Rights-as-a-service · in private beta
The rights layer every UGC stack is missing.
Most teams pirate-rip UGC. We're building rights-clearance + an audit trail as a standalone API for ad networks, DSPs, agencies and every brand using UGC anywhere on the internet. In private beta, onboarding design partners now — pricing isn't set.
Rights-as-a-service
Public-comment + consent-form request flow
Public-comment + consent-form
Public-platform-comment request
Audit trail
Full request/approve/reject
Compliance-aligned, not compliance-automated
GDPR +
- Private betaOnboarding design partners now
- 2Request channels live: platform comment + consent form
- 3Compliance regimes we align to: GDPR, CCPA, DSA
- In buildExternal, authenticated API access
- 01
Public-comment + consent-form request flow
We ask for rights the way the platforms actually allow it today: a public comment on the original post, plus a public consent form the creator can fill in. No DM automation exists — we’re not claiming it does.
- Public-platform-comment request
- Public consent-form capture
- Manual admin review for edge cases
- 02
Audit trail
Every request, approval and rejection is logged today. Cryptographic tamper-evidence (hash-chaining) is the beta’s build target, not shipped — the trail isn’t signed yet.
- Full request/approve/reject history, live today
- Tamper-evident hash-chain: build target, not shipped
- Export formats: still being designed
- 03
Compliance-aligned, not compliance-automated
Our audit trail is built around GDPR, CCPA and DSA recordkeeping expectations. We don’t yet offer pre-filled regional legal templates or an automated right-to-be-forgotten SLA — that’s roadmap, not shipped.
- GDPR + CCPA + DSA-aligned event logging
- Region-specific legal templates: not built
- Automated takedown SLA: not built
- 04
External, authenticated API access
The beta’s actual build: a real external API key with real enforcement, so partners outside Idukki can call the clearance and audit-trail endpoints directly. The key schema exists internally today; enforcing it externally is what design partners are helping us finish.
- Per-partner API keys
- Real request authentication — in active build
- Read access to clearance status + audit history
- 05
Notifications: roadmap, not shipped
Outbound webhooks (rights.granted, rights.revoked, rights.expired) don’t exist — there’s no webhook delivery infrastructure in the platform today, for any domain. Poll the audit endpoint for now.
- No webhook infrastructure today
- Poll-based status checks work today
- Webhook events: roadmap
- 06
Human review, not just automation
The comment + consent-form flow doesn’t catch every case — disputed ownership, non-responsive creators. Those go to the same manual review queue Idukki’s own dashboard uses internally.
- Manual review queue for edge cases
- Same reviewers as Idukki’s internal UGC ops
- No fully automated fallback yet — by design
- Research
- Building
- Beta
- Live
Get a sandbox key as a design partner
Private beta is onboarding ad networks, DSPs, agencies and platform teams that move UGC at scale, to build the external API surface with real partners instead of in a vacuum. Tell us what you need — it shapes the build order.
- Direct input into the API contract
- Early access once external auth ships
- No pricing commitment yet — pricing isn’t set
We read every message and reply by email. If it fits, we suggest a call.