VEILGUARD

CONTENT SHIELD // ATTRIBUTION LAYER ACTIVE // PHASE 1 OPERATIONAL

VEILGUARD is the ClearGlass content protection layer — a defense-in-depth architecture for images, screenshots, concept drafts, media uploads and proprietary workflow content. It is built entirely from lawful, consent-based controls: dynamic watermarking bound to viewer and session, traceable per-render variants, ephemeral previews, scoped permissions, tamper-evident logging, honeypot canaries, and risk-driven access that tightens on its own.

It is designed to be invisible. A legitimate viewer sees a clean surface and one quiet disclosure line — not a wall of warnings and disabled buttons. Restriction that announces itself invites the challenge; protection that simply makes the easy paths unrewarding, and every leaked frame attributable, does not.

DEFENSE STACK · SEVEN LAYERS

01

EDGE

Session gate, burst limiting and protected-route enforcement at the perimeter. Everything below assumes this layer has already been passed — a valid session is not a trusted session.

02

IDENTITY

Plan, session reference and a first-party device token. No covert fingerprinting: no canvas, font or WebGL probing, and no cross-site identifier.

03

RISK

Coarse, consented signals scored 0–100 with a named reason for every point. Access breadth, refusal counts, capture-shaped interactions, device age, implied travel.

04

POLICY

Classification × plan × risk resolved by subtraction only — no combination can ever grant a capability that one of the three withheld. Verified exhaustively in CI.

05

GRANT

An HMAC-signed, expiring authorisation carrying capabilities, the tracer and the watermark. The client is told what it may do; the server decides what it may do.

06

RENDER

Capped resolution, rotating watermark, an ephemeral window that closes on its own, and deterrence for the easy copy paths — all without trapping the keyboard or blocking zoom.

07

RECORD

A hash-chained, pseudonymous event ledger. Editing, deleting or reordering history breaks the chain at the point of the change, and an external anchor catches a full rewrite.

TRACER · PER-VIEWER ATTRIBUTION

K7M2Q9XB

Every render carries an 8-character tracer in Crockford base32 — no I, L, O or U, the glyphs people misread off a screen. Change the identity to see the code change.

EVIDENCE STRENGTH FROM A PARTIAL CAPTURE

A leak rarely arrives intact. Tracing compares only the characters that survived, and reports how likely an unrelated viewer would match that well by chance.
RecoveredFalse matchVerdict
All 8 characters9 × 10⁻¹³Conclusive
4 characters1 × 10⁻⁶Strong
3 characters3 × 10⁻⁵Indicative
1 character3 × 10⁻²Inconclusive

SHIELD TELEMETRY · SIMULATED STREAM

[BOOT] Shield initialised · policy table loaded · 4 classification tiers

[KEY] Signing key present · tracer derivation domain-separated

[LEDGER] Hash chain verified · head anchored to external store

[CANARY] 24 enumeration canaries armed · linked from nowhere

[GRANT] concept-draft-atlas · restricted · view-only · TTL 90s

[MARK] Watermark rotation 20s · tracer variants applied across 20 tiles

[SIGNAL] Capture-shaped keystroke observed · frame obscured · logged

[RISK] Session re-scored 31/elevated · share capability withdrawn

STATED PLAINLY · WHAT THIS CANNOT DO

  • A web page cannot prevent a screenshot. The operating system's capture path does not consult the page. Anyone claiming otherwise is describing a speed bump.
  • A camera pointed at a monitor defeats every software control ever written.
  • Content cannot be prevented from leaving. A determined viewer always wins.
  • A leaked frame can usually be traced back to the grant that produced it — from a partial, re-photographed crop.
  • Casual reuse stops being one gesture, which covers the overwhelming majority of real-world loss.
  • Access narrows automatically as a session starts to look unusual, with no human in the loop.
  • The audit record cannot be quietly edited after the fact.

THREAT MATRIX · CONTROL AND RESIDUAL RISK

ThreatControlResidual
Right-click save, drag to desktopContext menu and drag suppressed on the shielded surface when export is not grantedMitigated screenshot path remains, and is marked
Screenshot of a confidential renderRotating per-viewer watermark and tracer; frame obscures on capture keystroke and focus lossAttributable not prevented
Bulk harvesting across many assetsBreadth signal raises risk; capabilities withdrawn at high band; grant lifetimes shortenSlowed patient low-rate scraping
Identifier enumerationRefusals counted into risk; canaries answer identically to unknown identifiersMitigated prober learns nothing, own risk rises
Client tampering to widen permissionsCapabilities carried in an HMAC-signed grant; policy re-derived server-side every requestMitigated
Forged telemetry to frame another viewerAttribution read from the verified grant, never from the request bodyMitigated attacker can only raise their own risk
Editing the audit record after an incidentHash-chained ledger; entry hash covers contents; verification reports the break pointDetected full rewrite needs the anchor too
Leaked export surfacing elsewhereDisclosed per-recipient beacon minted into each exported copyDetected unless stripped or opened offline
Camera photograph of the screenVisible watermark survives re-photographyNot prevented remains attributable

PRIVACY BY CONSTRUCTION

NO COVERT TRACKING

Every control is disclosed to the viewer. No canvas, font or WebGL probing; no cross-site identifier.

PSEUDONYMOUS LEDGER

Entries carry a salted reference, never a raw identity. Re-identification is a separate, gated capability.

BOUNDED RETENTION

Risk state is a 15-minute rolling window — never a standing behavioural profile on a person.

MASKED MARKS

Watermarks can show a masked identity. The tracer does the attribution, so masking costs nothing.

ACCESSIBILITY IS NOT OPTIONAL

CONTENT STAYS READABLE

Images keep real alt text; the watermark overlay is hidden from assistive technology rather than read aloud.

NO TRAPS

No keyboard trap, no focus suppression, no zoom blocking. Every permitted action has a real focusable control.

REDUCED MOTION

Watermark animation stops on request; rotation continues, because it is a security function rather than decoration.

A STANDING ALTERNATIVE

Every shielded item links to a route for requesting an accessible or unmarked copy.

PHASED ROLLOUT

PHASE 1 · ATTRIBUTION Shipped

Grant gate, tracer and rotating watermark, hash-chained ledger, risk scoring, canaries, shielded viewer.

PHASE 2 · DURABILITY Next

Durable append-only ledger, shared cross-replica state, external checkpoint anchoring, CSP and cache headers.

PHASE 3 · SERVER BURN-IN Planned

Restricted assets rasterised server-side with the mark burned in, so no unmarked source reaches the browser at all.

PHASE 4 · DETECTION AT SCALE Planned

Beacon alerting, scheduled canary sweeps, reverse image search, per-cohort anomaly baselining.

VEILGUARD ships as part of the ClearGlass governed commerce platform. The full threat model, architecture and implementation strategy are documented alongside the source, and the protection invariants are enforced by continuous integration rather than by convention.

Book a security engagement