Data boundary, identifier handling and responsibility.
How Vestigit treats identifiers, samples and detection records, and where the boundary sits between the customer's stack and the Vestigit service.
How Vestigit handles video, identifiers and detection artefacts.
Video and identifier processing occurs in agreed environments. Customer identity systems remain the source of truth. Only the customer maps identifiers to a person, account, subscriber or device. Detection records are designed to support investigations; they are not represented as admissible legal evidence and do not commit Vestigit to specific certifications, subprocessor lists, retention or residency guarantees on this page.
Data boundary at a glance
Video and identifier processing occurs in agreed environments. Customer identity, authentication and entitlement systems remain the source of truth; Vestigit may receive pseudonymous session context required for internal technical correlation.
Identifier ownership
The embedded identifier is opaque. Only the customer maps a result to a person, account, subscriber or device — that mapping stays inside the customer entitlement layer.
Detection record
The recovered identifier is the core output. Workflow context, timestamp and sample reference depend on the validated deployment and sample path.
Customer-controlled policy
Revocation, blocking and takedown decisions remain owned and executed by the customer.
Where Vestigit ends and your stack begins.
| Area | Customer | Vestigit |
|---|---|---|
| Content ingest & encoding | Owned | Integrates into supported stages |
| Session identity & mapping | Owned | Provides mapping surface |
| Watermark embedding | Provides workflow access | Owned |
| Sample capture | Owned or provider-fed | Assists in defined workflows |
| Detection & attribution | Consumes results | Owned |
| Policy & enforcement | Owned | Provides evidence inputs |
| Data residency & retention | Owned | Agrees during discovery |
Questions we scope together.
- Data residency requirements for sample and detection artefacts.
- Retention policy for samples, detections and audit logs.
- Encryption in transit and at rest for the sample path.
- Access control model, role assignment and audit-log expectations.
- Logging integrations with the customer SIEM / observability stack.
- Restricted-network access model for on-prem or hybrid deployments.
What to request during discovery.
- Solution scope and data boundary description.
- List of independent assessments available to review under NDA.
- Shared responsibility matrix agreed for the target deployment.
- Discovery inputs required for security, legal and procurement review.
Discuss security and data requirements.
Data boundary, retention, logging integrations and shared responsibility — aligned during discovery.

