Connect a recovered identifier to its configured delivery context.
When a sample yields a valid detection, Vestigit returns an opaque forensic identifier. A customer-controlled mapping can then link it to the configured delivery context, where that workflow has been validated.
- 01Suspected sampleCapture 07:42:11
- 02Detection resultSample analyzed
- 03Recovered ID, if available0xA2·F1·E4 — or none if inconclusive
- 04Customer-controlled mappingCustomer systems
Define the context the recovered identifier is intended to represent.
One protected asset can branch into multiple attribution contexts. Select the one that matches your delivery workflow to preview the mapping shape and operational use.
- Protected delivery
- Packaged VOD or catch-up delivered through entitled sessions.
- Identifier context
- Per-session opaque identifier that the customer-controlled mapping can link to a session record, where the deployment supports it.
- Mapping owner
- Customer entitlement / session store.
- Operational use
- Investigate a specific playback session and its authorized boundary.
Available attribution depends on the identifier and mapping configured in the delivery workflow.
From protection setup to investigation response.
Protection setup
Content preparation, protected variants, publishing.
Authorized delivery
Entitlement context, personalized delivery, playback.
Investigation & response
Suspected sample, detection result, recovered ID (if available), customer-controlled mapping, customer action.
Vestigit can recover an opaque technical identifier, when a valid detection is possible.
The customer-controlled mapping can connect that identifier to an authorized delivery context.
The customer or appointed operator controls the decision and response.
Model the exposure window before action is taken.
Adjust the assumptions behind a VOD release or pre-release screener. Explore how assumed attribution and response times may affect modeled exposure.
Illustrative starting values — edit every assumption.
SVOD context: unit value represents an assumed value of one legal playback. The model selector changes context labels only and never inserts benchmark assumptions.
No Vestigit benchmark is applied. Enter assumptions for your own scenario.
No Vestigit benchmark is applied. Enter assumptions for your own scenario.
Chart summary — the dashed lighter curve is “Baseline assumptions” (no customer action). The solid cyan curve is “With modeled action after identification”, using your own assumed impact on further spread. Both curves are cumulative and monotonic and are identical until the customer-action marker, after which the modeled-response curve increases at a rate reduced by your assumption. Identification alone does not reduce spread — response actions remain customer-controlled.
Baseline modeled cumulative audience at horizon: 115,109. Modeled-response scenario: 115,109. Difference in modeled audience: 0. Values are derived deterministically from the assumptions above.
Assumptions and formula
Baseline curve: cumulative modeled audience follows a bounded curveR · (1 − exp(−3.2 · d / H))where R is the assumed unauthorized reach and H is the horizon in days.
Modeled-response curve: identical to baseline until the customer-action marker; after that point, additional cumulative audience is scaled by(1 − impact/100), where impact is your own estimate of the reduction in further spread. Identification alone does not reduce spread; the response action is customer-controlled.
Commercial exposure = final cumulative audience × unit value × assumed legal conversion.
This scenario is based solely on user-provided assumptions. It is not a prediction of piracy, detection performance, avoided loss or recovered revenue.
This scenario is based solely on user-provided assumptions. It is not a prediction of piracy, detection performance, avoided loss or recovered revenue.
From detection result to investigation record.
- Asset reference
- ASSET 0249 · Delivery 014
- Recovered opaque ID
- 0xA2·F1·E4·9B
- Sample time window
- 2026-07-23 07:42:11 → 07:43:24 UTC
- Detection status
- Conclusive in this illustrative record
The selected label is an illustrative description of the circumstances of the sample as reported or observed. It is not an automatic recognition of the attack type and it is not a claim of guaranteed survivability. See attack resistance.
Other possible states: Inconclusive — no identifier returned.
- Attribution context
- Playback session
- Mapping status
- Available in customer systems (illustrative)
- Mapping owner
- Customer entitlement / session store.
- Action owner
- Customer or appointed operator
Other possible mapping states: Mapping unavailable, Mapping not found.
Vestigit can process an opaque technical identifier. Any association with a named individual is performed through the customer's controlled mapping process.
The attribution context changes across the release lifecycle.
- Authorized audienceNamed reviewers, festivals, buyers and internal teams.Most useful identifier contextPer-recipient identifier on individually marked deliveries.Typical mapping ownerDistribution / screener operations.Expected response workflowAccess review, delivery revocation, direct outreach.
Check your current workflow.
A quick self-check to align on what is already decided, what needs confirmation and what should be validated in a PoC.
- 01Streaming, downloadable or mixed delivery
- 02Titles, screeners or library scale
- 03Encoder, packager, CDN and DRM
- 04Identifier the recovered result should represent
- 05Where the mapping is stored
- 06Sample hand-off and expected response workflow
This page describes protected streaming delivery. Support for downloadable or offline screener workflows depends on the packaging and delivery path, and is confirmed during technical discovery.
VOD & screener questions.
Scope VOD and screener protection.
Bring one workflow, its delivery path and the context you need to recover. We will define the identifier scope, responsibility split and validation plan.