Skip to content
Vestigit
TECHNOLOGY / 00 / OVERVIEW

A forensic layer built around the stack you already run.

Vestigit connects protected playback, session context and detection response. It adds recoverable attribution to the video path while identity, entitlement and enforcement remain under customer control.

System model

One protection flow. Three technical planes.

Each plane answers a different question: where the A/B signal is embedded, which session reference it maps to, and how a suspected copy is correlated back to that reference through Session Mapping.

  • Customer-controlled
  • Vestigit
  • Shared
Protected Playback
Session & Control

Selection context flows up to the Vestigit-Mixer; the Session Adapter also stores the token ↔ sequence mapping record used at detection time.

Detection & Response

CDN + Vestigit-Mixer (creates one session-specific stream)

Shared-controlled

Request-aware logic on the delivery path selects A/B segments per session using the token↔sequence mapping supplied by the Session Adapter, producing one session-specific stream.

Attribution semantics
Detector extracts the A/B sequence. Session Mapping then correlates that sequence with the stored opaque token / session reference. End-user identity is not encoded in the media.

Ownership boundary: customer authentication, entitlement, session lifecycle, packager, origin, player and enforcement are customer-owned. The Vestigit Session Adapter, Detector, Session Mapping and attribution result are Vestigit-owned. The embedding integration and CDN mixer interface are shared.

Deployment fit

Three routes into the same operating model.

The protection logic remains consistent. Component placement and the customer change surface depend on the existing media stack.

  1. Content source
    Customer
  2. Vestigit Cloud Embedder
    Vestigit cloud
  3. Customer Encoder / Transcoder
    Customer
  4. Packager / Origin
    Customer
  5. CDN + Vestigit-Mixer
    Delivery / Vestigit
  6. Player
    Customer
Vestigit
Vestigit Detector + Session Mapping
Detection component — same for every model

The Embedder creates two synchronized A/B streams. Packager and Origin preserve both. The Vestigit-Mixer on the delivery path selects segments per session to produce one session-specific stream. Detection runs on the Vestigit side in every model.

Placement

Vestigit-managed cloud, between the contribution source and customer Encoder / Transcoder.

Customer change surface

Contribution routing, paired A/B encoding and agreed session mapping.

Best fit

Cloud-first workflows or a lighter operational footprint.

Data boundary

Recover an identifier. Keep identity in your domain.

Vestigit is designed around an agreed opaque or pseudonymous session context. Only the customer maps the recovered result to a person, account, subscriber or device.

Customer environment
  • Account
  • Authentication
  • Entitlement
  • Session mapping
Vestigit boundary
  • Opaque / pseudonymous session context only
  • e.g. session ref 7F2A…
  • Detector extracts a sequence; Session Mapping resolves the agreed session reference.
Customer workflow

End-user identity mapping and any enforcement action happen inside the customer environment.

  • Customer systems remain the source of truth for identity.
  • Data residency and retention are agreed during discovery.
  • Enforcement remains customer-controlled.
Review Security & Privacy
Architecture inputs

Five decisions shape the real deployment.

  1. Embedding point
    Can the encoder or packager generate synchronized A/B variants?
    Defined during discovery
  2. Mixing point
    Where can request-aware logic run across the origin or CDN path?
    Defined during discovery
  3. Session key
    Which stable session or token identifier should be recoverable?
    Defined during discovery
  4. Operating envelope
    What latency, cache, failure and observability rules apply?
    Defined during discovery
  5. Response boundary
    Which customer system receives the result and takes action?
    Defined during discovery

Map Vestigit to your delivery stack.

Bring your current HLD, vendor list and session flow. We will identify integration points, data boundaries and the criteria required for a meaningful PoC.