Siberson
Partnership Contact Request a Demo
Data Classification

Siberson Veriket Dynamic Screen Watermark: Don't Let On-Screen Data Stay Anonymous

Jul 23, 2026 · 15 min read
Back to all articles
S
Siberson Team
Jul 23, 2026 · 15 min read

Enterprise security tools can control digital channels — email, USB, web uploads, cloud storage and file transfer. But when sensitive information appears on screen, a user photographing the monitor with a personal phone, or capturing the image another way, remains a serious risk.

Siberson Veriket Data Classification's dynamic screen watermark can display, on the user's screen, information such as the username, domain, IP address, computer or device name, a hashed user identity, the date and time, and organization-specific fixed or dynamic text.

The screen watermark can run in two operating modes: it can stay on continuously through the user's session, or it can appear only while a defined Windows application, process or service is running — for example only while Microsoft Excel, a PDF viewer, a custom line-of-business app or a specific Windows process is active.

The goal is not to physically block every possible on-screen leak, but to raise user awareness, deterrence, accountability and post-incident traceability.

Sensitive application windowUSER01 · FIN-PC-09 · 10.10.20.41 · 23.07 14:40USER HASH: 8F3A9C21 · 23.07 14:40Dynamic overlay: user · domain · IP · device · time · hashed ID
Figure 2: A dynamic watermark ties the on-screen view to a user, device, IP, time and hashed identity.

The last visible point of data security: the user's screen

Organizations use many layers of control to protect data. Files are encrypted, email attachments are analyzed, USB devices are restricted, cloud storage is controlled, and DLP policies stop sensitive files from leaving the organization. Yet one area is often overlooked in the data lifecycle: the user's screen.

For an employee to read a sensitive report, customer record or technical document, the information inevitably becomes readable on screen. At exactly that point data crosses from the digital security boundary into the realm of physical observation. A user can take a screenshot, photograph the monitor with a personal phone, share the wrong screen in an online meeting, show the screen to an unauthorized person, or leave sensitive data visible in a remote-work setting.

In these scenarios the file may never be sent out digitally. No USB is connected, nothing is emailed to a personal account, nothing is uploaded to cloud storage — yet the information on the screen may still have left the organization's control. This risk is critical in banks and financial institutions, defense and aerospace projects, public agencies, telecoms, healthcare, R&D centers, software teams, and call-center and customer-service operations.

The Siberson Veriket dynamic screen watermark adds a security layer that provides deterrence and traceability at this final point — where data is displayed on the user's screen.

What is screen watermarking?

A screen watermark is a visual security mark shown over the user's desktop or application screen. It does not have to be a static company logo or a "Confidential" label. Siberson Veriket supports generating the watermark dynamically from user, device and session context. The watermark can include the Windows username, domain username, hashed username, IP address, domain, computer or device name, date and time, organization-defined fixed messages, and organization-specific dynamic identity values.

For example, the user's screen might show:

USER01 — COMPANY.LOCAL — 192.168.10.42 — 23.07.2026 14:40

A domain-format identity can also be used:

COMPANY\USER01 — DEVICE: OPS-PC-104 — 23.07.2026 14:40

When the organization prefers not to show the username directly, a hashed identity value can be used:

USER HASH: 8F3A9C21 — DEVICE: FIN-PC-01 — 23.07.2026 14:40

With this approach, when a screen photo or screenshot leaves the organization, the dynamic values on the image can give an investigation meaningful context. The point of the watermark is not just to place text over an image — it is to tell the user: this screen is tied to a specific user, device and session; the image is not anonymous.

Veriket's screen watermark is not content-based

It is important to position how Veriket's screen watermark works. It is not a content-based control that activates by analyzing the displayed document. In other words, it does not open automatically by reading personal data inside a document, detecting keywords or regular expressions, analyzing the file's classification label, or interpreting the sensitivity of the displayed content. Instead, the watermark is managed through two operating models.

Mode 1 · Always-onShown for the whole sessionDesktop · every corporate appHigh-security terminalsCall centres · SOC · defenseMode 2 · App / process / serviceShown only while a trigger runsEXCEL.EXE · WINWORD.EXEPDF viewer · ERP clientCustom Windows process / service
Figure 1: Two operating modes — always-on for the whole session, or shown only while a defined Windows app, process or service runs.

1. Always-on screen watermark

The watermark is shown continuously throughout the user's Windows session or working environment.

2. Application, process or service based watermark

The watermark is shown only while a defined application, process or Windows service is running. This distinction is critical to positioning the solution technically: the core value of the screen watermark comes not from analyzing content, but from associating the viewing environment with a specific user, device or session.

Mode one: always-on dynamic watermark

In the always-on model the screen watermark stays visible on the desktop throughout the user's session. It suits environments where most of what appears on screen is sensitive — for example bank operations centers, call centers, defense project work areas, SOC and NOC screens, closed government networks, healthcare record terminals and outsourced operations centers.

How the always-on model works

When the user logs into Windows, the Veriket screen watermark activates. It can be displayed on the desktop, over corporate applications, in office apps, in browser windows and in custom line-of-business apps. What is shown is set through central policy. Example format:

COMPANY INTERNAL · USER: USER01 · IP: 10.10.10.15 · 23.07.2026 14:43

Instead of showing the username directly, a hashed identity can be used:

SESSION: 7C6F2A91D4 · DEVICE: OPS-PC-104 · 23.07.2026 14:43

Advantages of the always-on model

Here the watermark does not need to wait for a particular application to run; all corporate information on the user's screen is marked with the same visible security layer. It can cover desktop applications, browser-based systems, custom corporate software, remote desktop sessions and different file types under one operating model. This makes it a more comprehensive approach where the application inventory is very broad or where it cannot be predicted in advance which application will display sensitive information.

Which organizations is it suited to?

This model is worth considering when most users work with sensitive data continuously, the environment is high-security, the organization uses outsourced staff, per-application policy is not desired, screenshots are expected to be attributable, or physical and screen-photo risk is high. The impact on user experience should also be weighed: the watermark's density, transparency, size and placement must not needlessly obscure day-to-day work screens.

Mode two: application, process or service based watermark

Not every organization wants the watermark always on. In some units only certain applications hold sensitive data, and users spend the rest of the day in general office apps or low-risk systems. In that case the Veriket watermark can be shown based on a specific application, process or Windows service — for example only while Microsoft Excel is open, a PDF viewer is running, Microsoft Word is in use, a specific browser is open, the organization's ERP client is running, a financial-reporting app is active, a custom customer application is in use, or a selected Windows process or service is running.

How the application-based approach works

The organization first identifies the applications, executables, processes or services that trigger the watermark — for example EXCEL.EXE, WINWORD.EXE, ACRORD32.EXE, a custom application's executable, a defined Windows service, or a specific desktop client. When the defined process or service starts, the watermark becomes visible; when it closes, the watermark can be removed. This lets the organization associate the watermark only with the defined high-risk applications instead of keeping it on across the entire environment.

Advantages of the application-based approach

This model gives a more selective balance between security requirements and user experience. The user sees the watermark only while working in applications that handle sensitive information. A finance employee might not see the watermark in email, calendar, general web use or corporate messaging — but the watermark appears when Excel opens. Likewise, a legal user might see the watermark only while a PDF viewer or document-management system is running. The key point: the watermark activates based on the defined application or process running, not on the content of the opened file. Opening a blank workbook and opening a financial report in Excel are identical for triggering — if the policy is bound to the Excel process, the watermark shows while Excel runs.

Applicable to any Windows process or service

The Veriket screen watermark is not limited to Microsoft Office. A custom application running on Windows, a third-party client, or a specific process or service can be brought into the watermark policy. This is strategically valuable for organizations that use bespoke line-of-business software — for example a bank operations app, a hospital information system, call-center software, a defense project client, a laboratory application, an ERP client, a customer-data viewer, a financial transaction terminal or a technical-design application — regardless of standard file formats. The solution adapts not only to general apps like Excel, Word or PDF, but also to the organization's critical business processes and custom software architecture.

Why application-based watermarking matters

Corporate data is not always viewed as a file. A customer record may sit in a web-based CRM screen; patient information may be pulled to screen from a healthcare app's database; a bank customer's financial details may be shown inside an operations app; a defense project's technical parameters may live in custom desktop software; a call-center agent may see customer data through a dedicated client. In these scenarios the user may not be opening a Word, Excel or PDF file at all — the information is displayed directly in the business application's interface. A security approach focused only on file extensions may not cover these application screens well.

Veriket's application-, process- and service-based watermarking extends protection beyond file types. The control focuses on the question:

Through which application or system is the user accessing sensitive information?

So organizations can design screen-watermark policy not just around file types, but around business processes, user roles and the applications in use.

What information can the dynamic watermark use?

For a watermark to deter, the displayed information must be attributable to a user, device or session.

Username

The watermark can show the username of the person in the Windows session (e.g. USER: USER01). This is direct, high-visibility deterrence — but when the photo is shared, the identity is also plainly visible.

Domain username

User information can be shown in corporate domain format (e.g. USER: COMPANY\USER01), useful where multiple domains or organizational structures exist.

Domain

The user's corporate domain can be a separate field (e.g. DOMAIN: COMPANY.LOCAL), helping show which organization the screen relates to across subsidiaries, operations or networks.

IP address

The client's IP address can be shown (e.g. IP: 10.20.14.84), helping correlate device, user and network records during an investigation.

Computer or device name

The corporate device name can be used (e.g. DEVICE: FIN-PC-221), helping identify which device the screenshot relates to.

Date and time

Dynamic time is one of the watermark's critical components (e.g. 23.07.2026 — 15:05:42). The time on the photo can be compared with session records, application access logs, Active Directory events, SIEM records and physical-access logs.

Hashed username

An organization may not want to show the real name or username on screen. The username can be hashed into a value that looks anonymous but is matchable by the organization (e.g. USER HASH: 9F21C8A4D7). This balances two needs: associating the screenshot with a specific user or session, and avoiding showing personal identity openly. The hash approach is worth considering for employee privacy, external meetings and screen sharing.

Static vs dynamic watermark

A static watermark shows the same text to all users — for example CONFIDENTIAL. That can remind people the data or environment is sensitive, but it does not help identify which user, device or session an image came from. A dynamic watermark adds user and session information — for example CONFIDENTIAL · USER HASH: A41F92D8 · DEVICE: HR-PC-17 · 23.07.2026 15:12.

CapabilityStatic watermarkDynamic watermark
Sensitivity awarenessYesYes
Attribution to a userLimitedSupported
Device informationUsually noneCan be added
IP informationUsually noneCan be added
Date and timeFixed or noneCan be dynamic
Contribution to investigationLimitedStronger
DeterrenceMediumHigher

Veriket's differentiator is being able to use the watermark not just as a visual warning but as a dynamic user and session identity.

Does the watermark fully prevent leaks?

The screen watermark is not a control that technically blocks all screen-based leaks. It does not physically disable a phone camera, cannot absolutely prevent someone else from seeing the screen, and does not stop an authorized user from manually transferring on-screen information elsewhere. So it does not replace controls such as DLP, access control, authentication, privileged access management, encryption, physical security, SIEM or user-behavior analytics. Its security value shows up in three areas.

Deterrence

When a user sees information tied to their own session, device or hashed identity on screen, they know a photo or screenshot will not stay anonymous. That awareness can help reduce opportunistic, unplanned breaches.

Traceability

Having user, device, IP or time data on a screenshot provides a starting point for an investigation.

Security awareness

The watermark continuously — or per application — reminds the employee that the system they use is corporate, controlled and traceable. So the watermark is less an absolute blocking mechanism and more a deterrent, visibility-providing, associating, awareness-raising control layer.

How DLP and screen watermarking work together

DLP and screen watermarking focus on different risk areas. DLP generally controls digital movements — email, web upload, USB copy, cloud app use, printing, clipboard operations and network transfer. The screen watermark instead deters the risk of a user exfiltrating data via photo or screenshot while information is on screen.

For example, Verikor DLP can block an Excel file from being emailed to a personal address; the Veriket screen watermark can mark the screen with the user's name, IP, device or hashed identity while the Excel app is open. Together they form a model where the digital transfer of sensitive data is controlled by DLP; the screen is dynamically marked while a critical app runs; the user sees the screen photo can be tied to their session; and if an incident occurs, the watermark information is compared with other security logs. This extends data security from file movement to screen visibility.

DLP · digital channelsEmail · USB · Web uploadCloud apps · Print · ClipboardControls how data is transferredScreen watermark · view layerPhoto of screen · screenshotScreen share · shoulder surfingDeters & attributes the viewTwo complementary layers — from data movement to data on display
Figure 3: DLP controls how data moves; the screen watermark covers the moment data is on display. They are complementary layers.

Use cases across environments

1. Financial reports in Excel

Finance teams handle budget, payroll, collections, pricing and cash-flow data in Excel. The organization can apply: no watermark while the user works on a normal desktop; a dynamic watermark activates when EXCEL.EXE starts; the watermark shows username, device, IP and time; and it is removed when Excel closes — e.g. FINANCIAL SESSION · USER: FINUSER01 · DEVICE: FIN-PC-09 · IP: 10.10.20.41 · 23.07.2026 15:24. The watermark does not analyze the file's content; it activates because Excel is open. Whether the file is a budget, a customer list or a blank workbook does not change the trigger.

2. Corporate documents in a PDF viewer

In legal, defense, finance and public organizations, sensitive documents are often distributed as PDFs. The Veriket watermark can be shown only while the organization's PDF viewer runs — for example Acrobat Reader, a custom PDF client or a third-party document viewer — e.g. DOCUMENT VIEWER · USER HASH: F17D8A92 · DEVICE: LEGAL-PC-14 · 23.07.2026 15:30. The watermark runs based on the PDF viewer process being active, not on the document's classification label or content.

3. A custom banking application

A bank operations employee may view customer information in a custom desktop application — not Excel, Word or PDF. Veriket can trigger the watermark via that app's Windows process or service: when BANKOPERATIONS.EXE runs the watermark appears, and it is removed when the user exits — e.g. SECURE OPERATIONS · USER: OPSUSER01 · DEVICE: BANK-PC-117 · 23.07.2026 15:35. This is valuable for non-file-based corporate systems: even when sensitive data lives in a database and is only shown in the app interface, there is a screen mark attributable to the user.

4. Call-center operations

Call-center staff may view customer name, phone, address, account, contract and transaction history on screen. They may not need to exfiltrate this as a file — a phone photo is enough. The organization can apply either an always-on model (watermark always visible on call-center terminals) or an application-based model (watermark visible only while the CRM or customer operations app is open). A staff hash can be used instead of a real username — e.g. CUSTOMER OPERATIONS · USER HASH: C71B9A22 · DEVICE: CALL-PC-042 · 23.07.2026 15:38. This adds deterrence in high-turnover outsourced and call-center operations.

5. Defense and R&D applications

Defense, aerospace and R&D teams work with technical drawings, source code, project plans, system architectures, product designs and test data — often not in standard file apps, but in CAD software, a code IDE, a lab application or a custom project client. The Veriket watermark can bind to those processes and show only while they run — e.g. PROJECT ENVIRONMENT · USER HASH: A8D1742E · DEVICE: RND-WS-44 · 23.07.2026 15:42. A screen photo then carries the user and device context along with the project information.

6. Healthcare information systems

In healthcare, patient information is usually viewed through a dedicated hospital information system and can include patient ID, diagnosis, lab results, treatment history, imaging reports and prescriptions. The Veriket watermark can be enabled while the relevant health application's process or service runs — e.g. CLINICAL SESSION · USER HASH: B52E91C4 · DEVICE: CLINIC-PC-18 · 23.07.2026 15:48, helping tie screens that display health data to specific user and device sessions.

Always-on or application-based?

Which model to use should be decided by the risk profile, working environment and user-experience goals.

ConsiderationAlways-onApplication / process / service based
CoverageWhole working screenDefined applications
Ease of managementSimplerNeeds an app inventory
User experienceMore visibleMore selective
Covering custom appsAutomaticallyDefine the process or service
Isolating critical appsLimitedStrong
New-application riskNo extra definitionMay need a policy update
Best environmentHigh-security terminalsMixed-use environments

Some organizations use a hybrid model — for example always-on for outsourced users, app-based for internal staff, always-on on call-center terminals, only-while-Excel-or-ERP for finance users, and always-on on a defense project network.

Designing an effective screen-watermark policy

1. Identify the business processes to protect

First determine where screen-photo risk is high — for example customer-data viewing, financial reporting, personnel data, technical design, health-record viewing, board documents, source-code development and call-center operations.

2. Choose the always-on or application-based model

The same model need not apply to every user group; critical terminals can be always-on, while general office users get an application-based policy.

3. Build an application and process inventory

For application-based use, define the application name, executable name, Windows process, related service, application owner, user group and business risk.

4. Decide what the watermark shows

Weigh each field for security value and employee privacy. Example policy: username hashed; device name shown; IP shown; domain shown; date and time shown; corporate message CONFIDENTIAL SESSION — producing e.g. CONFIDENTIAL SESSION · USER HASH: D42F18A9 · DEVICE: SEC-PC-105 · IP: 10.21.5.18 · 23.07.2026 16:00.

5. Optimize the visual design

The watermark must be visible but not block the user's work. Consider transparency, font size, repetition, angle, position, contrast, multi-monitor behavior and different resolutions.

6. Run a pilot

Start with a limited user and application group — for example 10 finance users, only the Excel process, user hash + device + time, over a 30-day evaluation.

7. Inform users

The watermark should not be positioned as covert surveillance. Users should be told clearly why it is applied, when it is active, what information is shown, and how it may be used in investigations.

8. Keep the application scope up to date

As new corporate applications go live, review the process- and service-based scope; otherwise the organization can protect old apps while leaving visibility gaps in new systems.

Balancing security and employee privacy

Showing username, IP, domain and device on screen should be evaluated for employee privacy and personal-data handling. Information security, legal, HR, KVKK/data protection and employee-relations teams should shape the policy together. The hashed username offers an alternative: instead of the real username, show an organization-specific matchable hash, so the screenshot that leaves does not plainly reveal the employee's name, while the authorized security team can still correlate the hash with system records. This is more balanced for screen-shared meetings, customer sites, remote-support sessions and settings where external users may see the screen.

Using the watermark in an investigation

When a screen photo is found online, on social media, in a messaging app or in a third party's system, the watermark values give a starting point. For example the image might carry USER HASH: 7A19D4F2 · DEVICE: OPS-PC-117 · IP: 10.40.5.21 · 23.07.2026 16:03. The security team can compare these with session records, Active Directory logs, device inventory, DHCP records, application access logs, DLP events, SIEM records and physical entry logs.

Screenshot foundHASH: 7A19D4F2OPS-PC-117 · 16:03AD / session logsDHCP · device inventoryApp access logsSIEM · DLP · door recordsInvestigationcontext, not sole proof
Figure 4: In an investigation, watermark values give a starting context to correlate with logs — not standalone proof.

However, a watermark should not be treated as conclusive proof of a breach on its own. An image may have been re-shared, photographed by another user, captured during screen sharing, or physically taken by an unauthorized person. The watermark provides strong context for an investigation; the final assessment should be made together with other technical and operational evidence.

Business value for organizations

Deterrence against insider risk

Seeing information tied to their own session on screen reduces a user's sense of anonymity.

Attribution on screenshots

Dynamic information in a photo or screenshot helps narrow down the likely source.

Coverage of custom applications

Control is not limited to Word, Excel or PDF; the organization's own applications, processes and services can be covered.

Flexible user experience

The organization can choose always-on or application-based operation, or build a hybrid.

Complementing DLP investments

While DLP controls digital transfer channels, the screen watermark adds deterrence at the display layer.

Raising security awareness

The watermark reminds the user the working environment is corporate and traceable.

Reducing remote-work risk

A visible security policy can be applied on devices used outside the corporate office too.

Application-focused governance

Organizations can build watermark policy around real business applications and operational risk areas instead of file extensions.

Common positioning mistakes

Saying "it analyzes content and opens on sensitive data"

Veriket's screen watermark is not triggered by content analysis. It can be always-on, or activate while defined applications, processes and services run.

Saying "it fully prevents screenshots"

The watermark mainly provides deterrence and traceability. It does not absolutely block a physical camera or every screen-capture method.

Saying "it only works on Office files"

A defined Windows application, process or service can be covered — including custom corporate applications.

Saying "it only shows the username"

Different dynamic values can be used: IP address, domain, device name, date-time and a hashed user identity.

Confusing document watermarking with screen watermarking

A document watermark is applied inside the file or page. A screen watermark works on the viewing environment and can be shown continuously or per application, independent of the file.

Conclusion: mark the viewing session, not just the data

Modern data security is not limited to controlling whether files are copied or sent. A different risk emerges the moment sensitive information is displayed on the user's screen: a phone camera can capture on-screen information without using email security, USB controls, cloud access policies or file-transfer rules at all.

The Siberson Veriket dynamic screen watermark approaches this risk with two flexible operating models — always-on, where the screen is marked with dynamic information throughout the session; and application-, process- or service-based, where the watermark appears only while Excel, a PDF viewer, a custom business app or a defined Windows process or service runs. Values such as username, IP, domain, device name, date-time and a hashed identity tie the screen to a specific session.

This does not fully prevent a screen photo, but it shows the user the image is not anonymous, and it gives the security team investigation context when an incident occurs. Used together with DLP, access management, encryption and security monitoring, the Veriket screen watermark becomes a strong component of an insider-threat and screen-leak strategy — because protecting sensitive data does not end when the file is opened. When data reaches the screen, security must remain visible.

Frequently asked questions

Does the Veriket screen watermark work based on content?

No. It does not activate by analyzing document content or classification level. It can be always-on, or shown while a defined Windows application, process or service runs.

Can the screen watermark be used only in Excel or PDF?

No. Excel and PDF viewers are example scenarios. Any suitable Windows application, process or service can be included in the policy.

Can the watermark stay on continuously?

Yes. An always-on dynamic watermark can run throughout the user's Windows session or working time.

Can the watermark be removed when an application closes?

In the application-based model the watermark can be configured to show while the process or service runs and be removed when that scope ends.

What information can the watermark show?

Username, domain, IP address, computer name, date-time, hashed username and organization-specific text.

Why use a hashed username?

To associate the image with a specific user or session without showing the real username openly on screen.

Does the screen watermark prevent screenshots?

No. It does not block physical methods like a phone camera. Its purpose is deterrence, user awareness and post-incident traceability.

Does the screen watermark replace DLP?

No. DLP controls digital data movement. The screen watermark adds deterrence and attribution at the stage where data is displayed on screen.

Can it be used in custom corporate applications?

Yes. The application's Windows process or related service can be defined and brought into the watermark scope.

Does the watermark have to be the same for all users?

No. Dynamic values from user, device, domain, IP and session data can be shown per user or device.

Data ClassificationInsider RiskVeriket
Share

See how Siberson protects your data end to end.

Request a Demo