Creator protection · EU-sovereign · offline

Invisibly marked. Provably yours.
Even after screenshot, re-upload and compression.

Fortress embeds an invisible, evidence-grade signature into your photos, videos and audio — one that survives the real distribution path: JPEG, H.264, MP3, resize, crop. Measured, not promised. 100% EU-sovereign, offline on your infrastructure. And when someone steals your work or an AI model ingests it, Fortress names the source and turns the EU AI Act, GDPR and DSM Directive into your leverage — not just a pretty label.

100% @ ~28–32 dB PSNR (invisible) Crop 10–50% → 100% 0/49 misattributions H.264 BER 0 % · MP3/AAC/Opus 0.97
🩸
“Someone leaked it” becomes a name. Every delivery carries its own invisible viewer signature — the scan finds the copy and names the account. Try it live below.
Six reasons

Why Fortress is different

🧬
SURVIVES THE PIPELINE

Not just the first upload

The invisible mark survives JPEG compression, re-color, noise and downscaling to 75% at 100% @ ~28–32 dB PSNR. C2PA/EXIF metadata is stripped on the first re-save or screenshot — Fortress lives IN the pixel, not beside it.

✂️
SURVIVES THE CROP

Real video & audio too

Crop-hardened: 10–50% crop → 100% recovery (4×4 tiling, each tile carries the full key). Video survives real H.264 (BER 0% + temporal majority), audio real MP3/AAC/Opus (confidence 0.97).

🎯
NAMES THE LEAKER

Per viewer

Every delivery carries its own invisible recipient signature. If your work resurfaces, the automated scan names exactly whose access it leaked through — 0 misattributions across 49 recipients in internal testing.

🇪🇺
EU-SOVEREIGN & OFFLINE

No US Cloud Act

Watermarking runs fully on-prem/offline — no US subprocessors, no cloud transfer, no US Cloud Act exposure. Privacy-by-design under GDPR; your work never leaves your infrastructure.

⚖️
THE LAW AS LEVERAGE

Prepared, not autonomous

The mark + machine-readable opt-out reservation become evidence. Fortress generates the GDPR Art. 15 / EU-AI-Act Art. 53 request and prepares filings for 5 court profiles (CH/DE/AT). You or your lawyer file — no auto-filing.

🛡️
TWO SHIELDS

Provenance AND authenticity

RESILIENT proves ownership and survives distribution. FRAGILE proves authenticity — shatters on any manipulation and exposes AI redraw (sign-flip 49%, 6/6 tamper channels). The live seal applies only to captures from your own camera, never uploads.

From leak to enforcement

How automated tracing works

Six stages — two deliberately in human hands (obtaining the evidence item and the final filing by a lawyer). That keeps it legally clean and robust for due diligence.

STUFE 1

Viewer mark

Each delivery gets an invisible recipient key.

STUFE 2

Scan sweep

3 OS scanners (feeds · repos · media) extract the key from supplied sources.

STUFE 3

Evidence package

SHA-256 + Ed25519 + ML-DSA-65 + POAW → tamper-evident dossier.

STUFE 4

Legal letter

Auto-generated: GDPR Art. 15 / EU AI Act Art. 53.

STUFE 5

Court (prepared)

Routing to 5 court profiles CH/DE/AT — prepared.

STUFE 6

Lawyer files

A human reviews & files. No autonomous filing.

📜 DSR letter preview (Art. 15 / Art. 53) →

Honest scope: scanners extract from sources you supply or are authorized to inspect — no active web crawling; “no hit ≠ no leak”. Actual submission to the court system is simulated today; it is triggered by a lawyer (and is legally impermissible autonomously).

● Live · in your browser · offline

First the thing creators actually want: invisible

The ownership mark on every upload. Mark an image and read the verdict beside it: we measure ΔE00 (CIEDE2000) against the threshold 1.0 — the colour distance at which the human eye can tell any difference at all — and we report the worst 64×64 window, not the image average. An average cannot show a local blemish; that is exactly where the old PSNR figure failed.

Measured on 12 real photos: worst window ΔE00 0.39, 0.35 in smooth areas — both well below the threshold. JPEG q75/q50/q30 12/12 each, downscale to ½ 12/12, 0 false alarms. Limit: this profile does not survive cropping — the crop-proof profile below does, but it is visible.

Watch “someone” become a name

This demo runs the exact shipped, IP-scoped Anti-Piracy SDK (only this capability is loaded — no other). Mark an image for a subscriber, simulate a leak via 25% crop, and let Fortress name the account.

Runs fully locally — no upload leaves your device. The same engine (v1.2.0) powers every Fancci plan.

The second shield — tampering becomes visible

For live-captured content: seal an image, verify it (unchanged → 0% flips), then tamper with it — Fortress detects the change and shows where (locality). In-app live capture only (Rule 10); the badge says “captured live & unaltered”, never “not AI-generated”.

Fragile seal = authenticity. Resilient mark (above) = provenance. Two shields, one engine.

And if you are the platform

A platform, a studio, a publisher: you are not protecting one work but the works of hundreds of creators. Fortress takes four jobs off your hands.

🔒

Per-subscriber leak tracing

Jede Auslieferung traegt eine eigene, unsichtbare Marke. Taucht eine Kopie auf, benennt die Extraktion den Account, nicht „irgendjemand". Das ist der eigentliche Wert: das Wasserzeichen beantwortet wer — nicht wo.

🏷️

AI labelling (EU AI Act Art. 50)

Maschinell erkennbare Markierung KI-erzeugter Inhalte — die Pflicht greift ab August 2026.

🧿

Authenticity at capture

Das fragile Siegel gibt es nur fuer eine Live-Aufnahme, nie fuer einen Upload — dreifach abgesichert. Das Badge sagt „live aufgenommen & unveraendert", nie „nicht KI-generiert".

⚖️

Evidence that actually moves

Aus einem Fund wird ein Dossier, das ein Anwalt einreichen kann — DSA Art. 16 verpflichtet Plattformen, auf Meldungen zu reagieren. Ohne diesen Schritt bleibt jeder Fund folgenlos.

GDPR — put honestly

Wir sagen nicht „Fortress macht euch compliant". Das kann kein Anbieter: Compliance ist eine Eigenschaft eurer Umsetzung, nicht eines Produkts. Was wir liefern, ist eine verteidigbare Ausgangslage — pseudonyme Marken je Abonnent statt eines zentralen Datentopfs, EU-souveraen und offline lauffaehig, und ein offensiver Hebel gegen Scraper statt nur einer Abwehrhaltung.

How this pays

Plattform-Lizenz jaehrlich, gestaffelt nach aktiven Creators — die wiederkehrende Linie. Erkennung als Dienst je geprueftem Verdachtsfall. Durchsetzungsanteil an tatsaechlich durchgesetzten Anspruechen — gleichgerichtete Interessen. Ein Modell, keine Messung: die Zahlen dahinter sind Annahmen, keine Ergebnisse.

Jede der zwoelf Faehigkeiten hat eine eigene Seite mit einer Live-Demo auf demselben SDK und maschinell nachgepruefeten Zusagen: All 12 business cases.

Three plans

The right protection level for every creator

Basic
Fancci Signature
Solo creators who want invisible proof of ownership — with zero effort.
  • Invisible ownership watermark on every upload (~28–32 dB)
  • Work registry / license entry (author + timestamp)
  • Basic leak alert (media scan)¹
Price anchor: per-seat flat rate + per-asset — the impulse entry.
Popular
Premium
Fancci Guardian
Pro creators & studios with a paying community — who want to know who leaked.
  • Everything in Signature, plus:
  • Per-viewer leak trace — names the subscriber (0/49 FP)
  • Crop-hardened: Crop 10–50% → 100%
  • Video (H.264) & audio (MP3/AAC/Opus)
  • Automatisierter Scan sweep (3 OS-Scanner)¹
  • Signiertes Evidence package (Ed25519 + ML-DSA-65)
  • Live-capture ProofCam authenticity — in-app camera only²
Price anchor: per-seat + per-viewer-mark — “insurance on your revenue”.
Ultra
Ultra Premium
Fancci Sovereign
Top earners & agencies facing systematic theft / AI scraping.
  • Everything in Guardian, plus:
  • Auto-generated legal letters (GDPR 15 / AI-Act 53)³
  • Court filing prepared — CH/DE/AT⁴
  • AI opt-out + license registry (claim pipeline)
  • Lugano CH↔EU cross-border — Roadmap
  • Priority + dedicated contact
Price anchor: enterprise retainer + success-% on recovered revenue.🏛️ Sovereign ULTRA demo: see all 4 stakeholder dashboards live →
CapabilitySignatureGuardianSovereign
Invisible ownership mark (resilient DCT-DC)
Work registry / license entry
Basic leak alert (media scan)¹
Per-viewer leak trace (0/49 FP)
Crop-hardened (10–50% → 100%)
Video (H.264) + audio (MP3/AAC/Opus)
Automatisierter Scan sweep (3 OS-Scanner)¹
Evidence package (Ed25519 + ML-DSA-65)
Live-capture ProofCam authenticity²
DSR generation (GDPR 15 / AI-Act 53)³
Court-filing PREPARATION CH/DE/AT⁴
AI opt-out / license-claim pipeline
Lugano CH↔EU cross-border🚧 Roadmap

¹ Scanners extract from supplied sources — no active web crawling; “no hit ≠ no leak”.
² Live in-app capture only (Rule 10); badge = “captured live & unaltered”, not “not AI-generated”. No external PAD/iBeta certification.
³ Fortress generates the letter; sent by a human/lawyer.
⁴ Filing is prepared; actual submission is simulated today — a lawyer files.

AI scraping

When a model eats your work — the lawful lever

How it works — honestly

1. Reservation. The platform publishes a machine-readable rights reservation (W3C TDMRep: tdm-reservation:1, /.well-known/tdmrep.json) per DSM Dir. Art. 4(3) + EU AI Act Art. 53(1)(c).

2. Evidence. The invisible provenance mark is the after-the-fact cryptographic proof: if it appears in an AI output, that — with the PQC-signed POAW timestamp — is rebuttable evidence of ingestion/ownership.

3. License key. Licensed trainers hold a signed key (registry is real: Trial 1,000 → Elite 500,000 media, ML-DSA-signed).

4. No key → claim. Without a license key the mark feeds the DSR/claim pipeline. The lever is registry + evidence + a human-sent claim.

What we do NOT claim (Rule 9)

  • No “model poisoning”. Poisoning models without a license key is not built and not sold (patent optionality, not a product).
  • No automatic fee. Fortress does not collect a license fee autonomously — it delivers evidence + a ready claim; a human enforces it.
  • No autonomous litigation. Basis: Hamburg Regional Court 27 Sep 2024 (Kneschke v. LAION) — the reservation must be machine-readable per the state of the art. Auto-publishing TDMRep is Roadmap.
  • A full redraw destroys the resilient mark (information theory) — which is exactly why the fragile product exists for authenticity.
🛡️ Generate the AI opt-out for your domain →
Sovereign Commerce · pilot

The leak becomes a storefront.

The same invisible mark that names the leaker can also be a purchase pointer. Wherever your image surfaces — reshared, forwarded, screenshotted — it still points back to you and your offer. The copy that used to take revenue away becomes a route back to you.

🔗
ONE POINTER, TWO PRODUCTS

Protection and sales from one mark

The image carries no product data — it carries a 128-bit pointer. Your registry resolves it live, so price, availability and link stay editable and revocable at any time. The very same key is the leak-trace key.

📤
14/14 MEASURED

Survives real sharing

Verified on real image files: JPEG q95/q85/q75/q60, crop 10/25/50 % and the screenshot combination (15 % crop + JPEG q80) — the pointer was recovered in every case. A QR code or metadata does not survive that.

🛑
9/9 ADVERSARIAL

No card without a real pointer

Deactivated offer, deleted pointer, forged hash, unreachable registry: in every case no purchase card appears rather than a wrong one. Unmarked images produce no hits.

What it looks like for a creator

01

Mark the image

At upload — invisible, a pointer to your offer.

02

It gets shared

Repost, screenshot, crop: the pointer stays readable.

03

Pointer is detected

Inside the app that has the scanner — where you control the receiving side.

04

Card appears

Current price, current link — payment through your payment provider.

Honest framing (Rule 9): Sovereign Commerce is a pilot / roadmap building block, not a shipped product. What is proven today are the technical core claims: 14/14 through the real sharing pipeline, 9/9 against attacks on pointer resolution. Not proven and therefore not claimed: revenue impact, conversion rates or market share — our unit-economics work is a model, not a measurement. The price of robustness: the share-hardened profile sits at ~20.7 dB PSNR instead of ~28–32 dB — more visible than the pure protection profile; that is a per-catalogue decision, not a free lunch. Reach: invisible marks need a scanner — given inside your own app's closed loop, not on the open web. Payments run through your existing payment provider; we neither assume nor mandate one.

Ready to truly protect your creators?

One SDK per use case, cleanly IP-separated, every claim backed by a measured number. That is how you hand over a product that holds up in due diligence.