Inspiration

Veris started with a simple concern: what happens when nobody believes a real photo anymore? Deepfakes and synthetic media are getting better every day, and that becomes especially dangerous for journalists and photographers working in conflict zones. A photograph can be the only evidence that something happened, yet it can also be dismissed as “AI” whenever it becomes inconvenient. Existing solutions like C2PA and Truepic rely heavily on software and metadata, which can potentially be stripped or altered. We wanted to start somewhere harder to fake: the hardware itself. That became the idea behind Veris: a camera where authenticity is created at the exact moment a photo is taken, rather than added afterward.

What it does

When you take a photo, Veris immediately hashes it and signs that hash using a TPM 2.0 chip. The TPM holds a hardware-bound private key that never leaves the chip, meaning neither software nor even we can simply copy it and create another valid signature.

The pipeline is:

  1. Capture — The camera takes the image.
  2. Sign — The image hash is signed by the TPM.
  3. Store — The image and metadata are stored on IPFS and backed up to Filecoin.
  4. Prove — RISC Zero and vlayer generate a zero-knowledge proof of authenticity.
  5. Verify — A smart contract on Ethereum verifies the proof.
  6. Mint — A Veris NFT acts as the certificate of authenticity.
  7. Claim — Anyone can scan a QR code and verify the image through Privv, without needing an account or special software.

The important part is that verification doesn't depend on simply trusting Veris. The proof can be independently checked.

We're building this as three form factors:

  • Standalone Veris Camera
  • Veris Hotshoe for DSLR and mirrorless cameras
  • Veris Clip for phones, which independently captures a verified image

How we built it

Our first working prototype runs on a Raspberry Pi 4 with a camera module. The TPM 2.0 is the core of the system, providing the hardware root of trust.

Around that, we built the rest of the pipeline using:

  • RISC Zero + vlayer for zero-knowledge proofs
  • IPFS for content-addressed storage
  • Filecoin for durable backup
  • Ethereum for on-chain verification
  • Privv for QR-based verification

We also tested Veris against AI-generated images, including one generated by Gemini that even carried Gemini's own watermark. Gemini's detection couldn't confidently identify it as AI-generated. Veris still caught it. That test was a big moment for us because it showed that we weren't just building another AI detector. We were approaching the problem differently: proving where the image came from.

Challenges

The hardest part was getting the entire pipeline to work together without compromising the security model. Zero-knowledge proofs aren't exactly built for speed, and we had to make the system practical without removing the privacy guarantees.

What we learned

The biggest lesson was that a hardware root of trust makes a fundamentally different promise from a software watermark. We also realised that privacy and authenticity don't have to be opposites. With zero-knowledge proofs, you can prove that something is authentic without necessarily revealing who created it or other sensitive information. Starting with journalists and conflict photographers also helped us define the problem much more clearly than trying to solve “fake media” for everyone at once.

What's next

Our next major step is the Veris Hotshoe attachment. The custom VHS-P1 Rev A board has already been designed and is heading to fabrication. After that, we're looking toward filing the patent and eventually expanding Veris beyond journalism into any situation where a photograph needs to be trusted without simply asking someone to take our word for it.

Built With

Share this project:

Updates

Submission history