Asset Foundry deploys into your own AWS account or on-prem, so in production deployments your content stays in your environment. SSO over OIDC and SAML 2.0, MFA and role-based access on the way in. Severity-tagged audit you export to your SIEM, visible watermarking on the way out, with C2PA Content Credentials on images. Visibility, reuse and governance across the sprawl, with no migration and no black box.
Deploy into your own AWS account or on-prem, hybrid supported. In production deployments your content stays in your environment, read-only against your drives, servers, cloud and any DAM you kept, with nothing migrated to stand it up.
Single sign-on over OIDC and SAML 2.0 through your existing identity provider, authenticator-app MFA, and role-based access scoped per team. Machine access uses managed credentials with a create, list and revoke lifecycle.
60+ models sit behind one API. Embeddings are computed inside the deployment with no external AI calls for retrieval, and every generated output carries visible watermarking, with C2PA Content Credentials on images carrying an AI-source assertion. Every job is audited.
A SOC 2 Type II aligned engineering posture, designed for MPA content-security best practices, describing engineering discipline rather than third-party certification. Severity-tagged audit logging exports straight to your SIEM.
Book the ones that fit your team, or the whole platform. Each shares one index.
Your identity and audit front door: SSO over OIDC and SAML 2.0, authenticator-app MFA, role-based access scoped per team, and a severity-tagged audit trail you export to your own SIEM. Read-only by design, so a question can never change your data, and every catalog answer resolves permissions per question with an audit row on each one.
Retrieval that stays inside your walls: embeddings are computed inside the deployment environment with no external AI calls, access controls apply inside the query itself, and 300+ connectors normalize the sprawl into one governed graph so people only ever surface what they are cleared to see, no ungoverned index leaking out the side.
Provenance baked in, not bolted on: every processed or generated output carries visible watermarking on video, image and document, plus C2PA Content Credentials on images with an AI-source assertion, so when the brand or legal team asks where an asset came from you can always answer.
Nothing moves without a record: write paths are explicit and opt-in, every transfer is checksum-verified and logged, integration secrets sit under managed credentials with a create, list and revoke lifecycle, and duplicates are skipped on an opt-in, source-path basis so the same asset never lands twice.
Deploy into your own AWS account or on-prem, hybrid supported. Point it at your identity provider over OIDC or SAML 2.0, turn on authenticator-app MFA, and scope roles per team. It stays read-only against your drives, servers, cloud and any DAM you kept, so nothing is touched or migrated while you get comfortable.
Confirm embeddings compute inside the deployment with no external AI calls, pin generation to models you approve, and switch on visible watermarking on every output plus C2PA Content Credentials on images. Wire the severity-tagged audit log to your SIEM and keep integration keys under managed credentials.
When the review arrives, show content staying in your environment, watermarking and provenance on generated assets, and a complete audit trail of who did what. Run the whole thing first as a four-week pilot on one slice of data you choose, deleted and verified at wrap.
In production deployments it runs inside your own AWS account or on-prem, hybrid supported, so content stays in your environment. It indexes your drives, servers, cloud and any existing DAM read-only, with nothing migrated. Embeddings are computed inside the deployment with no external AI calls for retrieval, and generation is pinned to models you approve. The optional fast-start pilot runs single-tenant in Fortify's cloud on data you choose, deleted and verified at wrap.
Single sign-on runs over OIDC and SAML 2.0 through your identity provider, with authenticator-app MFA and role-based access scoped per team. Machine access uses API keys under managed credentials with a create, list and revoke lifecycle. Every action writes a severity-tagged audit entry that you export directly to your own SIEM, so access and provenance live in the tools you already monitor.
60+ generative models sit behind one API inside your deployment. Embeddings for retrieval are computed inside the environment with no external AI calls, so your library is never shipped to a third-party model to be searched. Every output carries visible watermarking on video, image and document, images carry C2PA Content Credentials with an AI-source assertion, every job is audited, and AI-suggested tags and mappings wait for human approval before anything is written.
It is built to a SOC 2 Type II aligned engineering posture and designed for MPA content-security best practices, which describe engineering discipline rather than third-party certification. That posture includes SSO, MFA, role-based access, and severity-tagged audit logging you can export. Rather than take it on trust, run a four-week pilot on one slice of your own data, read-only, and see the deployment, the audit trail and the provenance in your own environment before you sign off.