For studio security & IT

Powerful AI, fully governed,
inside your environment.

Asset Foundry runs in your AWS account or on-prem, so in production deployments your content stays in your environment. SSO, MFA and role-based access on the way in. Visible watermarking, C2PA Content Credentials and a full audit trail on the way out. Built to stand up to your next MPA and SOC 2 review.

The daily friction
Every vendor demo ends the same way: great tool, but it wants my content in someone else's cloud, and my answer is no.
Someone is already pasting frames into a public AI tool, and when legal asks I have zero provenance and zero audit trail.
The MPA site review is coming, and I can't vouch for a black-box platform I'm not allowed to see inside.
What changes for you
01

It runs where your content already lives.

Deploy into your own AWS account or on-prem, hybrid supported. In production deployments your content stays in your environment, with read-only access to your sources to start and no data migrated. The optional fast-start pilot runs single-tenant in Fortify's cloud on archival data you choose, deleted and verified at wrap.

02

Generative AI you can actually sign off.

60+ models sit behind one API. Embeddings are computed inside the deployment environment with no external AI calls for retrieval, generation is pinned to local models or providers you approve, and every output carries visible watermarking plus C2PA Content Credentials on images with an AI-source assertion. Every job is audited.

03

SSO, MFA and RBAC from day one.

Single sign-on over OIDC and SAML 2.0 through the identity broker, authenticator-app MFA, and role-based access scoped per production. Integration keys are held under managed credentials with a create, list and revoke lifecycle and per-action audit.

04

Ready for the MPA and SOC 2 review.

A SOC 2 Type II aligned engineering posture, designed for MPA content-security best practices, describing engineering discipline rather than third-party certification. It includes SSO, MFA, role-based access, and severity-tagged audit logging you can export to your own SIEM.

Your part of the stack

The pieces that earn their keep for content security & it.

Book the ones that fit your team, or the whole platform. Each shares one index.

A day in the life

Onboarding a new platform, the way security actually does it

STEP 01

Stand it up inside your walls

Deploy into your AWS account or on-prem, hybrid supported. Point it at your identity provider over OIDC or SAML 2.0, turn on authenticator-app MFA, and scope roles per production. It stays read-only against your sources to start, so nothing is touched while you get comfortable.

STEP 02

Turn on the guardrails

Pin generation to local models or providers you approve, confirm embeddings compute inside the environment, and switch on visible watermarking on every output plus C2PA Content Credentials on images. Wire the severity-tagged audit log to your SIEM and keep integration keys under managed credentials.

STEP 03

Prove it to the auditor

When the MPA or SOC 2 reviewer arrives, show content staying in your environment, watermarking and provenance on every generated asset, and a complete audit trail of who did what. Run the whole thing first as a four-week pilot on data you choose, deleted and verified at wrap.

Questions
Can we run Asset Foundry without our content leaving our environment?

In production deployments it runs inside your own AWS account or on-prem, so content stays in your environment. Embeddings are computed inside the deployment with no external AI calls for retrieval, and generation is pinned to local models or providers you approve. The optional fast-start pilot runs single-tenant in Fortify's cloud on archival data you choose, deleted and verified at wrap.

How does Asset Foundry govern generative AI and provenance?

60+ generative models sit behind one API. Every output gets visible watermarking on video, image and document, and images carry C2PA Content Credentials with an AI-source assertion. Every job is audited, and AI-suggested tags and mappings wait for human approval before anything is written.

Will Asset Foundry stand up to an MPA or SOC 2 audit?

It is built to a SOC 2 Type II aligned engineering posture and designed for MPA content-security best practices, which describe engineering discipline rather than third-party certification. That posture includes SSO, MFA, role-based access, and severity-tagged audit logging you can export.

How do identity, access and credentials work?

Single sign-on over OIDC and SAML 2.0 through the identity broker, authenticator-app MFA, and role-based access scoped per production. Machines use API keys with a managed create, list and revoke lifecycle, and integration secrets are held under managed credentials with per-action audit.

Prove it on your own work

Four weeks. Your team's numbers.