Looking to implement C2PA? Trufo provides tooling to take care of everything from certificates and timestamping to watermarking and fingerprinting. Learn More
Trufo wordmark
Product

C2PA at Scale: Media Processing and Robust Servers

Scaling C2PA with task-based media processing and local SDKs on the Trufo Platform.

The Trufo Team · September 22, 2026

As we pass 1M API calls served per day and 100+ companies on the Trufo Platform, our engineering team has made some key upgrades to the Trufo Platform and the user experience to support production C2PA at scale.

For C2PA implementers, there are two useful characterizations of how the C2PA system works:

  • Trufo Signing (using our managed signing API/SDK) vs. Local Signing (using an in-house Generator Product).
  • Trufo Processing (sending the media to Trufo’s servers) vs. Local Processing (the media stays on-prem).

Both processing modes are important, and come with their own challenges when running at scale.

#Trufo (Server-Side) Processing

Many of the API calls involve media processing actions in the Trufo server, with watermarking being the primary one. There are two primary challenges here:

  • There are many media formats and codecs in use, especially once video streams get involved. The server needs to be able to handle these variations and manage the algorithm configs.
  • Some media items are much larger than others. The server needs to be able to handle full-length cinematic movies without disrupting the latency of handling lightweight API calls.

With v1.4.0, Trufo now provides a method to schedule tasks: instead of a single request-response loop, API users can submit tasks (standalone or in batches) and retrieve the result once the job is done, with status updates as the job is underway. More expensive files (over 10MB or audio/video where media processing is specified) will be routed through this system (GPU-powered), while lightweight requests remain quick (CPU-bound, bottlenecked by network latency + codec processing).

#Local (Client-Side) Processing

For many use cases, local processing, where the media file is never sent to Trufo servers, is important. This may be due to privacy concerns (data is sensitive) or network I/O concerns (data is large).

For this setting, Trufo provides developer SDKs for sensitive operations, such as C2PA manifest construction (for “Trufo Signing” where per conformance the SDK is part of the TOE) and C2PA invisible watermarking (where ID management needs to be managed by the server). In order to download the software, there is a sdk-download API key that can be minted once the library license agreement is signed.

The low-level operations are in Rust (C2PA) and PyTorch (watermark), and are optimized for production performance.

#Scaling with Trufo

For organizations rolling out C2PA, Trufo’s extensive support for both processing routes allows C2PA workflows to grow and adapt as the C2PA ecosystem takes off. It is easy to start with a proof-of-concept and quickly scale up to millions or billions of C2PA-trusted assets.

If there are missing features that you would like to see supported, please let us know!