Skip to content

IDENTITY · 2026-08-17

Org identity on Content Credentials

One signing identity across your apps — without turning Krusade into another asset library.

When a newsroom, agency, or brand signs outbound media, the interesting question is not “was something signed?” but “was it signed as us?” C2PA Content Credentials can carry that answer. Krusade's job is to make the identity consistent across tools without becoming a DAM, a blockchain, or a private receipt-chain ledger. Files stay where they already live. We stamp the publish handoff.

One certificate, held by Krusade

Production signing is designed so claim-signing keys never sit on application disk. Krusade signs all customer content under a single Krusade certificate. You do not manage CSRs, rotation, or per-user certs. Manifests read as signed by Krusade as the claim generator. That trade-off is documented on the Trust & Security page.

It removes certificate toil. It also means the cryptographic issuer is Krusade until an organization brings its own certificate. Current deployments still sign with a development certificate, so many verifiers report the issuer as untrusted even when the signature is cryptographically valid. A CA-issued C2PA Trust List certificate is the next milestone on that public trust page. Valid and trusted are different fields: valid is the math on this file; trusted is whether the chain matches a known root.

Developer, Team, and Enterprise

On the pricing page, Developer is $0: the first 1,000 signs are free (lifetime), then pay-as-you-go at $0.015 per sign, with Krusade shared certificate identity and unlimited public verification.

Team is $49/month. It is positioned as company identity for content credentials—one signing identity across your apps. The plan includes a DNS-verified org domain under Krusade's cert, 3 seats (+$15/extra), 5,000 signs/month included, then $0.010 per sign via credits, plus IPTC metadata and webhook integrations. Organization identity, DNS-verified domains, and team invites are Team-plan features. After you subscribe, you register an organization name and domain, publish a DNS TXT record, and verify. Until the domain verifies, credentials still sign under the Krusade certificate without that domain claim.

Enterprise is custom and contact-only. The public plan lists an independent org identity hub: bring-your-own certificate / DIDs (planned), org-wide signing API and audit trail, multi-ingredient provenance trees, on-premises or dedicated cloud, and SLA support. BYO cert is not self-serve today.

What appears at verify time

Public verify and third-party C2PA tools show the signing certificate and the assertions in the active manifest. On Team, once the domain is verified, credentials can carry that org domain so downstream viewers see a consistent organization—not a pile of personal signing identities. Signature history is the audit trail: who signed, when, which asset, under which org.

Members share that identity. There are no per-user certificates to distribute. The signing API and the browser sign flow both stamp under the org's current identity. Optional signer-name assertions exist as an opt-in claim inside the C2PA envelope; they are not a replacement for org-level identity.

That audit trail is the answer to “who signed what, when?” across tools that do not share a library. It is not version control, rights search, or a place to store masters. If a buyer's primary need is a canonical media archive, Krusade is the wrong product; the DAM stays the system of record and Krusade stamps the file that leaves it.

DNS verification is a TXT record published on the org domain, then checked from your account. It does not issue a public CA certificate to the customer. Team identity still rides under Krusade's certificate, with the verified domain as the organization claim once that check succeeds. Enterprise BYO certificate and DID support is listed as planned on pricing—talk to us; it is not a self-serve toggle.

Krusade is the independent layer when assets leave an editor, a CMS, or a CDN and must still be trusted. We do not replace Adobe Content Credentials as a format; we speak the same C2PA standard. Start with What is C2PA? and the Docs if you are wiring the stamp into a pipeline rather than clicking through the browser.