Apple has detailed Reference Image, an opt-in camera mode for the main sensor on the iPhone 18 Pro and Pro Max that cryptographically signs image data immediately after capture. The design aims to prove that a picture originated at a physical sensor before later editing, rather than attaching provenance only at the end of an image-processing chain.

The sensor starts in a dedicated secure state and signs the raw pixels, while the Secure Enclave signs metadata such as focal length and zoom. Signed timestamps bracket the capture, and the phone stores the result as a secure DNG digital negative. Apple’s Private Cloud Compute then verifies that the sensor and enclave belong to the same device before developing the image and applying a combined ML-DSA-87 and RSA-3072 signature.

The final file does not reveal the photographer or device identity. Apple says that offers stronger privacy than public credentials, but verification rests on Apple’s signing service and factory certificate authorities. A neural network also scores whether the data resembles genuine sensor output; its model weights are not public, even though processing code is available for inspection.

The system can establish a capture chain, not the truth of the scene. A signed photo could still depict a screen, staged event or misleading composition, so provenance should not be treated as factual verification.