REAL — Sign

Drop a C2PA-signed file. We validate the signature, look up the signing cert in the trust list, and anchor the file's SHA-256 to the chain. Unsigned files are rejected.