01
ASSESS
Score how audit-ready your rights declaration is against the public Compliance Framework — EU AI Act, GDPR, CCPA, COPPA, HIPAA, and four other categories. Returns specific gaps to remediate, not just a number.
Always free →For organisations that rely on content rights — and the ones that grant them
You signed the agreement. Now content is moving — into a model, into a campaign, into a publication that ships with your name on it. Can you show, per asset, that what you are doing with it was licensed for that use? If you are on the other side of the deal, it is the same question in reverse.
A Getty invoice proves you paid. It does not prove what you were allowed to do, or whether you still can.
For content platforms: your catalogue is full of creator-uploaded terms that are silent on AI training. When a creator sues, all you have is T&Cs never built for AI.
EU AI Act: your agreements were drafted before the use existed. “All media now known or hereafter devised.” Dispute the scope and you hold a PDF and a spreadsheet.
For AI labs: you're ingesting at scale under the EU AI Act, state provenance laws, and litigation. You need to verify rights programmatically, across millions of inputs. Bilateral deals don't scale.
It is the Verifiable Credential piece (the receipt) that every other layer leaves out and that is your exposure — and it isn't only about AI training. Any time content is licensed and someone later has to prove what was permitted, the receipt is the proof.
All digital content — articles, artwork, music, photographs and more — carries rights governing how it may be used. Our Assess tool identifies the rights currently available to you, our Verifiable Credential binds those rights to the content file, and our License creates machine-readable Proof of Use that can be presented to regulators, counterparties or in the event of a dispute. Our Audit Services provides continuous oversight of all your content.
01
ASSESS
Score how audit-ready your rights declaration is against the public Compliance Framework — EU AI Act, GDPR, CCPA, COPPA, HIPAA, and four other categories. Returns specific gaps to remediate, not just a number.
Always free →02
Verifiable Credential
(content rights record)
Issue your content's rights as a machine-readable, revocable record — after ASSESS shows the declaration is audit-ready (Step 01).
See pricing →03
LICENSE
Upgrade your credentials to a verifiable license cosigned by LicenseFoundry. Production houses, AI labs — practically anyone — can verify the rights to your assets with our free verification SDK.
Ed25519-signed via did:web:licensefoundry.com ·
production verifiers reject sandbox credentials by construction
04
Audit Services
We're not an AI lab. We're not a content platform. We're the third party that signs what issuers grant and that labs verify — with no business that competes with either side. That's the structural difference between us and self-signed credentials, coalition-controlled trust lists, or lab-built verification stacks.
A LicenseFoundry credential is a signed, machine-readable record of the rights granted on a piece of content. Anyone — a person or an AI system — can verify it against the issuer's did:web key, with no account, no API key and no permission from us. The keys are published and any party can mirror them; once cached, the check runs offline.
Yes. Each license is a W3C Verifiable Credential, cryptographically signed with Ed25519 by the rights-holder's platform. The signature proves who issued it and that nothing in it has been altered.
That's one of the asks in the Leiden Declaration on AI and Mathematics — backed in June 2026 by the International Mathematical Union, the global body for mathematics. A LicenseFoundry credential turns that reservation into a signed, verifiable record: your work is licensed so it can't be used for AI training without the author's consent, and the terms are provable later.
Yes. Rights are declared per use — training, RAG, embedding, display, derivatives — each with its own scope, such as territory and duration. The credential records exactly what was granted, not a single vague 'licensed' flag.
Yes. Revocation flips a bit in a public Bitstring Status List v1.0, and every verifier sees the change within its cache window. A paid invoice cannot be un-paid — a license can be revoked, and a lab can check its status at the moment of use.
Yes. Every credential is independently verifiable after the fact — offline, by any third party, using open-source SDKs — so a licensing position can be reconstructed and checked without trusting LicenseFoundry's systems or word.
Yes. Where content carries a LicenseFoundry credential, you can verify the exact rights and scope you've been granted — including whether AI adaptation is permitted — offline, in your browser, with no account. It's the free verification tool below, and the same open SDK lets a brand or agency check rights automatically at scale.
The core idea
Content Credentials (C2PA) answer what this file is and where it came from — origin, edit history, who signed off. They can carry a rightsholder's reservation (“not for training”), but a reservation is a one-sided declaration, not a grant. C2PA cannot express that a named party was granted a defined right on defined terms, nor prove the grantor had standing to grant it.
Verifiable Credentials answer what you are permitted to do — a signed, portable record of the rights granted: grantor, grantee, scope, term, and current standing. The signature verifies offline; standing verifies against a status list any party can mirror. An AI lab, an auditor, or a court can check both without depending on us being available, cooperative, or still in business in 2030.
That verifiable rights record is the piece every other layer leaves out — and it isn't only about AI training. Any time content is licensed and someone later has to prove what was permitted, the receipt is the proof. ASSESS → VERIFIABLE CREDENTIAL → LICENSE → AUDIT is how you create it and stand behind it.
How a credential is created — and who does what
What one credential records (per asset)
Per-right scope is the differentiator — one signed record per asset, revocable, verifiable offline.
Today's AI license is a rental agreement in a drawer. Ours is the notarised lease — same contract, self-proving form, and it always knows whether it's still in force.
Your rights aren't a label on a file. They're a record: which uses you've granted on a piece of content, at what scope — and whether that still holds. A plain file can't carry that, and a PDF in a vendor's database can't be verified without the vendor.
So we issue a receipt — a signed, portable record of the rights granted on the content (what's allowed, the scope, and whether it's still valid) that an AI lab, an auditor, or a court can verify on their own, years later — without trusting us, and without needing our permission. The keys are published; any party can mirror them. The file just points to it.
Where we live: we co-sign the rights record and publish the keys + revocation list everyone checks against (did:web:licensefoundry.com) — deliberately out of the negotiation, the payment, and the content path. That separation is what makes the attestation neutral. Change the rights or withdraw them, and the revocation is public and immediate.
Every piece of content answers to AI now — check what yours says. Most content is silent: it declares no rights at all. Silence isn't consent — but it isn't proof, either. Paste a URL or drop a file; we read the machine-readable rights and tell you plainly. Public signals only; a file is hashed in your browser and never uploaded. Not legal advice.
Whether you're an AI lab checking training data or a brand, agency, or design team clearing content for a campaign, verification is free and open. A real signed license, verified in your browser — Ed25519, no server, no login, no trust in us. Edit any character below and watch the signature fail. (Verifying your own issuer's credentials resolves their key via did:web — that's the open SDK.)
did:web and check revocation against a status list — both run in the open verifier SDK.W3C VC Data Model 2.0
Standardised credential envelope
JWT-VC compact JWS
Wire format every JWT verifier handles
Ed25519 / EdDSA
Modern asymmetric signatures
CoMP · RSL · SPUR
What their license pointers resolve to
Bitstring Status List v1.0
W3C revocation with offline cache
did:web
DNS-rooted trust anchor
Where the standards exist, we adopt them. Where they don't yet, our schema is designed to absorb the next version without breaking credentials we've already issued.
Independence isn't marketing — it's a structural property of who can credibly sign what. Self-signed credentials are an issuer's claim, not evidence. Coalition-controlled trust lists carry their members' biases. Robots.txt and C2PA address adjacent problems — opt-out and provenance — but not licensing. Bilateral lab-platform deals work for the giants and leave the mid-market exposed. A third-party signature from an entity with no business in either direction is the baseline this market is structurally missing.
Neutral signing
Issuers can't sign their own credentials and call them verifiable — self-attestation is the model labs already reject. We sign for them, with our key, under our DID. The credential carries weight precisely because we have no incentive to lie about what was granted.
No conflict of interest
We're not in either side's business. We have no incentive to declare more content trainable than it is, or fewer credentials valid than they are. Our only product is keeping the trust layer working for both sides — which fails the moment we tilt towards either one.
Audit-grade attestation
Regulators and external counsel give more weight to independent third-party attestation than to self-signed documents. A compliance report citing our DID is structurally more defensible than the same artefact a customer produced about itself.
Reviews are priced in euro: Exposure Scan €2,500, full Review €15,000, Portfolio Review €30,000. See the review ladder →
Platform issuance is priced separately in US dollars, from $0.027 per credential, with subscription bundles and audit tiers. See platform pricing →
Open-source datasets are the supply that makes AI training defensible. We treat them as critical infrastructure, not a paying customer segment. Verifiable Credential issuance is free, unlimited, for any OSI-licensed asset — automatically, at issuance time. (ASSESS scoring is free for everyone; OSS gets the Verifiable Credential tier free on top.)
What's free for everyone: ASSESS (score any asset, unlimited, no auth required).
What's free for OSI-licensed assets: Verifiable Credential (issue rights manifests for OSI-licensed assets, unlimited). Eligibility is automatic — we parse the LICENSE file at issuance. OSI-recognised licenses (MIT, Apache-2.0, BSD, CC0, CC-BY, CC-BY-SA, GPL family, LGPL, MPL, and the full OSI list) qualify.
What's not free: LICENSE (third-party attestation) and AUDIT (continuous oversight for labs) remain standard-priced for everyone, including OSS use cases. A commercial lab auditing its OSS ingestion is paying us for our oversight, not for the OSS use itself.
The OSS bot. We also run the LicenseFoundry
OSS sidecar bot — it proactively credentials known OSS
datasets on HuggingFace, GitHub, and Kaggle, adding a
.licensefoundry/manifest.yaml to your repo
via a single PR. One PR per repo per lifetime; no nag,
no signup. Adds your dataset to
catalog.licensefoundry.com when published.
OSS terms
Free/unlimited
Disclaimer. The bot's rights translation is
one reasonable interpretation of each license — not legal
advice. You review the PR before merging and edit anything
that doesn't match your intent. The bot opens at most one PR
per repo, ever. Close it without merging and the bot will
never approach that repo again. Add a comment containing
licensefoundry-no-thanks to a closed PR and we
won't approach any of your repos again.
A credible AI license needs three things: a structured rights claim from the content owner, a cryptographic signature from a neutral third party, and a verification path every AI lab already uses. We provide the signature and the verification path. Whether you're the one issuing rights or the one ingesting them, the conversation starts the same way.
For content owners
Most conversations start with an exposure review of the arrangements you already have — what you granted, to whom, over which assets, and whether you could evidence it. We onboard issuers in cohorts and stay hands-on through go-live.
For AI labs
Verification is free — install the SDK and verify credentials offline in milliseconds. Audited Provenance and bundle subscriptions activate when you need documented oversight of your training-corpus rights, not before.
Self-signed credentials are self-attestation. The cryptographic separation between the party making the rights claim and the party signing it is the whole point — and the structural reason this trust layer can only ever be one layer.