Skip to content
Vestigit
Product / Sentinel Portal

Every detection, with the context to act.

Sentinel Portal brings detection results, source attribution, attack context and evidence into one operational view, so teams can move from a suspicious copy to the right response without rebuilding the case across tools.

Sample-based detection · Human-reviewed context · Customer-controlled response

Operator review
ILLUSTRATIVE DATA
In review
12
Suspected
4
Reviewed today
27
Selected incidentVST-ILL-0042
Live Event · Feed A-17
Playback session · Region 03
Suspected
Confidence94.8%
Recipient
Playback session · Region 03
Attack
Re-encode + crop 6%
Captured from
External sample · Source 12
Read a result

Read a detection in seconds.

Move from the operating picture to one reviewable case without losing the fields that explain what was found, where the sample came from and how strong the match is.

Sentinel PortalILLUSTRATIVE DATA
Samples today
41
In review
12
Suspected
4
  • VST-ILL-0042Suspected
    Live Event · Feed A-17
    Confidence94.8%
  • 3 additional cases in review — open the table view on a larger screen.
Case workflow

From match to evidence, without rebuilding the story.

The portal keeps the recovered reference and sample context alongside the reviewer's notes, while the final response remains inside the customer's authorised workflow.

  1. 01 · External source or operator

    Suspected copy received

    Sample arrives from an external source or an operator submission.

  2. 02 · Vestigit detector

    Identifier recovered

    The forensic identifier is recovered from the captured sample.

  3. 03 · Customer-owned mapping

    Playback session or recipient mapped

    The recovered reference is resolved through the customer-owned mapping.

  4. 04 · Operator · Sentinel Portal

    Result reviewed in Sentinel Portal

    An operator reviews the case, its fields and the sample context.

  5. 05 · Sentinel Portal · export

    Evidence preserved or exported

    The case can be reviewed and exported as a human-readable report or as structured data (illustrative capabilities depend on deployment).

  6. 06 · Customer workflow

    Response routed through the customer’s systems

    The final action is executed inside the customer’s workflow.

Sentinel Portal does not crawl the internet automatically. It reviews samples that have already been received.

The recovered reference may resolve to a session, account, token, device or partner — depending on deployment.

The portal routes the response; it does not, on its own, block a live stream in every deployment. An auditable record designed to support investigation and further enforcement.

Time-to-action lab

Model the cost of waiting with your own assumptions.

Extend the homepage scenario with your event profile, price and response timing. The output estimates exposure; it does not promise recovered revenue.

ILLUSTRATIVE DATA

90 min
80,000
$19.99
20.0%
12 min
17 min
22 min

Timing inputs are clamped so detection ≤ attribution ≤ action ≤ duration.

1
Illustrative estimate — not a forecast
Deterministic pirate viewer model across 90 minutes.Two curves: without action and with action. Vertical markers show leak start, detection, attribution and action. Use the Action-minute range control to move the action point.040,00080,000Pirate viewers0 min90 minLeak start0Detection12Attribution17Action22No actionWith actionExposure before action

Use the Action minute range control in the sidebar (keyboard: arrows / PageUp / PageDown / Home / End) to move the action point. You can also drag the handle on the chart. One Y measure at a time.

Revenue at risk at action minute (shared with homepage)
$297,451
Potential paid viewers at action minute
14,880
Estimated exposure before action
9,918 viewer-hours
Cumulative revenue exposure — no action (integrated)
$319,840
Cumulative revenue exposure — with action (integrated)
$189,619
Exposure reduction vs no action
80.1%
Response headroom (duration − action)
68 min
Methodology and assumptions

Viewer growth follows a deterministic profile: Rapid spike 1 − e^(−3.5 · t/D), Steady build t/D, Late surge (t/D)².

The action scenario follows the no-action curve until the action minute, then decays with a 10-minute time constant: V(t) = V(action) · e^(−(t−action)/10).

Revenue at risk at action minute (shared with homepage). Computed from the canonical homepage baseline as AFFECTED(τ) × SWITCH(τ) × price, where τ = action / duration × 90 min. The Lab's peak scales the baseline AFFECTED curve (baseline peak: 80,000). At the untouched default scenario (90 min, 80,000 peak, $19.99, action minute 22) this reading reconciles with the homepage Live Event preview at approximately $297,451. Potential paid viewers at the action minute is AFFECTED(τ) × SWITCH(τ) scaled by peak, so paid viewers × price equals this same shared figure.

Cumulative revenue exposure (integrated) is a separate, extended outcome: marginal new pirate viewers across the whole duration × the editable conversion assumption × price. It is not the same as the instantaneous shared reading above and grows with duration.

Exposure is expressed in viewer-minutes (converted to viewer-hours in the summary). Conversion is an editable scenario assumption. Estimated unauthorized viewers are not proven one-for-one lost sales.

Linked mirror count describes distribution breadth only: it slightly slows post-action decay to reflect residual distribution persistence, but never multiplies unique viewers, potential paid viewers, or revenue at risk. All results are illustrative estimates and are not guaranteed revenue.

Operating rhythms

One evidence layer. Three operating rhythms.

Sentinel Portal · caseILLUSTRATIVE DATA
Case
VST-ILL-0042
Asset
Live Event · Feed A-17
Recipient / Session
Playback session · Region 03
Confidence
94.8%
Attack
Re-encode + crop 6%
Captured from
External sample · Source 12
Bitrate
1080p / 6 Mbps
Leak lag
24 min after start

Time-to-action drives every field: confidence, attack profile and the minute the response is routed.

Role views

One record, fewer handoffs.

The case stays the same. Each team sees the fields needed for its decision.

VST-ILL-0042· Anti-piracy / Operations
ILLUSTRATIVE DATA
Status
Suspected
Attack
Re-encode + crop 6%
Capture source
External sample · Source 12
Scanned
07:42:11 UTC
Response boundary

The portal informs the response. Your systems execute it.

Vestigit
Detector
Review · Evidence
Sentinel Portal
Customer workflow
  • Entitlement / access control
    depending on deployment
  • NOC / SOC
    depending on deployment
  • Ticketing
    depending on deployment
  • Reporting
    depending on deployment
  • System executing revoke
    depending on deployment
Next step

Bring one real workflow. We’ll show you how the portal handles it.