Evaluate a forensic watermarking solution by defining the protection need, distribution model, response workflow and attribution target first. Then compare every vendor under the same conditions across eight criteria: detection time, minimum usable sample, robustness, delivery integration, identifier design, mixed-copy handling, PoC acceptance and total cost. Use the 100-point scorecard below.
On this page6 sections
Table 1.Scorecard, 100 points
100 points totalScore every vendor from 1 to 5 on each row. 1 means no evidence, 5 means clear evidence you can check. Multiply each score by the weight shown, add the results, then divide by five to get a mark out of 100. Score the evidence, not the presentation.
| No. | Criterion | Weight | What to ask for | Warning sign |
|---|---|---|---|---|
| 1 | Detection time | 15 pts | How long each stage takes, measured on clean and on damaged samples, with the start and stop point of every timer written down. | One best case number with no test conditions. |
| 2 | Minimum usable sample | 10 pts | How much video the detector needs for each relevant motion profile, acquisition method and agreed degradation. | A single number presented as if it applies to everything. |
| 3 | Robustness and test scope | 20 pts | A named test matrix covering transformations and capture methods, the settings used, and how often the right copy was identified. | The words attack resistant with no test list behind them. |
| 4 | Delivery-workflow integration | 15 pts | A walkthrough of the relevant delivery model, including variant creation, per-delivery selection, available identity signals and failure behaviour. | A generic "no player change" claim with no architecture for your delivery path. |
| 5 | Identifier and payload | 10 pts | The payload required for your attribution scale; how identifiers stay unique and map through to the agreed attribution target; and exactly what the detector and mapping service return. | A capacity figure quoted instead of a working identity design. |
| 6 | Mixed-copy (collusion) handling | 10 pts | A commitment to run the agreed mixed copy tests during the proof of concept, and how results will be reported. | A confident claim with no test planned on your content. |
| 7 | PoC model | 10 pts | A written plan with pass or fail levels agreed in advance and a named person who signs off each result. | A polished demo with no exit criteria. |
| 8 | Pricing and total cost | 10 pts | Cost split into one off, recurring, usage based, third party and internal effort, with the assumptions stated. | A single price with no scope or architecture attached. |
1.Define the use case
Define the protection need, distribution model, required response, attribution target and operational owner. Record them on one page and send the same brief to every vendor.
Use the OTT content protection checklist for OTT delivery and the IPTV deployment guide for managed IPTV. A published integration schema for server-side A/B watermarking also gives vendors shared vocabulary[1].
2.Measure performance
Forensic watermarking puts an invisible identifier into each authorised copy. When a copy leaks, a detector reads that identifier back from a captured sample. The four questions below decide whether that works fast enough to be useful.
2.1Detection time
Detection time is really three clocks. Acquisition time is how long it takes to capture enough of the unauthorised stream. Analysis time is how long the detector needs. Response time is how long it takes for the result to reach someone who can act. Vendors often quote only the middle one.
Ask for a typical value and a worst case value, for the exact moment each timer starts and stops, and for results on damaged samples as well as clean ones. Ask which confidence level the figure assumes.
Note
A number without test conditions is a marketing claim, not a result.
2.2Minimum usable sample
The minimum usable sample is the shortest video segment the detector needs. A usable figure must state the test conditions.
Require separate results by motion profile, acquisition method and degradation. Also confirm whether the sample must be continuous and whether black frames, credits or still scenes count.
2.3Robustness
Robustness means the identifier can still be recovered after transformation or re-capture. Replace the phrase attack resistant with a test matrix. Ask which conditions were tested, with what settings, and how often the right copy was identified.
Ask for the software version and the date of the report, and check that both match the product being offered. Enhanced content protection specifications are a useful reference when writing these requirements[2]. Vestigit publishes its own robustness and validation detail in the same terms.
2.4Mixed-copy (collusion) test
Collusion here means attackers combining two or more authorised copies. Agree a mixed-copy test up front, on your own content, and ask the vendor to demonstrate it during the proof of concept and report the results.
3.Check technical fit
Most projects are decided by the work around the mark rather than by the mark itself. Two areas matter: where the system touches each delivery model, and how the recovered identifier resolves to the agreed attribution target.
3.1Integration
- Delivery model and components in scope: OTT, managed IPTV, or both.
- Where the two variants are created and how encoded representations stay aligned.
- Where per-delivery variant selection happens for each distribution model.
- Which session or entitlement signal is available at that point.
- Effect on caching, origin or headend load, latency and delivery continuity.
- Failure behaviour, logging and operational ownership.
Compare the answers against your own setup in Architecture and Integrations, and ask for a table naming who owns each component.
Note
No player change does not mean no integration work. Ask where the work moves to.
3.2Identifier and mapping
What matters is not a capacity figure. It is whether you can run enough unique identifiers for the expected scale, and whether a recovered identifier resolves to the agreed attribution target.
Prefer identifiers that carry no personal data. Review where the mapping is stored alongside your security and privacy requirements.
4.Prove it
4.1PoC
A useful proof of concept runs on your own content, on a path that looks like production, with pass levels agreed in writing before any test starts. Three stages keep the result readable.
Agree a pass level and an owner for each of these: picture quality, correct attribution rate, false results, robustness coverage, minimum sample length, time to an actionable result, delivery-layer impact, failure behaviour, and operational readiness. Vestigit runs this shape as a discovery and PoC engagement, and you can require the same shape from any supplier.
4.2Cost and pricing factors
Request the same five cost groups from every vendor, with the assumptions beside each one.
Compare totals only after the scope and architecture match.
5.Procurement checklist
Ask every shortlisted vendor for the same pack. It is short enough to paste into an RFP, and gaps become visible straight away.
- Test conditions, with the start and stop point of every timer.
- Sample-length table by motion profile, acquisition method and agreed degradation.
- Robustness report, with the software version and the report date.
- Diagram of your delivery path and who owns each part.
- Identifier and mapping note.
- Scope of the agreed mixed copy tests.
- PoC plan with pass levels and named sign off owners.
- Full cost breakdown, with growth and overage assumptions.

