For IT, infrastructure and security at a brand or enterprise

Powerful AI over your library,
governed, inside your own cloud.

Asset Foundry deploys into your own AWS account or on-prem, so in production deployments your content stays in your environment. SSO over OIDC and SAML 2.0, MFA and role-based access on the way in. Severity-tagged audit you export to your SIEM, visible watermarking on the way out, with C2PA Content Credentials on images. Visibility, reuse and governance across the sprawl, with no migration and no black box.

The daily friction
Every AI tool we evaluate wants our brand library uploaded to their cloud, and the answer from legal is no.
Marketing is already pasting product shots into some public AI tool, and when the brand team asks I have zero provenance and zero audit trail.
The security review is coming and I cannot sign off on a platform I am not allowed to see inside.
What changes for you
01

It runs where your content already lives

Deploy into your own AWS account or on-prem, hybrid supported. In production deployments your content stays in your environment, read-only against your drives, servers, cloud and any DAM you kept, with nothing migrated to stand it up.

02

SSO, MFA and RBAC from day one

Single sign-on over OIDC and SAML 2.0 through your existing identity provider, authenticator-app MFA, and role-based access scoped per team. Machine access uses managed credentials with a create, list and revoke lifecycle.

03

Governed AI you can actually sign off

60+ models sit behind one API. Embeddings are computed inside the deployment with no external AI calls for retrieval, and every generated output carries visible watermarking, with C2PA Content Credentials on images carrying an AI-source assertion. Every job is audited.

04

Built for the audit, not to dodge it

A SOC 2 Type II aligned engineering posture, designed for MPA content-security best practices, describing engineering discipline rather than third-party certification. Severity-tagged audit logging exports straight to your SIEM.

Your part of the stack

The pieces that earn their keep for it / infrastructure / security.

Book the ones that fit your team, or the whole platform. Each shares one index.

A day in the life

Onboarding a new platform, the way IT and security actually does it

STEP 01

Stand it up inside your walls

Deploy into your own AWS account or on-prem, hybrid supported. Point it at your identity provider over OIDC or SAML 2.0, turn on authenticator-app MFA, and scope roles per team. It stays read-only against your drives, servers, cloud and any DAM you kept, so nothing is touched or migrated while you get comfortable.

STEP 02

Turn on the guardrails

Confirm embeddings compute inside the deployment with no external AI calls, pin generation to models you approve, and switch on visible watermarking on every output plus C2PA Content Credentials on images. Wire the severity-tagged audit log to your SIEM and keep integration keys under managed credentials.

STEP 03

Prove it to the auditor

When the review arrives, show content staying in your environment, watermarking and provenance on generated assets, and a complete audit trail of who did what. Run the whole thing first as a four-week pilot on one slice of data you choose, deleted and verified at wrap.

Questions
Can we run Asset Foundry without our content leaving our environment?

In production deployments it runs inside your own AWS account or on-prem, hybrid supported, so content stays in your environment. It indexes your drives, servers, cloud and any existing DAM read-only, with nothing migrated. Embeddings are computed inside the deployment with no external AI calls for retrieval, and generation is pinned to models you approve. The optional fast-start pilot runs single-tenant in Fortify's cloud on data you choose, deleted and verified at wrap.

How do identity, access and audit work with our existing stack?

Single sign-on runs over OIDC and SAML 2.0 through your identity provider, with authenticator-app MFA and role-based access scoped per team. Machine access uses API keys under managed credentials with a create, list and revoke lifecycle. Every action writes a severity-tagged audit entry that you export directly to your own SIEM, so access and provenance live in the tools you already monitor.

How do you keep generative AI governed instead of a leak risk?

60+ generative models sit behind one API inside your deployment. Embeddings for retrieval are computed inside the environment with no external AI calls, so your library is never shipped to a third-party model to be searched. Every output carries visible watermarking on video, image and document, images carry C2PA Content Credentials with an AI-source assertion, every job is audited, and AI-suggested tags and mappings wait for human approval before anything is written.

Will this stand up to our security review without being a black box?

It is built to a SOC 2 Type II aligned engineering posture and designed for MPA content-security best practices, which describe engineering discipline rather than third-party certification. That posture includes SSO, MFA, role-based access, and severity-tagged audit logging you can export. Rather than take it on trust, run a four-week pilot on one slice of your own data, read-only, and see the deployment, the audit trail and the provenance in your own environment before you sign off.

Prove it on your own work

Four weeks. Your team's numbers.