Monitoring consoles, case managers, KYC screens
A session-specific signal over every protected page, tied to the identifier you pass at sign-in. Works on the internal tools you already run, with no agent to install on analyst machines.
For fintech, compliance and fraud teams
KYC records, transaction-monitoring alerts, SAR drafts and customer-risk screens are viewed by in-house analysts, outsourced teams and auditors. ExactMark marks each signed-in Web Session with a covert spatial signal, so a photographed monitor or exported screenshot can be traced to its most likely source, with the network context to go with it.
The problem
Compliance tooling is built around access control, and access control stops at the screen. An analyst's monitor is photographed on a phone. An outsourced team exports a case view to share for context. An auditor drops a screenshot of a customer-risk screen into a slide that leaves the building.
The access log shows forty people with permission to view that record. It does not show which one was looking at that screen when the picture was taken.
The answer
ExactMark renders a low-opacity, session-specific, redundant tiled signal over each protected page for each signed-in viewer. When a screenshot or photograph surfaces, Evidence Lab normalises it, searches across crop, scale, small rotation, colour, brightness and compression, correlates against candidate sessions and returns the most likely source with ranked candidates, or an inconclusive result.
Lighthouse adds the network picture for that session: VPN, proxy or Tor indicators, provider, coarse location and what changed since earlier sessions, without ever storing the raw IP.
How it works
Drop <script src="https://exactmark.com/script.js"> into the monitoring console and call exactmark.identify() with the analyst's pseudonymous ID. Marks are covert by default; visible and combined modes exist when you want the deterrent seen. The SDK never captures or records the page.
SAR drafts, case summaries and KYC packs exported as PDF go through Imprint: one file in, a recipient-linked copy out for each outsourced team, auditor or counterpart, up to 100 at a time by CSV. Content and text are preserved.
Upload the screenshot or photograph, or forward it to your Web App's private evidence email address. Cases keep workflow state, notes and the original asset, and export a branded PDF evidence report for the MLRO or investigations file.
Capabilities
A session-specific signal over every protected page, tied to the identifier you pass at sign-in. Works on the internal tools you already run, with no agent to install on analyst machines.
Optional per-session context for protected Web Sessions: VPN, proxy and Tor indicators, provider, coarse location and changes from earlier sessions. The raw IP address is never stored.
Normalisation, search across crop, continuous scale, small rotation, colour and compression, then correlation against candidates. The result is a most likely source with a confidence score and ranked candidates, or a clearly stated inconclusive.
Mark PDFs, PNGs, JPGs and WEBPs for each recipient before they leave the team. Each copy carries the spatial signal, signed non-identifying metadata and an opaque filename reference.
Forward suspicious screenshots straight to a Web App's private evidence address. Each case tracks workflow state and notes, retains the original asset and produces a downloadable branded PDF report.
Owner, Admin, Developer, Analyst and Viewer roles with per-Web-App access. Hosted in Dublin with Supabase in Ireland and application-level AES-256-GCM encryption of forensic data.
Questions
Straight answers. If yours is not here, ask us directly.
No. ExactMark is not DRM, screenshot prevention or spyware. It is attribution and deterrence: when a screen does leak, it tells you which session most likely produced it, with ranked candidates you can act on.
No. The SDK renders a signal over the page; it never captures or records the page content. The only files ExactMark ever receives are the evidence files your team chooses to submit.
Yes. Pass a pseudonymous identifier at sign-in and keep the mapping to a real person inside your own systems. Attribution results reference the identifier you supplied.
For protected sessions, Lighthouse records VPN, proxy and Tor indicators, the provider, a coarse location and whether these changed from earlier sessions. The raw IP address is never stored. Lighthouse is an optional service.
It returns an inconclusive result rather than a low-confidence guess presented as fact. For evidence that matters, Recovery+ provides a human-led investigation as an optional service.
Self-serve sign-up with USD plans via Stripe Checkout, plus a one-time testing plan for a controlled pilot on one internal tool.