Certificate Policy & Certification Practice Statement (CP/CPS)
Version: 1.0
Effective Date: July 2026
This Certificate Policy (CP) and Certification Practice Statement (CPS) describes the practices Tauth follows as a C2PA Certification Authority when issuing, managing, renewing, and revoking certificates used for signing Content Credentials.
1. Introduction
This document applies to all certificates issued under the Tauth C2PA CA hierarchy and conforms to the C2PA Trust Model and applicable conformance program requirements. It defines the roles, responsibilities, and obligations of the CA, subscribers, and relying parties.
2. Certificate Issuance
Certificates are issued only after successful identity validation of the applicant organization, verification of key possession, and acceptance of the Subscriber Agreement. Issued certificates identify the subscriber as the signer of Content Credentials.
3. Key Management
CA private keys are generated and protected in hardware security modules. Subscribers must generate and store their private keys in secure environments and must never share or export them in unprotected form.
4. Revocation
Certificates are revoked upon subscriber request, key compromise, breach of the Subscriber Agreement, or when required by the C2PA conformance program. Revocation status is published through our repository.
5. Contact
Questions regarding this CP/CPS may be directed to ca@tauth.io.