Certificate Policy & Certification Practice Statement (CP/CPS)

Version: 1.0
Effective Date: July 2026

This Certificate Policy (CP) and Certification Practice Statement (CPS) describes the practices Tauth follows as a C2PA Certification Authority when issuing, managing, renewing, and revoking certificates used for signing Content Credentials.

1. Introduction

This document applies to all certificates issued under the Tauth C2PA CA hierarchy and conforms to the C2PA Trust Model and applicable conformance program requirements. It defines the roles, responsibilities, and obligations of the CA, subscribers, and relying parties.

2. Certificate Issuance

Certificates are issued only after successful identity validation of the applicant organization, verification of key possession, and acceptance of the Subscriber Agreement. Issued certificates identify the subscriber as the signer of Content Credentials.

3. Key Management

CA private keys are generated and protected in hardware security modules. Subscribers must generate and store their private keys in secure environments and must never share or export them in unprotected form.

4. Revocation

Certificates are revoked upon subscriber request, key compromise, breach of the Subscriber Agreement, or when required by the C2PA conformance program. Revocation status is published through our repository.

5. Contact

Questions regarding this CP/CPS may be directed to ca@tauth.io.