Quantum-Safe Digital Provenance System with AI Redaction 

The Quantum-Safe Digital Provenance System is a capability designed to help our customers prove that digital content is authentic, unaltered and attributable to a trusted source. 

It was developed to address growing challenges: 

  • increasing misuse of synthetic and AI-generated content 
  • the need to prepare digital trust systems for post-quantum cryptography 
  • the ability to support redaction while maintaining its original authenticity 

The system provides a way to sign, redact, and verify documents while preserving trust in the remaining visible content. It is designed to support standards-aligned digital provenance for official and high-trust communications. 

Core functionality 

Quantum-safe digital signing 

The solution applies ML-DSA-87 digital signatures to document provenance data, providing a post-quantum signature path for authenticity protection. 

This allows content to be cryptographically bound to its source using a modern signature scheme aligned with emerging post-quantum standards.  

Redaction-preserving authenticity 

A key feature of the system is its ability to support authorised redaction without invalidating authenticity for the remaining content. 

Rather than breaking trust when content is removed, the system preserves verification of the non-redacted portions of the document. This enables selective disclosure of sensitive material while retaining confidence in what remains visible.  

Merkle-tree proof structure 

It uses a SHA-512 Merkle tree structure to support efficient proof generation and validation. 

This design localises changes to the redacted portions of the document, allowing verification to continue without re-signing the entire document. It also keeps proof material compact and structured for validation workflows.  

PDF-based signing and redaction workflow 

The system includes a working PDF-first workflow that allows a user to: 

  • upload a PDF  
  • select tokens or content for redaction  
  • sign the document  
  • generate a redacted output  
  • verify that the redacted version still validates against the authenticated original  

This demonstrates the end-to-end feasibility of authenticity-preserving redaction in a practical document workflow.  

How Authenticity survives redaction 

Merkle tree creation

Figure 1. Six-step workflow showing PDF upload, Merkle-root creation, ML-DSA-87 signing, redaction processing and retained-content verification. 

 AI-assisted redaction support 

AI-assisted token redaction, supporting faster identification of content. 

This functionality is intended to improve usability and reduce manual effort while keeping the human user in control of what is actually redacted.  

Verification workflow 

The solution includes a verification mechanism that checks the redacted document against the original authenticated root hash. 

This gives verifiers a way to confirm that: 

  • the document originated from a trusted signing process  
  • permitted redactions were applied  
  • the remaining content is still authentic  

The result is a trust-preserving verification model rather than a traditional all-or-nothing signature outcome. 

Jellyfish PKI 

Jellyfish PKI connection 

It extends established PKI trust concepts into a document-provenance use case by binding content integrity and source identity to a quantum-safe signature path. 

Where does it fit in the Jellyfish stack?  

The solution builds on Jellyfishes existing signature based support for PDFs and codesigning. It is best treated as an adjacent provenance and verification capability that can integrate with existing trust services, rather than as a replacement for core certificate-management functions. 

How does it interact with the wider system?  

When connected into broader trust workflows, it can support verified publishing, controlled release of redacted material, clearer public trust signals, and future extensions such as browser-based verification and approval workflow integration. 

Integrity, Privacy and Trust 

A standards-aligned provenance layer that works across AI-generated and human-authored content, while keeping verification simple for end users 

Source and integrity assurance 

Bind content to the originating person, entity, or government organisation using secure digital signatures and PKI. 

Quantum-safe signature path 

Adopt ML-DSA-first signing and verification while remaining compatible with existing C2PA ecosystems and implementation patterns 

Privacy-preserving redaction 

Enable selective disclosure so sensitive sections can be removed while non-redacted content remains provably authentic. 

User-facing verification labels 

Add clear PDF / document add-ons and browser-style indicators to show whether content is signed, by whom, and in what capacity 

Strategic Advantages 

  • Assisting organisations prove authenticity in a future where both AI misuse and cryptographic transition are board-level issues. 
  • Enhanced trust and integrity in digital communications 
  • Better alignment with privacy and data protection obligations 
  • Future-proofed investment path for post-quantum transition 
  • Leadership position in standards-led cyber innovation 
  • Smart AI driven signature maintaining redaction 

Enhanced Cyber resilience 

Quantum-safe signatures reduce long-term exposure to AI-enabled manipulation and future cryptanalytic change. 

Authenticity validation 

PKI-backed provenance makes the source and integrity of official content independently verifiable 

Transparency with privacy 

Selective disclosure allows sensitive content to be redacted without discarding trust in what remains. 

Stronger public trust 

Citizens and partners gain a clearer way to separate official information from synthetic or altered content.