AILANTA
All research
GitHub · npm · PyPI · Discovery evidence

Content authenticity is moving from detection to provenance

A seven-month GitHub cohort and package-usage snapshot test whether provenance, credentials, and identity binding are becoming an infrastructure category.

2026-07-2551 items10 source types14 validation posts
Main finding

Provenance is established; identity binding remains early

51 subject-filtered implementations and packages show that provenance is already a visible implementation layer: signing and provenance appear in 96.1% of the cohort and reusable verification interfaces in 41.2%. Identity binding appears in only 0% and post-hoc detection in 3.9%. The data support a shift from detection toward provenance, but do not yet confirm the stronger claim that identity-bound workflows are becoming a mature category.

01

Market snapshot

Comparable measurements from independent market surfaces.

51

Implementations and packages

Deduplicated and subject-filtered primary cohort.

4

Median repository stars

Calculated across repositories with at least one star.

32

Registry packages

Real npm and PyPI package records, not synthetic entries.

385,700

Latest-month npm downloads

Usage surface only; downloads are not equivalent to customers.

02

Search-match dynamics

Bars show monthly GitHub Search API matches for provenance and content-credential terminology; loaded counts show the deduplicated repositories retained for detailed analysis.

Jan 26341 loaded
Feb 26634 loaded
Mar 26784 loaded
Apr 26753 loaded
May 26665 loaded
Jun 26492 loaded
Jul 26360 loaded
03

What exists inside the category

One item may contain more than one feature.

Post-hoc AI detection

2 · 3.9%

Provenance and signing

49 · 96.1%

Identity binding

0 · 0%

Watermarking

6 · 11.8%

Verification SDKs and APIs

21 · 41.2%

Audit workflows

1 · 2%

04

Representative projects

05

Cross-source validation

These publications are not part of the primary numeric cohort.