Loading the interactive demo for "Limits, evidence and what to do after a leak"… The lesson text below is already here. The hands-on part loads next (requires JavaScript).
No watermark survives everything. Screenshots, heavy crops, re-recorded photos of screens: all valid exits. This chapter is what still gives you options when tracing fails.
Work the checklist above in order. Preserve, compare, audit, then attribute. Accusations come last or not at all.
The order that preserves options
Freeze first: file plus URL plus time plus handle. Hashes make later copies comparable and takedown notices credible.
Compare before confronting: similarity tells you whether Inspect is worth the run. Metadata tells you about the file's journey. Neither names a human alone.
After the first hour
File takedowns with evidence attached. Fix the route that leaked: method, format, channel. Tell paying supporters what changed without accusing the innocent.
Then make the next drop the one that traces. That is the entire funnel from this course into protected delivery.
Takeaways
- Save the exact file, never a screenshot, and log URL plus time immediately.
- Similarity and metadata come before accusations; Inspect comes last.
- Without a delivery log even a perfect recovery names nobody.
Check yourself
Optional, local, instant. 0/2 answered.
- First thing after discovering a leak?
- In what order do compare, audit, and Inspect come?
For your niche
Client leaks are usually carelessness, not malice. Evidence-first response preserves the business relationship while you fix the route.
Leaks hit revenue within hours. Freeze evidence before takedowns, or the thread with the fingerprints vanishes with the post.
Repost culture blurs lines between theft and tribute. Timestamps plus delivery logs separate them cleanly.