The Journal
EngineeringJul 02, 2026 · 2 min read

Visible watermarks, and a licence number on every image

What we actually put on your images: a visible mark on the free plan, nothing on paid plans, and a commercial licence certificate number for every image. No invisible signal and no C2PA manifest — and why we would rather say so.

Teo Brandao

Teo Brandao

Infrastructure

Visible watermarks, and a licence number on every image

Provenance is easy to announce and hard to ship. So instead of announcing anything, here is exactly what happens to an image between the model and your Vault.

There are two things, and only two. On the free plan, every image gets a visible ockeeper mark. On every plan, every image that renders successfully gets a commercial licence certificate with its own number. That is the whole system.

Two plans, two outputs

Images made on the free Keyring plan carry a small, semi-transparent ockeeper mark in the bottom-right corner. Images made on Keeper, Vault or Keystone carry no mark at all. The mark is added after the model returns the image and before it is stored, so the copy in your Vault is the copy you download.

Both are licensed for commercial use. The watermark is about the plan, not the licence: a free image is yours to use commercially, mark and all.

A mark you can see is a mark anyone can check.

— provenance note

What the free mark is

Where — The bottom-right corner of the image.

What — The ockeeper padlock and wordmark in a semi-transparent capsule.

When — On every image made on the free plan, at render time.

Never — On any image made on a paid plan.

The licence certificate

Every image that renders successfully is issued a commercial licence certificate, numbered in the form OCK-2026-000123-4: the year, the render job, and the image's position in its batch. The number is shown on the image's render page in the studio, with the date it was issued.

It is a record, not a file — there is no PDF to download. If a client asks where an image came from, the certificate number is the thing to quote.

What we do not embed

We do not write a C2PA manifest, and we do not embed an invisible watermark. There is no hidden signal of ours in the pixels and no public verification API. If an image leaves your Vault and the visible mark is cropped out, nothing we added to the file says it came from ockeeper.

The third-party models we call may attach provenance data of their own to what they return. That is the model provider's choice, not ours, and we make no promise about whether it is there or whether it survives.

What that means for you

If you need clean images for client work, a paid plan gives you them. If you need to show where an image came from, keep its certificate number with the file. And if you share free-plan images, the mark goes with them.

1 — visible mark, on free-plan images only

0 — marks on paid-plan images

1 — licence certificate per image


Questions about licensing, or about a certificate number? Write to us — we respond within 1 business day.

FILED UNDER

  • Provenance
Teo Brandao

Teo Brandao

Looks after the render pipeline at ockeeper. Writes about waiting times, seeds, watermarks and which parts of a render we control and which we do not.