Asset Foundry is the trust layer for your facility. It runs in your own AWS account or on-prem, so in production deployments your clients' content stays in your environment. Checksum-level duplicate and cost reports across 8 storage tiers, SSO, MFA and role-based access on the way in, and governed generative AI you can actually sign off. One self-serve platform your team stands up, not another vendor cloud you have to explain to a client.
Gateway pulls checksum-level duplicate reports and storage-cost reports across all 8 tiers, so you can see exactly what is copied where and what it costs before you sign the next capacity PO. Read-only by design, so a report can never touch the data it describes.
Duplicates are matched on the file's checksum, not its name or path, so a master copied across tiers under different names still reads as one asset. Reclaim the space instead of renting more of it, across cloud, on-prem and LTO tape.
60+ generative models sit behind one API on elastic GPU that scales from zero to N and back to zero. Fabric computes embeddings inside your deployment with no external AI calls for retrieval, so in production deployments your team gets AI without a client's frames going to someone else's cloud.
SSO over OIDC and SAML 2.0, authenticator-app MFA, role-based access, and a severity-tagged audit trail you export straight to your SIEM. Every generated output carries visible watermarking, and images carry C2PA Content Credentials with an AI-source assertion. A SOC 2 Type II aligned engineering posture, designed for MPA content-security best practices.
Book the ones that fit your team, or the whole platform. Each shares one index.
Your identity, audit and cost console over the whole estate: SSO over OIDC and SAML 2.0, authenticator-app MFA, role-based access, and a severity-tagged audit trail you export to your SIEM. Plus the reports you never had, checksum-level duplicate and storage-cost reports across 8 tiers, and recovery ops with dry-run and undo so a bad move is reversible, not a restore ticket.
Governed retrieval you can put in front of the facility: embeddings are computed inside your own deployment with no external AI calls, and access controls apply inside the query itself, so people and agents only ever surface what they are cleared to see. AI that never sends a client's content out of your environment.
Generative and processing horsepower with provenance baked in, not bolted on. 60+ models and 13 job types on elastic GPU that scales 0 to N to 0, so idle nodes never sit on the bill. Every output carries visible watermarking on video, image and document, and images carry C2PA Content Credentials, so you can always answer where an asset came from.
Nothing lands or moves without a record. Checksum verification (md5 or sha-256) on every file at intake, opt-in duplicate SKIP keyed to source path so you stop re-ingesting the same drop, explicit opt-in write paths, and managed credentials with a create, list and revoke lifecycle. The write side of the estate, under control.
Stand it up in your own AWS account or on-prem, hybrid supported, and point it at your identity provider over OIDC or SAML 2.0. Turn on authenticator-app MFA, scope roles per client and project, and keep it read-only against your storage to start. Nothing is migrated and nothing is touched while you get comfortable, and in production deployments the content stays in your environment.
Before you renew a tier or size the next PO, Gateway shows checksum-level duplicates and storage cost across all 8 tiers, cloud, on-prem and LTO tape. You reclaim the space that duplicates were paying rent on and hand finance a number instead of a bigger invoice. Nexus SKIPs the next re-drop of a delivery you already have.
Switch on generation pinned to models you approve, confirm Fabric's embeddings compute inside the environment with no external AI calls, and turn on visible watermarking on every output plus C2PA on images. When a client's security review arrives, show content staying in your environment, provenance on every generated asset, and a full audit trail wired to your SIEM. Prove the whole thing first on a four-week pilot, on archival data you choose, deleted and verified at wrap.
Yes. It deploys into your own AWS account or on-prem, hybrid supported, so in production deployments your clients' content stays in your environment. It starts read-only against your storage with nothing migrated, and Fabric computes embeddings inside your deployment with no external AI calls for retrieval. The optional fast-start pilot runs single-tenant in Fortify's cloud on archival data you choose, deleted and verified at wrap.
Gateway produces checksum-level duplicate reports across all 8 storage tiers, matching on the file's checksum rather than its name or path. A master copied across cloud, on-prem and LTO tape under different names is still recognized as one asset, so you can see exactly what is paying rent and reclaim the space with confidence. Cost reports across the same 8 tiers turn every retention and capacity call into a number instead of a guess.
Yes. 60+ generative models sit behind one API on elastic GPU that scales from zero to N and back to zero. Fabric computes embeddings inside your own deployment with no external AI calls for retrieval, generation is pinned to local models or providers you approve, and every output carries visible watermarking with C2PA Content Credentials on images. In production deployments the content stays in your environment, and every job is audited.
SSO over OIDC and SAML 2.0, authenticator-app MFA, role-based access, and a severity-tagged audit trail you export to your own SIEM, plus visible watermarking and C2PA provenance on generated assets and content staying in your environment in production deployments. It is built to a SOC 2 Type II aligned engineering posture and designed for MPA content-security best practices, which describe engineering discipline rather than third-party certification. The fastest way to prove it is a four-week pilot on data you choose, deleted and verified at wrap.