • The request falls inside them

A one page PDF summary of the provenance and governance claims that apply to a governed Session. Generated in your browser, nothing is sent anywhere.

New dimension
Content protection

The stack protects delivery.
Not the decision.

Content protection is mature. Encryption and DRM control access, forensic watermarking traces a leak back to its source, monitoring finds copies in the wild, and device integrity keeps the client honest. All of it assumes a finished piece of media moving from A to B. When the experience is composed per person at runtime, there is no finished master to secure or trace, so the composition itself needs to be bounded and accounted for. The Session runs from source to screen, and so do provenance and governance: authority resolved at the source, every decision bounded on the way, proof still readable at the screen. A governed Session does that, and hands the existing layers a record they can act on.

DRM and encryptionAccess to the streamDecides who may decrypt and play, not what was assembled once playback began
Forensic watermarkingAttribution of a leakIdentifies the source of a copy after it escapes, not the terms applied while it played
Monitoring and takedownContent in the wildWorks on distributed copies, so it arrives after the experience is over
Player and device integrityThe endpointConfirms the client can be trusted, not that the composition stayed inside its rights
Governed SessionThe runtime decisionAdds the layer the others were never built for: bounded composition, written down as it runs
Agentic layerThe network at the speed of agentsEnd to end protection that moves as fast as the leak does, and finds where content was taken. Open to DRM and protection partners, under NDA
Chapter 04After executionProof

The Session ends.
The proof stays.

What was authorized. What happened. What was settled.

One verifiable record. The same facts for everyone with a stake. Proof that can travel with the media.

Two public commitments sit with Aava, the open source protocol created by the Solu team, and Solu builds its execution layer on it.

Credential 001

C2PA

Coalition for Content Provenance and Authenticity

Contributor Member, via Aava

The open standard behind Content Credentials: a tamper evident record that travels with the media and states where it came from, what was done to it and by whom.

Reference
Credential 002

EU Code of Practice

Transparency of AI-Generated Content

Signatory, via Aava

Signatories commit to making machine generated and machine modified media identifiable to the people who see it, in a form that survives distribution.

Reference
Credential 003

Aava

Authority and provenance at runtime

Open source, Solu is a contributor

The protocol that carries authority, rights, policy and transparency signals in a form software and AI agents read at runtime. Both commitments sit with Aava, so every Session inherits them, and the rules can be inspected rather than trusted.

Coming soon

The Aava
Foundation.

Aava will be placed in independent stewardship, so the rules that govern a Session belong to the parties bound by them rather than to any single company. We are opening the first conversations with rights owners, and with the content protection and provenance organisations that sit either side of them.

Tell us who you are and we will come back to you directly before the public introduction. Nothing is published, and nothing is shared.

Chapter 05The guardrailWhere we stand

People are not
the product.

Solu is not adtech and there is no surveillance profile at the centre of the model. The rights owner defines what may happen, the runtime holds it to that, and the record proves what did happen. Provenance added at the end of a pipeline is a label. Provenance carried by the Session is a fact.

Questions
Plain answers
01What is C2PA?
C2PA, the Coalition for Content Provenance and Authenticity, is the open standard behind Content Credentials. It defines a tamper evident record that travels with a piece of media and states where it came from, what was done to it, by whom and with which tools. A viewer, a platform or a regulator can read that record and verify it instead of taking a claim on trust.
02What does the European Union Code of Practice on Transparency of AI-Generated Content require?
It asks signatories to make AI generated and AI modified media identifiable to the people who encounter it: machine readable markings that survive distribution, and clear disclosure where it matters to the viewer. Transparency becomes an operating requirement rather than a statement of intent.
03How does Aava relate to content authenticity?
Aava carries authority, rights, policy and transparency signals in a form software and AI agents can read at the moment of execution, and it emits the record of what actually happened. Both public commitments sit with the protocol, so every Session inherits them, and Solu Networks is one of its contributors.
04If media is personalised, how can anyone verify what was delivered?
Every execution is resolved against authority and recorded. The brand can see what was delivered, where and on what terms. The rights owner holds the same record, and the Session credentials extend into Content Credentials, so what a person saw can be verified afterwards by the people and the regulators who need to check it.