Straight‑Talk Q&A
Direct answers about what this does, what it does not, and what it is built to achieve
CerboTrace is in development and not yet open. The answers below describe the product and what it deliberately will not do. Where a figure only means something once measured, you get the target and the method behind it.
Is the watermark truly impossible to remove?
No, and nothing is. A determined person with the right tools can strip or destroy any digital watermark. This is exactly why the watermark is not the foundation of the product. The thing that dates your work is the signed, independently timestamped registration record, which lives in our registry and cannot be edited out of a file someone downloaded. The watermark is an extra tracer on top, scoped to survive casual redistribution.
Will CerboTrace find every stolen copy of my design?
No. Anyone who tells you otherwise is selling something. Two separate things have to go right: we have to find the listing at all, and we then have to recognise your design in it. Both will be measured and published separately, because a perfect matcher scores zero on a listing nobody ever fetched.
Discovery is planned through reverse-image search APIs and official platform APIs rather than keyword lists you maintain, and one candidate stream is matched against every registered design rather than per-customer keyword sweeps. Theft that never appears on a marketplace — a file passed around in a private Facebook group or a Telegram bundle dump — is not something any crawler reaches, which is why a public "report a stolen listing" page is part of the plan.
Do I still have to file DMCA notices myself?
Yes, always, by design. We generate the evidence pack and pre-fill the forms; you review and submit under your own name. We will not auto-file, at any tier, at any price. A takedown filed automatically on a model's output is a misrepresentation claim waiting to happen under 17 U.S.C. § 512(f), and the person holding that liability would be you. Confidence tiers plus your explicit confirmation are the firewall.
Will this stop people from buying my file and sharing it in Facebook groups?
No. Nothing stops that. If you use the full watermarking service, the intent is that a leaked copy carries an identifier tying it back to the transaction it came from — survival rates for that channel are published with the rest of the benchmark. Screenshots and screen recordings cannot be prevented by anyone.
Can CerboTrace scan the entire internet?
No. The focus is the marketplaces that actually cost you sales — Etsy first, then Creative Fabrica, Design Bundles, Amazon Merch and Pinterest as sources of infringing traffic. Whole-web crawling costs more than this market can pay. Covering the surfaces that matter properly beats claiming coverage of everything.
How often will you scan?
Weekly by default, with daily available as a paid option. The target is that you hear about an infringing listing within seven days of it going live — measured and reported, not assumed. Weekly works because infringing listings typically stay up considerably longer than that.
What's the false-positive rate?
The target is no more than one confirmed false accusation per 10,000 alerts. One wrongful notice against an innocent creator does permanent damage in a community this small, so that is the number the system is designed against, and results are published against a versioned benchmark.
That target drives the engineering. The benchmark deliberately includes hundreds of genuinely independent designs in the same genres, because in a market where every mandala resembles every other mandala, a matcher only ever tested against copies of itself tells you nothing about its error rate. Matches are graded Exact, Derived or Similar, only the first two are eligible for enforcement, and nothing generates paperwork until you press Confirm.
Could watermarking break my customers' files, for example laser-cut paths?
This is the failure we care about most: a protection tool that damages the thing it protects is worse than no tool. The acceptance bar is that a watermarked SVG renders pixel-identical at 300 DPI against the original and preserves path-length and bounding-box invariants — checked mechanically, not by eye. Round-tripping through LightBurn and Cricut Design Space is part of the test matrix, not something left to hope.
You also keep your original file. If a buyer ever reports a problem, you have a clean fallback that does not depend on us.
How much will it cost?
Pricing goes up before signups open. The tiers on the homepage show the shape of it — how many products each covers — and the free tier is genuinely usable, not a trial that expires under you.
A scan cycle has to cost pennies per creator, or indie pricing stops being viable. Fetching one candidate stream and matching it against the entire registry is what makes that arithmetic work — and it gets better as more creators join, rather than staying flat.
Why should I trust you over just checking manually every week?
Three reasons, none of them "our AI is advanced". A scheduled scan does not skip a week when you are busy. Fingerprints and timestamps recorded at registration are stronger than a screenshot taken after you noticed the problem. And a search built on image similarity can surface a listing that has been retitled in a language you do not speak, which keyword searching cannot.
If you already check reliably and your catalogue is small, manual checking is a legitimate choice.
Are you scraping Etsy in a way that could get my shop banned?
Your shop is never involved in a scan, so nothing we do can be attributed to it. More importantly, the architecture is deliberately built to avoid the hostile-collection question rather than to manage it.
Discovery runs primarily on paid reverse-image search APIs — products sold for exactly this purpose, where the constraint is our budget, not anyone's access rules — and on Etsy's official API within its published quota, governed by the rate-limit headers Etsy itself returns. Our red lines, published as policy: no residential proxies, no user-agent spoofing, no multi-key quota evasion, and no collection from surfaces that have said no. Every grey tactic has a legitimate alternative that merely costs money, and an IP-protection company caught running a scraper botnet would deserve the headline.
What if Etsy changes its page layout and your scraper breaks?
There is no scraper to break. Discovery runs on reverse-image APIs and official platform APIs — versioned contracts, not page markup we reverse-engineered. Avoiding exactly this fragility is much of the reason for choosing them.
Things will still break occasionally. When coverage is degraded you get told, rather than a quiet scan being handed to you as a clean result. Response-time commitments arrive with the service agreement at launch.
Will the watermark bloat my file size?
Small by design: the payload is a signed 64-bit identifier, not a second copy of anything. Per-format figures are reported alongside the rest of the benchmark.
Could a thief just re-save the file in Inkscape or Photoshop and strip the watermark?
A plain "Save As" strips file metadata, which is why metadata is only ever a secondary channel. The geometric and path-order channels are designed to survive ordinary editing, though a skilled person who knows what to look for can still defeat them.
This is the reason the registry, not the watermark, is the evidence. Stripping a watermark from a downloaded file does nothing to the signed record showing the design was registered months earlier.
Do you store my original designs? What if you get hacked?
Your original files are deleted after processing — we do not keep a library of your unwatermarked designs. Some things are retained, though, and it is worth being precise about which.
What is retained: fingerprints and embeddings, low-resolution normalised renders used for comparison, and evidence captures of infringing listings. The renders are derivatives for matching, not distributable copies of your product. The evidence captures are retained deliberately and immutably, because a dispute that surfaces two years later has to find the evidence bit-identical — that retention is the product.
A breach would therefore expose fingerprints, comparison renders and evidence of other people's infringement. It would not hand anyone a clean copy of your catalogue. If retaining renders is not acceptable to you, that is a fair reason to skip this service, and you should know it now rather than after signing up.
Is this GDPR compliant?
GDPR obligations are built in from the first migration rather than retrofitted: data export, deletion that honours the retention policy above, and a published subprocessor list. EU sellers are a large share of this market, which makes this cheap to do now and expensive to bolt on later. A data processing addendum ships with the service agreement.
If a competitor also uses CerboTrace, can they see my watermark or track my customers?
No. Each account sees only its own works and matches. Unless you display a badge, there is no way for anyone to tell you use CerboTrace at all. The identifier embedded in a delivered file carries no information about you or your buyer — it is an opaque reference that only means something inside our registry, so finding it tells an outsider nothing.
What happens if your costs spike?
If variable costs rise, scan cadence degrades in a documented and announced way before prices move — fewer scans at your existing rate, not a surprise invoice. Any pricing change is announced plainly and in advance, never applied quietly.
Could CerboTrace itself get cut off by a platform?
Yes, and the architecture assumes it. Losing official API access to one marketplace would reduce coverage there without stopping detection, because reverse-image discovery runs entirely independently of any single platform's permission, and confirmed cases let us sweep an infringing shop's whole catalogue from a single starting point. You would be told that coverage was reduced. Our posture toward platforms is cooperative — counterfeit listings are their compliance problem too.
Does watermarking visibly degrade image quality?
It is designed to sit below the visible threshold, and perceptual impact is measured on the same benchmark as everything else — on 300 dpi prints as well as screens, because a laser-cut sign and a phone thumbnail fail in different ways. Results are published with the rest of the numbers.
Can thieves reverse your algorithm to remove the identifier automatically?
The payload is verified against a key held server-side and differs per product, so a general-purpose removal tool has nothing fixed to target. We also will not expose raw similarity scores to non-owners, because a visible score lets someone perturb a design until it stops matching — that is a tuning signal, not a feature.
We assume adversaries adapt. The transformation benchmark grows over time and every successful evasion becomes a permanent test case. Obfuscation buys time; the signed registration record does not expire when the obfuscation does.
Bottom line: CerboTrace will not end piracy and will not do your legal work. The intent is to register and timestamp your work, watch the marketplaces that cost you money, recognise your design even after it has been rasterised and dropped onto someone else's mockup, and hand you an accurate evidence pack you choose whether to use. When it launches, the detection numbers are published so you can judge them yourself.