Frequently asked questions
What is invisible forensic watermarking?
Invisible forensic watermarking (a steganography technique) embeds a hidden, individualized identifier into each copy of a file, message, or screen — a different mark for every recipient. The mark cannot be seen and does not change how content looks or reads, but it can be recovered later to determine exactly whose copy a leaked artifact came from. It is sometimes called forensic fingerprinting, and it differs from a visible watermark, which asserts ownership rather than identifying a recipient.
How do you find out who leaked a document?
If every copy was individually watermarked before distribution, you upload the leaked artifact — a file, a screenshot, a photo, a printout, or even pasted text — to EchoMark's investigation tool. It recovers the mark, compares it against every marked copy that was distributed, and returns the recipient whose copy leaked, along with a confidence score, the time that copy was created, and chain-of-custody documentation. This typically takes minutes rather than the weeks a conventional investigation requires.
Can a leak be traced from a photo of a screen or a screenshot?
Yes, and this is the case most tools cannot handle, because content photographed off a screen never crosses the network. EchoMark watermarks persist into the resulting photograph or screenshot. Because the marks are embedded across the whole display, email, image, or document, attribution can be recovered even from a cropped image or a photo taken at an angle.
Do invisible watermarks survive printing, photocopying, and low-quality images?
Yes, they are specifically designed to. Marks are embedded steganographically in the content rather than in file metadata, so stripping metadata, re-saving, or converting formats does not remove them. For images specifically, EchoMark's Luma image mark is built for degradation and survives printouts, photocopies, and mobile photos, while the Chroma mark protects against high-fidelity leaks of the original file. Detection uses computer vision, which tolerates distortion, angles, and compression typical of a phone photograph.
Can an email leak still be traced if the text was re-typed or no leaked artifact surfaces?
Often, yes. EchoMark offers optional AI-rephrasing for emails, which generates alternate phrases throughout the email that are literally unique, but semantically the same. Each alternative phrase preserves the meaning and tone of the original. When these alternative phrases are applied throughout an entire email, each user can receive a unique copy of the email - so even if only a quoted passage surfaces later, that specific combination of phrases can be traced back to an individual.
How is forensic watermarking different from DLP?
Data loss prevention monitors data in motion and tries to block sensitive content from leaving, which means it can interrupt legitimate work and cannot help once someone bypasses the network entirely with a camera. Forensic watermarking takes the opposite approach: people keep working normally, and every copy stays individually attributable after the fact. The two are complementary — EchoMark covers the offline and analog paths DLP structurally cannot see.
Can EchoMark be deployed on-premises or in air-gapped environments?
Yes. EchoMark supports multi-tenant SaaS, single-tenant, on-premises, and fully air-gapped deployments, including government special clouds. In those configurations no content leaves your infrastructure and no EchoMark personnel have access to your systems or data.