Invisible forensic watermarking for video content protection.
Vestigit embeds an opaque identifier server-side and recovers it from a captured sample of unauthorized distribution. The recovered identifier can be correlated to an agreed session or token in your entitlement layer where the deployment supports and validates it. Only the customer maps that identifier to a person, account, subscriber or device.
What forensic watermarking is.
Forensic watermarking embeds an opaque identifier inside a video stream or file. From a captured sample of unauthorized distribution, that identifier can be recovered and correlated to an agreed session or token in your entitlement layer, where the deployment supports and validates it.
Vestigit delivers this as a server-side workflow that integrates with existing encoders, packagers, origins and CDN delivery, with no requirement to modify the player.
- Designed to be invisible under production viewing conditions.
- Independently reviewed for recovery under a defined set of transformations.
- Identifier is opaque; account or subscriber mapping stays inside your systems.
- Complementary to DRM. Designed to work alongside multi-DRM environments.
See Security & Privacy for the data boundary and identifier handling.
From source attribution to customer action.
Source attribution
Recover an opaque identifier from a captured sample; correlate to an agreed session or token identifier in defined workflows.
Detection record
Recovered identifier plus workflow context — designed to support investigations by the customer or a provider.
Deterrence
Session-scoped identifiers discourage credential sharing and redistribution where the deployment supports per-session variants.
Customer enforcement
Attribution feeds customer-controlled revocation, blocking or policy actions. Vestigit does not execute enforcement.
Different problems. Better together.
DRM controls who can access playback. Forensic watermarking attributes what leaks despite that access.
| Capability | DRM | Forensic watermarking | Vestigit value |
|---|---|---|---|
| Controls who can access playback | Yes | No | DRM enforces entitlement; watermarking is complementary. |
| Attributes a leaked sample to a source identifier | No | Yes | Forensic watermarking recovers an opaque identifier from a captured sample. |
| Works alongside multi-DRM environments | Yes | Yes | Vestigit is independent of DRM and designed to operate with it. |
| Produces a detection record for investigations | No | Yes | Detection record is designed to support investigations by the customer or a provider. |
| Executes revocation, blocking or takedown | Partial | No | Vestigit outputs feed customer-controlled enforcement actions. |
How the identifier is embedded and recovered.
Vestigit embeds an opaque identifier server-side or at the edge, then recovers it from a captured sample. Per-session identifier variants are used where the deployment supports and validates them. Full mechanics, including A/B segment handling and edge composition, are covered on the architecture page.
What has been reviewed.
Recovery has been independently reviewed against the following transformations. Robustness beyond this list is workflow-specific and agreed during discovery.
What the detection record contains.
The recovered identifier is the core output. Additional fields depend on deployment and are confirmed during discovery.
Opaque identifier tied to the embedded sequence. Core output.
Contextual metadata from the detection workflow, where validated for the deployment.
Where sample metadata carries reliable capture / detection times.
Pointer to the analyzed sample and its metadata, where supported by the sample path.
The detection record is designed to support investigations run by the customer or an appointed anti-piracy provider. Enforcement decisions remain customer-controlled.
Independent third-party assessment.
The Vestigit forensic watermarking implementation and recovery profile have been reviewed by an independent assessor.
See forensic watermarking in your workflow.
Discovery, PoC scoping and reference architecture support from the Vestigit technical team.

