What is image authentication: establishing that a photo or video was recorded on this device, at this time and in this place, and has not been altered since, so a reviewer can rely on it as evidence.
Image authentication is the process of establishing that a photo or video is what it claims to be: recorded on a particular device at a particular time and place, and unchanged since it was received. It answers the questions a claims handler, inspector or landlord asks before acting on an image, and it answers them with records rather than with the submitter's word.
It matters because a picture in an inbox carries no proof of its own. Any file can be renamed, re-dated or edited before it is sent. The term is the same in UK and US usage; "photo verification" and "image verification" describe the same aim, and image forensics is the laboratory discipline that examines an image after the fact when no authentication was built in at the time.
What image authentication answers
- Origin: was this recorded by the camera in the session, or selected from the gallery as an existing file?
- Time: when was it received, on a clock the submitter does not control?
- Place: where was the device when it recorded, and did the submitter allow location to be read?
- Integrity: is the file the reviewer sees today the same file that arrived, byte for byte?
The four answers together are the provenance of the image. Any one of them alone is weak. A timestamp without integrity can be attached to a changed file; integrity without origin proves that an edited photo is still the same edited photo.
How image authentication works in a guided capture
Venta Capture, a product of VentaVid, builds the four answers into the submission rather than reconstructing them later:
- Recorded in the session: the participant opens a secure, personal link in the mobile browser and records with the in-session camera. Each such item is marked as taken via the platform. A photo chosen from the gallery instead is labelled "Provenance: Not verified" and checked separately.
- Server receipt time: the moment the submission arrived is recorded server side. Any time written inside the file by the phone is shown but marked unverified.
- Location: the device position is recorded during the session where the participant allows it. A refusal is recorded as neutral and never counted against the submission.
- Seal: the submission receives a SHA-256 digital fingerprint and a signed seal with a version, plus a downloadable manifest so a third party can verify the file outside the platform.
Alongside the seal sits the session timeline: the link created, each time it was opened, the recording events, the submission, and every later action by the team. That is the difference between a photo with a date on it and a sealed submission with a history.
Image authentication example: a lease return with a kerbed alloy
A leasing company sends a return-inspection link three days before collection. The driver walks the car through the guided steps: four corners, each wheel, the odometer, the interior, and a short video with commentary. On the nearside front wheel the video shows kerb scuffing across two spokes.
The driver later disputes the recharge, saying the damage happened in the collection agent's care. The file answers without argument. The wheel photo was recorded in the session, received on the Tuesday evening before collection, located within the driver's postcode, and the fingerprint on the file matches the manifest. The scuff was there before the car was handed over. The dispute closes on the record, not on who sounds more certain.
What image authentication does not do
It does not prove when the damage occurred. The receipt time proves when the system received the image. The scuff could be a week old or a year old; the record shows it existed by that date.
It does not prove the content is truthful. A properly authenticated recording can still show a staged scene or the wrong vehicle. Authentication settles origin, time, place and integrity; the assessment of what the image shows stays with the qualified person.
It does not replace judgement with a score. Where a submission carries signals, each comes with its caveat, and a person decides.
The mistakes teams make: accepting emailed attachments and calling them authenticated, reading a phone's own timestamp as proof, and storing images in a shared drive where nothing tells you whether the file was changed after the decision.
Where the authentication record lives
The seal, the manifest, the receipt time, the location record and the session timeline stay in the case file next to the media, under the organisation's own case reference. The manifest can be downloaded and checked outside the platform, which is what "externally verifiable" means in practice, and the seal can be renewed when a retention policy requires it. Details at the Venta Capture page.