Fortress embeds an invisible, evidence-grade signature into your photos, videos and audio — one that survives the real distribution path: JPEG, H.264, MP3, resize, crop. Measured, not promised. 100% EU-sovereign, offline on your infrastructure. And when someone steals your work or an AI model ingests it, Fortress names the source and turns the EU AI Act, GDPR and DSM Directive into your leverage — not just a pretty label.
The invisible mark survives JPEG compression, re-color, noise and downscaling to 75% at 100% @ ~28–32 dB PSNR. C2PA/EXIF metadata is stripped on the first re-save or screenshot — Fortress lives IN the pixel, not beside it.
Crop-hardened: 10–50% crop → 100% recovery (4×4 tiling, each tile carries the full key). Video survives real H.264 (BER 0% + temporal majority), audio real MP3/AAC/Opus (confidence 0.97).
Every delivery carries its own invisible recipient signature. If your work resurfaces, the automated scan names exactly whose access it leaked through — 0 misattributions across 49 recipients in internal testing.
Watermarking runs fully on-prem/offline — no US subprocessors, no cloud transfer, no US Cloud Act exposure. Privacy-by-design under GDPR; your work never leaves your infrastructure.
The mark + machine-readable opt-out reservation become evidence. Fortress generates the GDPR Art. 15 / EU-AI-Act Art. 53 request and prepares filings for 5 court profiles (CH/DE/AT). You or your lawyer file — no auto-filing.
RESILIENT proves ownership and survives distribution. FRAGILE proves authenticity — shatters on any manipulation and exposes AI redraw (sign-flip 49%, 6/6 tamper channels). The live seal applies only to captures from your own camera, never uploads.
Six stages — two deliberately in human hands (obtaining the evidence item and the final filing by a lawyer). That keeps it legally clean and robust for due diligence.
Each delivery gets an invisible recipient key.
3 OS scanners (feeds · repos · media) extract the key from supplied sources.
SHA-256 + Ed25519 + ML-DSA-65 + POAW → tamper-evident dossier.
Auto-generated: GDPR Art. 15 / EU AI Act Art. 53.
Routing to 5 court profiles CH/DE/AT — prepared.
A human reviews & files. No autonomous filing.
Honest scope: scanners extract from sources you supply or are authorized to inspect — no active web crawling; “no hit ≠ no leak”. Actual submission to the court system is simulated today; it is triggered by a lawyer (and is legally impermissible autonomously).
The ownership mark on every upload. Mark an image and read the verdict beside it: we measure ΔE00 (CIEDE2000) against the threshold 1.0 — the colour distance at which the human eye can tell any difference at all — and we report the worst 64×64 window, not the image average. An average cannot show a local blemish; that is exactly where the old PSNR figure failed.
Measured on 12 real photos: worst window ΔE00 0.39, 0.35 in smooth areas — both well below the threshold. JPEG q75/q50/q30 12/12 each, downscale to ½ 12/12, 0 false alarms. Limit: this profile does not survive cropping — the crop-proof profile below does, but it is visible.
This demo runs the exact shipped, IP-scoped Anti-Piracy SDK (only this capability is loaded — no other). Mark an image for a subscriber, simulate a leak via 25% crop, and let Fortress name the account.
Runs fully locally — no upload leaves your device. The same engine (v1.2.0) powers every Fancci plan.
For live-captured content: seal an image, verify it (unchanged → 0% flips), then tamper with it — Fortress detects the change and shows where (locality). In-app live capture only (Rule 10); the badge says “captured live & unaltered”, never “not AI-generated”.
Fragile seal = authenticity. Resilient mark (above) = provenance. Two shields, one engine.
A platform, a studio, a publisher: you are not protecting one work but the works of hundreds of creators. Fortress takes four jobs off your hands.
Jede Auslieferung traegt eine eigene, unsichtbare Marke. Taucht eine Kopie auf, benennt die Extraktion den Account, nicht „irgendjemand". Das ist der eigentliche Wert: das Wasserzeichen beantwortet wer — nicht wo.
Maschinell erkennbare Markierung KI-erzeugter Inhalte — die Pflicht greift ab August 2026.
Das fragile Siegel gibt es nur fuer eine Live-Aufnahme, nie fuer einen Upload — dreifach abgesichert. Das Badge sagt „live aufgenommen & unveraendert", nie „nicht KI-generiert".
Aus einem Fund wird ein Dossier, das ein Anwalt einreichen kann — DSA Art. 16 verpflichtet Plattformen, auf Meldungen zu reagieren. Ohne diesen Schritt bleibt jeder Fund folgenlos.
Wir sagen nicht „Fortress macht euch compliant". Das kann kein Anbieter: Compliance ist eine Eigenschaft eurer Umsetzung, nicht eines Produkts. Was wir liefern, ist eine verteidigbare Ausgangslage — pseudonyme Marken je Abonnent statt eines zentralen Datentopfs, EU-souveraen und offline lauffaehig, und ein offensiver Hebel gegen Scraper statt nur einer Abwehrhaltung.
Plattform-Lizenz jaehrlich, gestaffelt nach aktiven Creators — die wiederkehrende Linie. Erkennung als Dienst je geprueftem Verdachtsfall. Durchsetzungsanteil an tatsaechlich durchgesetzten Anspruechen — gleichgerichtete Interessen. Ein Modell, keine Messung: die Zahlen dahinter sind Annahmen, keine Ergebnisse.
Jede der zwoelf Faehigkeiten hat eine eigene Seite mit einer Live-Demo auf demselben SDK und maschinell nachgepruefeten Zusagen: All 12 business cases.
| Capability | Signature | Guardian | Sovereign |
|---|---|---|---|
| Invisible ownership mark (resilient DCT-DC) | ✓ | ✓ | ✓ |
| Work registry / license entry | ✓ | ✓ | ✓ |
| Basic leak alert (media scan)¹ | ✓ | ✓ | ✓ |
| Per-viewer leak trace (0/49 FP) | — | ✓ | ✓ |
| Crop-hardened (10–50% → 100%) | — | ✓ | ✓ |
| Video (H.264) + audio (MP3/AAC/Opus) | — | ✓ | ✓ |
| Automatisierter Scan sweep (3 OS-Scanner)¹ | — | ✓ | ✓ |
| Evidence package (Ed25519 + ML-DSA-65) | — | ✓ | ✓ |
| Live-capture ProofCam authenticity² | — | ✓ | ✓ |
| DSR generation (GDPR 15 / AI-Act 53)³ | — | — | ✓ |
| Court-filing PREPARATION CH/DE/AT⁴ | — | — | ✓ |
| AI opt-out / license-claim pipeline | — | — | ✓ |
| Lugano CH↔EU cross-border | — | — | 🚧 Roadmap |
¹ Scanners extract from supplied sources — no active web crawling; “no hit ≠ no leak”.
² Live in-app capture only (Rule 10); badge = “captured live & unaltered”, not “not AI-generated”. No external PAD/iBeta certification.
³ Fortress generates the letter; sent by a human/lawyer.
⁴ Filing is prepared; actual submission is simulated today — a lawyer files.
1. Reservation. The platform publishes a machine-readable rights reservation (W3C TDMRep: tdm-reservation:1, /.well-known/tdmrep.json) per DSM Dir. Art. 4(3) + EU AI Act Art. 53(1)(c).
2. Evidence. The invisible provenance mark is the after-the-fact cryptographic proof: if it appears in an AI output, that — with the PQC-signed POAW timestamp — is rebuttable evidence of ingestion/ownership.
3. License key. Licensed trainers hold a signed key (registry is real: Trial 1,000 → Elite 500,000 media, ML-DSA-signed).
4. No key → claim. Without a license key the mark feeds the DSR/claim pipeline. The lever is registry + evidence + a human-sent claim.
The same invisible mark that names the leaker can also be a purchase pointer. Wherever your image surfaces — reshared, forwarded, screenshotted — it still points back to you and your offer. The copy that used to take revenue away becomes a route back to you.
The image carries no product data — it carries a 128-bit pointer. Your registry resolves it live, so price, availability and link stay editable and revocable at any time. The very same key is the leak-trace key.
Verified on real image files: JPEG q95/q85/q75/q60, crop 10/25/50 % and the screenshot combination (15 % crop + JPEG q80) — the pointer was recovered in every case. A QR code or metadata does not survive that.
Deactivated offer, deleted pointer, forged hash, unreachable registry: in every case no purchase card appears rather than a wrong one. Unmarked images produce no hits.
At upload — invisible, a pointer to your offer.
Repost, screenshot, crop: the pointer stays readable.
Inside the app that has the scanner — where you control the receiving side.
Current price, current link — payment through your payment provider.
One SDK per use case, cleanly IP-separated, every claim backed by a measured number. That is how you hand over a product that holds up in due diligence.