For rights, legal, compliance and brand protection

Know it's cleared and current.
Prove where it came from.

Fabric finds assets by their rights and flags current versus superseded, so you can tell which version legal actually cleared. Forge returns generated images with visible watermarking and C2PA Content Credentials carrying an AI-source assertion. Gateway puts an audit row on every question. No migration, no new silo, just a clear answer when someone asks.

The daily friction
Marketing wants to ship this today, and I cannot tell which of these files is the version we actually cleared.
When someone asks who approved this asset and on what terms, I have a folder name and a hope.
The brand team is already generating AI images, and I have no idea what is in them or where they came from.
What changes for you
01

Current and cleared, not just close

Fabric finds assets by their rights and flags current versus superseded, with permissions enforced inside the query itself. You can tell at a glance whether a file is the version legal cleared, not last quarter's lookalike or an expired license.

02

Provenance on every generated image

Forge returns generated output with visible watermarking on video, image and document, and C2PA Content Credentials on images carrying an AI-source assertion. When legal asks where an asset came from, the answer travels with the file.

03

An audit row on every question

Gateway resolves permissions per question and writes a severity-tagged audit row on every one, exportable to your SIEM. You stop reconstructing who saw and pulled what from folder timestamps and memory.

04

Built for the review you know is coming

A SOC 2 Type II aligned engineering posture, designed for MPA content-security best practices. That is engineering discipline, not third-party certification, and it comes with SSO over OIDC and SAML 2.0, authenticator-app MFA and role-based access.

Your part of the stack

The pieces that earn their keep for rights, legal, compliance & brand protection.

Book the ones that fit your team, or the whole platform. Each shares one index.

A day in the life

A clearance question lands, from 'which version' to a trail you can hand legal

STEP 01

Confirm cleared and current

Marketing wants a hero image out today. You ask Fabric for the asset by its rights and it flags current versus superseded, with permissions resolved in the query, so you approve the version that was actually cleared and not an expired or retired lookalike.

STEP 02

Govern what the brand generates

The team needs a fresh variant. Forge generates it inside your permissions and returns it with visible watermarking plus C2PA Content Credentials on images carrying an AI-source assertion, so a generated asset is traceable the moment it exists instead of becoming an unlabeled mystery later.

STEP 03

Produce the trail on demand

A rights question comes back weeks later. Gateway shows a severity-tagged audit row on every query, exportable to your SIEM, so you answer who pulled what and when with a record, not a reconstruction from folder timestamps.

Questions
How do I know which version of an asset is cleared and current before it ships?

Fabric finds assets by their rights and flags current versus superseded, with permissions and version time-awareness enforced inside the query itself. So when marketing asks to ship a still or a cut, you can tell at a glance whether it is the version legal actually cleared, rather than an expired license or a superseded lookalike, before it goes out the door.

Can we prove an AI-generated image is generated and where it came from?

Yes. Forge returns generated images with C2PA Content Credentials carrying an AI-source assertion, and applies visible watermarking on video, image and document outputs. The provenance travels with the file, so when legal or a partner asks whether an asset is AI-generated and how it was made, the answer is embedded in the asset instead of living in someone's memory.

What audit trail do we get when legal or an auditor asks who accessed an asset?

Gateway resolves permissions per question and writes a severity-tagged audit row on every query, which you can export to your own SIEM. It is read-only by design, so a question can never change your data. That gives you a complete, exportable record of who asked for what and when, instead of reconstructing access from folder timestamps after the fact.

Is Asset Foundry certified for MPA or SOC 2?

No, and we do not claim to be. Asset Foundry is built to a SOC 2 Type II aligned engineering posture and designed for MPA content-security best practices, which describe engineering discipline rather than third-party certification. That posture includes SSO over OIDC and SAML 2.0, authenticator-app MFA, role-based access and severity-tagged audit logging you can export. The fastest way to see it against your own library is the four-week pilot: one slice, read-only, findings in your numbers.

Prove it on your own work

Four weeks. Your team's numbers.