Encypher Trace
When protected content surfaces, trace the copy it came from.
Give every recipient a copy with its own invisible fingerprint. If protected content leaks, a recoverable marker connects it to the recipient, session, and timestamp, turning a broad investigation into a direct lead.
Per-recipient
invisible fingerprint on every copy you share
3
fields on a resolved record: recipient, session, and timestamp
Print recovery
available now for protected documents and recovered scans
Trace in action
Watch a leaked copy give itself up
A controlled board brief goes out, comes back as a printed and scanned PDF, and the public verifier still names the copy it came from. The marker rides in the text, so it survives the trip through a printer.
Try the scanned PDFHow it works
Protect it, share it, resolve a recovered marker
Protection happens before you send, so tracing a leak later is a lookup, not an investigation from scratch.
- 1
Protect before you share
Before you distribute, each recipient gets their own copy carrying a unique, invisible fingerprint embedded in the content itself.
- 2
Share through your normal workflow
Send protected copies as usual. The digital marker is designed for common copy-paste paths, and enterprise plans can add print provenance before distribution.
- 3
Resolve a recovered marker
Upload a preserved marked fragment or recovered scan. When the marker is recoverable, Trace maps it to the recipient, session, and timestamp for an investigation record.
Investigation outcome
A recovered fragment becomes a direct lead
Move from a preserved marker to the distribution record your team can review.
Illustrative investigation record
Recovered fragment
Scan path selected
"The revised operating plan keeps the Q3 launch sequence and review gates unchanged."
An Encypher marker was recovered from the preserved text.
Resolved investigation record
- Resolved recipient
- Recipient 04
- Distribution session
- Board briefing / session 04
- Protected timestamp
- 2026-07-18 14:32 UTC
- Recovery path
- Selected: ScanOther paths: photo / copied text
- Evidence export
- Available
What Trace does
A unique marker on every protected copy
Each recipient gets a distinct invisible marker. When a preserved marker is recoverable, it resolves to that recipient's distribution record.
A fingerprint per recipient
Every shared copy carries its own unique, invisible fingerprint embedded in the content itself, not a visible watermark anyone can crop out.
Built for real distribution paths
Digital markers are designed for common copy-paste paths. Enterprise print provenance supports print-to-scan review; aggressive whitespace normalization can remove the signal.
Know when protected content surfaces
Detection webhooks can report when a recoverable protected marker is found, so your team can investigate the matching distribution record.
No workflow change
Protection happens before you send, with nothing for recipients to install and no change to how you already distribute documents.
From leak to record
Evidence your team can investigate
Recover a marker from a protected fragment or eligible scan and resolve it to the matching recipient, session, and timestamp. Results and source conditions are logged for the investigation record.
Identity you control
Every paid plan includes a free CAWG identity certificate, pending enrollment and program approval. White-label identity, with a private key issued from the Encypher root CA, is available for teams that want tool identity plus organization identity.
Two layers, two jobs
Each protected copy combines a C2PA document manifest with an Encypher recipient marker. C2PA provides document-level provenance; the Encypher layer resolves the recipient's distribution record.
Audit trail for protection and trace operations
Protection and trace operations are logged and exportable for your own records and reviews.
Evidence export for review
Trace results export as evidence packages with timestamps and recipient mapping for an internal investigation.
Where this fits
Financial services · Legal · Media and entertainment · Government · Healthcare
For engineers
curl -X POST https://api.encypher.com/api/v1/sign \
-H "Authorization: Bearer $ENCYPHER_API_KEY" \
-H "Content-Type: application/json" \
-d '{"text": "Board memo draft.", "metadata": {"recipient": "j.doe@firm.com", "session": "q3-board-pack"}}'- A per-recipient Encypher marker on every protected copy
- Enterprise print provenance resolves through the matching distribution record
- Detection webhooks when a recoverable marker surfaces
- Evidence package export for investigations