Citadel did not find enough risk to interrupt the workflow. This is not a guarantee that the material is true, benign, or legally sufficient.
REVIEW
Pause. A required check was incomplete, unavailable, or not applicable. Citadel found no suspicious evidence, but it also could not return ALLOW.
WARN
Suspicious or conflicting evidence crossed a review threshold. Route to human review, add friction, or request stronger evidence.
BLOCK
Risk is high enough that the workflow should stop or quarantine the item before trust.
INDETERMINATE risk level
The risk level paired with REVIEW when a required check could not finish. It does not mean fake, and a score of 0 does not turn it into ALLOW.
indeterminate evidence verdict
A supporting result, such as authenticity.verdict, that did not reach a conclusion. It is separate from the top-level routing action.
Risk score
A 0-100 score for routing and triage. Treat it as decision support, not a standalone fraud verdict.
Threat category
A machine-readable label for the kind of evidence found, such as prompt injection, hidden text, authenticity signal, metadata inconsistency, or edit evidence.
Controls scan depth and latency: fast, secure, or comprehensive. Mode does not add a separate SCU multiplier.
focus
Controls which evidence family Citadel prioritizes and how image units bill. steg, ai, and edits are focused paths (one path is 4 SCU per image, two paths are 8 SCU per image unit); all runs all three image/PDF evidence paths together and bills 12 SCU per image unit (4 SCU × 3 paths).
focus=steg
Looks for hidden content, prompt injection, content steering, unsafe text, secrets, and related threat signals.
focus=ai
Looks for image/PDF authenticity evidence, such as likely AI generation, AI editing, reposting, provenance gaps, or visual inconsistency.
focus=edits
Runs standalone localized manipulation review without assuming a trusted original. If the check cannot complete, Citadel returns REVIEW; pause and follow guidance.next_step.
focus=metadata
Inspects original JPEG, PNG, WebP, GIF, classic TIFF, HEIF, or PDF bytes in mode=secure. Returns file evidence and a separate C2PA receipt with NO_DECISION; it does not run threat detection. Bills 2 SCU per analyzed parent and 2 SCU per distinct analyzed native PDF image.
focus=all
Runs all three supported hidden-content, AI-authenticity, and edit-evidence paths together for image/PDF evidence. Bills 12 SCU per image unit (4 SCU × 3 paths).
Consistency (Preview)
Compares the documents in one packet with each other and with the manifest facts, through POST /v1/consistency/packets. It is not a focus value. Findings point at exact locations and never produce BLOCK. Costs 6 SCU per page (an image document counts as one page).
profile
Adjusts policy tolerance, such as balanced, strict, or AI-safety-oriented routing.
data_sensitivity
Controls how sensitive Citadel should be to normal business PII, credentials, secrets, and regulated data.
Evidence about whether an image or PDF visual appears generated, AI-edited, reposted, provenance-backed, or visually inconsistent.
AI edits
Localized evidence that visible content may have been changed, such as altered text, cloned areas, removed objects, or manipulated damage.
Steganography, or steg
Hidden or disguised content inside text, images, OCR output, PDFs, or documents. In Citadel docs, steg also covers prompt-injection and hidden-instruction safety.
Prompt injection
Text or hidden instructions that try to override a system, developer, tool, or workflow policy.
Content steering
Instructions that try to push a model or workflow toward a specific unsafe, biased, unauthorized, or misleading action.
Provenance
Evidence about origin and history, such as metadata, capture hints, signatures, or whether a file appears derived from another source.
File evidence
Bounded structure and metadata observations from submitted image or PDF bytes. Unsigned claims are context, even when they disagree.
Content Credentials
A C2PA receipt that checks an embedded signed claim on submitted bytes when supported. A trusted claim authenticates what was signed, not the real-world scene.
Tell
In consistency, a mistake in copied text that makes sense only if the text came from another person's or item's record, such as the wrong sex and the wrong side. A repeat without a tell stays a quiet template candidate.
Reference file
A trusted original used for a separate source comparison when the workflow already has one. Standalone edit review does not assume one.
Embedded image
A unique image inside a PDF that can be billed separately from page processing. Repeated copies are deduplicated by hash before counting.