Asset Foundry runs in your AWS account or on-prem, so in production deployments your content stays in your environment. SSO, MFA and role-based access on the way in. Visible watermarking, C2PA Content Credentials and a full audit trail on the way out. Built to stand up to your next MPA and SOC 2 review.
Deploy into your own AWS account or on-prem, hybrid supported. In production deployments your content stays in your environment, with read-only access to your sources to start and no data migrated. The optional fast-start pilot runs single-tenant in Fortify's cloud on archival data you choose, deleted and verified at wrap.
60+ models sit behind one API. Embeddings are computed inside the deployment environment with no external AI calls for retrieval, generation is pinned to local models or providers you approve, and every output carries visible watermarking plus C2PA Content Credentials on images with an AI-source assertion. Every job is audited.
Single sign-on over OIDC and SAML 2.0 through the identity broker, authenticator-app MFA, and role-based access scoped per production. Integration keys are held under managed credentials with a create, list and revoke lifecycle and per-action audit.
A SOC 2 Type II aligned engineering posture, designed for MPA content-security best practices, describing engineering discipline rather than third-party certification. It includes SSO, MFA, role-based access, and severity-tagged audit logging you can export to your own SIEM.
Book the ones that fit your team, or the whole platform. Each shares one index.
Your identity and audit layer: SSO over OIDC and SAML 2.0, authenticator-app MFA, role-based access scoped per production, and a severity-tagged audit trail you can export to your own SIEM. It is the front door you already know how to govern.
Provenance baked in, not bolted on: every processed or generated output carries visible watermarking on video, image and document, plus C2PA Content Credentials on images with an AI-source assertion, so you can always answer where an asset came from.
Retrieval that respects permissions: embeddings are computed inside your deployment environment with no external AI calls, and access controls apply inside the query, so people only ever surface what they are cleared to see.
Nothing moves without a record: write paths are explicit and opt-in, every transfer is checksummed and logged, and duplicates are caught with checksum-level duplicate detection before they sprawl across your storage.
Deploy into your AWS account or on-prem, hybrid supported. Point it at your identity provider over OIDC or SAML 2.0, turn on authenticator-app MFA, and scope roles per production. It stays read-only against your sources to start, so nothing is touched while you get comfortable.
Pin generation to local models or providers you approve, confirm embeddings compute inside the environment, and switch on visible watermarking on every output plus C2PA Content Credentials on images. Wire the severity-tagged audit log to your SIEM and keep integration keys under managed credentials.
When the MPA or SOC 2 reviewer arrives, show content staying in your environment, watermarking and provenance on every generated asset, and a complete audit trail of who did what. Run the whole thing first as a four-week pilot on data you choose, deleted and verified at wrap.
In production deployments it runs inside your own AWS account or on-prem, so content stays in your environment. Embeddings are computed inside the deployment with no external AI calls for retrieval, and generation is pinned to local models or providers you approve. The optional fast-start pilot runs single-tenant in Fortify's cloud on archival data you choose, deleted and verified at wrap.
60+ generative models sit behind one API. Every output gets visible watermarking on video, image and document, and images carry C2PA Content Credentials with an AI-source assertion. Every job is audited, and AI-suggested tags and mappings wait for human approval before anything is written.
It is built to a SOC 2 Type II aligned engineering posture and designed for MPA content-security best practices, which describe engineering discipline rather than third-party certification. That posture includes SSO, MFA, role-based access, and severity-tagged audit logging you can export.
Single sign-on over OIDC and SAML 2.0 through the identity broker, authenticator-app MFA, and role-based access scoped per production. Machines use API keys with a managed create, list and revoke lifecycle, and integration secrets are held under managed credentials with per-action audit.