Prove You Created an Image First: Copyright Seal for JPG, PNG and SVG Files (2026)
IP Copyright

Prove You Created an Image First: Copyright Seal for JPG, PNG and SVG Files (2026)

Cryptographically seal any image file before you post it (JPG, PNG, SVG, or TIFF) and hold legally admissible timestamp proof under eIDAS and ZertES.

D
Dani Wattenhofer· Co-Founder & Business Development
·June 16, 2026· 7 min read

In February 2025, a Geneva-based graphic designer delivered a full brand identity package to a fintech startup: logo, icon set, and brand guidelines, before the contract was countersigned. Three weeks later, the startup's in-house team published the logo as their own design on LinkedIn. The designer's only proof was a Dropbox upload timestamp and an email thread. The startup's lawyers said both were inconclusive. The designer had shared every file before sealing any of them.

The AI Image Theft Problem in 2026

AI image generators are trained on scraped web content, including images posted to Instagram, Behance, and client portals before any formal protection. If your work is online, it is likely inside training datasets. What you can control is everything you create from today forward.

The problem is that when you try to assert ownership, in a dispute, a licensing negotiation, or a DMCA takedown, the opposing party's first question is: when did you actually create this? Reverse image search tools can find copies but prove nothing about origin. Courts need a creation timestamp from an accredited, independent authority, not a platform upload date or a social media post. Without it, your claim rests on memory and circumstantial evidence. With it, the legal presumption shifts to your side.

Why EXIF Data and File Timestamps Are Not Enough

Creators assume EXIF metadata (camera model, date taken, GPS) is sufficient to prove authorship. It is not. EXIF data is trivially modified by any image editor; opposing counsel will raise this in every dispute.

File system timestamps are weaker still. The "Date Modified" field changes when a file is copied, compressed, or uploaded. Dropbox and Google Drive replace your local timestamp with the platform's upload date, recorded by a third party, not an independent legal authority.

What courts need is a qualified electronic timestamp from an accredited Certification Service Provider, cryptographically bound to the exact file content at the moment of sealing. That is what eIDAS Art. 41 establishes as legally presumed accurate. The challenger must rebut it, not you.

What Would Have Been Different

If the Geneva designer had sealed each master SVG before sending the first draft, the conversation with the startup's lawyers would have lasted minutes, not months. The PAdES-compliant certificate from Swisscom Trust Services would have shown the exact SHA-256 hash of each file, bound to a UTC timestamp hours before the startup's claimed design date. Under eIDAS Art. 41, the legal presumption shifts to the holder of the qualified timestamp: the timestamp is accurate unless the challenger proves otherwise. One email with the /validate link would have ended the matter without a lawyer.

How Cryptographic Image Sealing Works

The process is precise and privacy-preserving. Your image is never uploaded or stored.

Swiss Trust Layer computes a SHA-256 hash, a fingerprint of the exact binary content of your image. Change a single pixel and the hash changes completely. This hash is sent to Swisscom Trust Services, which issues a qualified electronic timestamp compliant with RFC 3161, bound cryptographically to your hash. The resulting PAdES-compliant certificate contains your hash, the timestamp, the issuer chain, and your verified identity. Any party, a lawyer, court clerk, or AI licensing team, can verify it at swisstrustlayer.com/validate without contacting you.

eIDAS Art. 41 grants a legal presumption that the timestamp is accurate, operative across all 27 EU member states. ZertES Art. 2 provides the same presumption under Swiss law. Under Berne Convention Art. 5, copyright exists at creation, but proving when is what protects you in practice.

Step-by-Step: Seal an Image File

Step 1: Select your file. JPG, PNG, SVG, TIFF, and WebP are all supported at any resolution, up to 500 MB per file.

Step 2: Upload at swisstrustlayer.com. The SHA-256 hash is computed in your browser. Your image data is never sent to Swiss Trust Layer's servers. Only the hash travels.

Step 3: Qualified timestamp is issued. Swisscom Trust Services anchors your hash to a RFC 3161-compliant qualified electronic timestamp. This is the legally binding event.

Step 4: Download your certificate. The PAdES-compliant certificate contains your hash, timestamp, issuer chain, and identity. Store it alongside the original file.

Step 5: Share the verification link. Anyone can confirm your certificate at /validate without contacting you. The evidence is admissible and independently verifiable.

When to Seal: Before the Post, Not After

The timing rule is absolute: seal before you share. Once an image is posted to a public platform, the metadata it carries is controlled by that platform, and any subsequent seal proves only that you held the file at a later date, not that you created it first.

Seal before uploading to Instagram, Behance, ArtStation, or Pinterest. Seal before emailing a design to a client for feedback. Seal before entering a design competition. Seal before submitting to a stock photography agency, or before licensing images for AI training datasets. Licensing teams increasingly require creation provenance as a contract condition.

Sealing costs CHF 5 per document. The cost of losing a copyright dispute in Switzerland runs CHF 150,000 to 400,000 on average (Swiss Arbitration Association). In the EU, IP infringement cases cost EUR 250,000 to 1.2 million on average (EUIPO, 2023).

Frequently Asked Questions

Can I seal a PNG or SVG file to prove copyright?
Yes. Swiss Trust Layer supports PNG, SVG, JPG, TIFF, and WebP. The SHA-256 hash captures the exact binary content of any file format, and the resulting qualified electronic timestamp is legally admissible under eIDAS Art. 41 and ZertES Art. 2 regardless of file type.

Is EXIF metadata enough to prove I took a photo?
No. EXIF metadata is trivially modified by any image editor and is routinely challenged in legal proceedings. Courts require a qualified electronic timestamp from an accredited, independent authority, not camera-embedded data that the file owner could have altered after the fact.

What happens if someone copies my image before I seal it?
You face a harder burden of proof. Circumstantial evidence (raw files, version history, cloud backups) carries no legal presumption. A qualified electronic timestamp does. This is why sealing before posting is the only reliable protection.

Can I seal multiple images at once?
Each file requires its own seal, as each generates a unique hash tied to that file's exact content. Batch processing is available through team accounts, where volume pricing makes high-frequency sealing cost-effective for studios, agencies, and photographers with large catalogues.

Does image sealing prove artistic originality, or just creation date?
Image sealing proves creation date and integrity: that a specific file existed in its exact form at a specific moment. It does not adjudicate artistic originality, which remains a question for courts or copyright authorities. However, establishing a prior creation date is the foundational requirement for asserting copyright, defending against infringement, and qualifying for AI licensing deals. Without the timestamp, the originality question is moot.


The Geneva designer settled the dispute for a fraction of the original invoice after four months of legal back-and-forth. The seals that would have protected every file in the handoff would have cost CHF 5 each. Against CHF 150,000 to 400,000 in average Swiss IP dispute costs (Swiss Arbitration Association), that arithmetic does not require a lawyer to explain. Seal before you post. Learn more about the legal framework at /eidas and /zertes.

Protect your work with Swiss Trust Layer AG

Seal your intellectual property with a court-proof e-Seal backed by Swisscom Trust Services.

Book a Free Demo

Related Articles

The qualified signature workflow, start to finish
Legal

The qualified signature workflow, start to finish

A qualified electronic signature involves identity verification, signing ceremony, PAdES application, RFC 3161 timestamping, and public verification. Each step serves a specific legal purpose. This is what the process looks like from upload to verified certificate.

July 19, 2026Read more →
5 documents Swiss businesses should never sign with a basic e-signature
Legal

5 documents Swiss businesses should never sign with a basic e-signature

Swiss law specifies document types where only a qualified electronic signature carries the legal weight of a handwritten signature. Using a simple or advanced e-signature on these documents creates an enforceable gap that surfaces in disputes. Here are the five categories that matter.

July 18, 2026Read more →
DocuSign vs SealMyIdea: where a visual signature isn't enough
Legal

DocuSign vs SealMyIdea: where a visual signature isn't enough

DocuSign provides advanced and simple electronic signatures. For real estate, IP transfers, fiduciary mandates, and employment contracts in Switzerland, only a qualified electronic signature under ZertES Art. 11 carries legal presumption. This is the gap DocuSign cannot close.

July 17, 2026Read more →
For agencies: prove you authored the work and get clean client sign-off
Legal

For agencies: prove you authored the work and get clean client sign-off

Creative and digital agencies lose IP disputes because they cannot prove creation date or obtain legally binding client acceptance. A qualified electronic signature for client sign-off, combined with timestamped delivery, creates the complete audit trail that courts recognise.

July 16, 2026Read more →
Blockchain proves a file existed. It doesn't prove a court will accept it.
Legal

Blockchain proves a file existed. It doesn't prove a court will accept it.

A blockchain timestamp records that a file existed at a point in time. It carries no legal presumption under eIDAS or ZertES. A qualified electronic timestamp issued by an accredited QTSP does.

July 15, 2026Read more →