For systems, storage and IT at a post, VFX or finishing facility

See every storage tier.
Govern the AI in-house.

Asset Foundry is the trust layer for your facility. It runs in your own AWS account or on-prem, so in production deployments your clients' content stays in your environment. Checksum-level duplicate and cost reports across 8 storage tiers, SSO, MFA and role-based access on the way in, and governed generative AI you can actually sign off. One self-serve platform your team stands up, not another vendor cloud you have to explain to a client.

The daily friction
I buy more storage every quarter and I couldn't tell you how much of it is duplicate frames paying rent across tiers.
Half the facility wants an AI tool, and I have no way to run one without a client's plates leaving the building.
The client security questionnaire lands, and I'm vouching for a black box I'm not allowed to see inside.
What changes for you
01

See the sprawl before you buy more

Gateway pulls checksum-level duplicate reports and storage-cost reports across all 8 tiers, so you can see exactly what is copied where and what it costs before you sign the next capacity PO. Read-only by design, so a report can never touch the data it describes.

02

Kill duplicates paying rent

Duplicates are matched on the file's checksum, not its name or path, so a master copied across tiers under different names still reads as one asset. Reclaim the space instead of renting more of it, across cloud, on-prem and LTO tape.

03

Governed AI, inside your walls

60+ generative models sit behind one API on elastic GPU that scales from zero to N and back to zero. Fabric computes embeddings inside your deployment with no external AI calls for retrieval, so in production deployments your team gets AI without a client's frames going to someone else's cloud.

04

Ready for the client security review

SSO over OIDC and SAML 2.0, authenticator-app MFA, role-based access, and a severity-tagged audit trail you export straight to your SIEM. Every generated output carries visible watermarking, and images carry C2PA Content Credentials with an AI-source assertion. A SOC 2 Type II aligned engineering posture, designed for MPA content-security best practices.

Your part of the stack

The pieces that earn their keep for systems, storage & it (post house / vfx / finishing facility).

Book the ones that fit your team, or the whole platform. Each shares one index.

A day in the life

Standing up the platform, the way facility IT actually does it

STEP 01

Deploy inside your own walls

Stand it up in your own AWS account or on-prem, hybrid supported, and point it at your identity provider over OIDC or SAML 2.0. Turn on authenticator-app MFA, scope roles per client and project, and keep it read-only against your storage to start. Nothing is migrated and nothing is touched while you get comfortable, and in production deployments the content stays in your environment.

STEP 02

Pull the duplicate and cost report

Before you renew a tier or size the next PO, Gateway shows checksum-level duplicates and storage cost across all 8 tiers, cloud, on-prem and LTO tape. You reclaim the space that duplicates were paying rent on and hand finance a number instead of a bigger invoice. Nexus SKIPs the next re-drop of a delivery you already have.

STEP 03

Turn on governed AI, then hand the auditor a clean trail

Switch on generation pinned to models you approve, confirm Fabric's embeddings compute inside the environment with no external AI calls, and turn on visible watermarking on every output plus C2PA on images. When a client's security review arrives, show content staying in your environment, provenance on every generated asset, and a full audit trail wired to your SIEM. Prove the whole thing first on a four-week pilot, on archival data you choose, deleted and verified at wrap.

Questions
Can we run Asset Foundry in our own AWS account or on-prem?

Yes. It deploys into your own AWS account or on-prem, hybrid supported, so in production deployments your clients' content stays in your environment. It starts read-only against your storage with nothing migrated, and Fabric computes embeddings inside your deployment with no external AI calls for retrieval. The optional fast-start pilot runs single-tenant in Fortify's cloud on archival data you choose, deleted and verified at wrap.

How do we find duplicate files across our storage tiers?

Gateway produces checksum-level duplicate reports across all 8 storage tiers, matching on the file's checksum rather than its name or path. A master copied across cloud, on-prem and LTO tape under different names is still recognized as one asset, so you can see exactly what is paying rent and reclaim the space with confidence. Cost reports across the same 8 tiers turn every retention and capacity call into a number instead of a guess.

Can our team use generative AI without a client's content leaving the building?

Yes. 60+ generative models sit behind one API on elastic GPU that scales from zero to N and back to zero. Fabric computes embeddings inside your own deployment with no external AI calls for retrieval, generation is pinned to local models or providers you approve, and every output carries visible watermarking with C2PA Content Credentials on images. In production deployments the content stays in your environment, and every job is audited.

What do we hand a client's security review?

SSO over OIDC and SAML 2.0, authenticator-app MFA, role-based access, and a severity-tagged audit trail you export to your own SIEM, plus visible watermarking and C2PA provenance on generated assets and content staying in your environment in production deployments. It is built to a SOC 2 Type II aligned engineering posture and designed for MPA content-security best practices, which describe engineering discipline rather than third-party certification. The fastest way to prove it is a four-week pilot on data you choose, deleted and verified at wrap.

Prove it on your own work

Four weeks. Your team's numbers.