AI video and 3D that stay on your hardware
Generate video and 3D models on hardware you own, with every result held for a person to approve.
Built for: A studio owner who makes product and brand video and cannot upload an unreleased client asset to somebody else's website · A game or app team that needs 3D models built from prepared reference images without shipping those images off-site · A marketing lead inside a regulated company, where sending anything to an outside model becomes a legal conversation · A product team that wants generation inside their own software and does not want to build the queueing, limits, and approval steps around it
The problem
ASL Media Worker exists because of this.
You need a short video of the product, or a 3D model of the part, and you need it this week. The tools that do this well all work the same way: you paste in a description, or you upload the photograph, and it goes to a company you have never met, to be processed on hardware you cannot see, under terms you skimmed once. If the thing in that photograph is an unreleased product, a client's artwork, or a person who did not agree to any of this, the upload is a decision you have already made and cannot take back. The second problem shows up after the file comes back. You cannot tell what made it. There is no record of which version of which engine produced it, no record of who looked at it, and no record of who decided it was fine to use. When somebody asks six months later whether that clip was reviewed before it went out, the honest answer is that nobody knows. And generated video fails in specific, embarrassing ways: a shot that never moves, a hand with the wrong number of fingers, a face that is almost but not quite somebody real. Nobody checked is not a small gap. The third problem is more boring and just as expensive. Generation is heavy work. One job starts, and the machine everyone else is using becomes unusable for twenty minutes. You find out because somebody walks over.
What changes
- The finished file stays on the machine you control. The path that hands it to you streams it through and keeps no copy of its own.
- Approval is on by default and enforced by the generation service, not by the application asking for the video. Removing it takes a deliberate change by whoever runs the installation; no request or user can bypass it.
- A reviewer can watch a held clip without releasing it, and that viewing is recorded. Most tools make you choose between seeing it and releasing it.
- The obviously broken results are discarded by machine first, so human review time goes to the judgment calls that need a person.
- The exact version of every generation engine is pinned and published with the result. A version that does not match stops the job instead of quietly producing something different.
- It gives way to the other work on your machine: one job at a time by default, and a refusal to start when memory is already spoken for.
- Your prompt never enters the audit trail, and neither does the name of the file you uploaded. What is recorded is what happened to the file, not what you asked for.
What it does
How ASL Media Worker works, start to finish.
ASL Media Worker generates video and 3D models on hardware you own, and the generated file never has to leave it. You send a written description and get back a short clip. You send one prepared image of a single object, with the background already removed or confirmed plain, and get back a standard 3D file you can open in any modeling or game tool. If you already have an animated 3D scene, it can render that scene out to video, and it can lay a timed sound mix over an approved clip. The way in is a thin relay: it authorizes the request, passes it through, and streams the result back without ever keeping a copy of its own. Everything it produces is held. A finished clip is not downloadable, not shareable, and not final until a person records an approve or reject decision against it. That hold is on by default, enforced by the generation service rather than by the application asking for the video, and nothing a request carries can switch it off; only whoever runs the installation can, deliberately, in its configuration. Because a reviewer obviously has to watch the thing before deciding, there is a separate viewing path that plays the exact held clip, writes down that it was viewed, and changes nothing about its status. Watching is not approving. The ordinary download stays closed the entire time and opens only once an approval exists, and a rejected result stays closed for good. Before any of that reaches a person, the result is checked by machine. Each clip is decoded again independently and screened for the failures that are obvious and measurable: the wrong number of frames, a picture that never changes, blown-out color, obvious noise. Those are thrown out automatically, so your review time goes to the judgment calls that actually need a person. Is this faithful to what was asked for? Is it in good taste? Is that a face you have the right to show? The screen was calibrated against real output from this hardware, and it is deliberately not permitted to decide anything about quality, whose face it is, or safety. Around the generation itself sits the plumbing you would otherwise have to build. Work is separated by workspace, so one team's jobs, uploads, and results are invisible to another and cannot be requested by name. Ceilings on jobs per day, jobs running at once, and total stored output are enforced when the job is created rather than discovered on a bill. A small fixed set of high-risk requests is refused at the door before any hardware is committed. Anything can be cancelled, and cancelling ends the process doing the work rather than leaving something running on your hardware. A machine that restarts in the middle of a job picks that work back up instead of losing it quietly. Old media expires on a schedule you set, and clearing starts in a report-only mode so you can read exactly what would be removed before anything is. The last piece is that the generation engine is a replaceable part. Video and 3D engines plug in behind one fixed contract, with their exact versions pinned and published alongside every result. That means two things for you. A version that does not match what was approved stops the job instead of quietly producing something different. And moving to faster hardware later does not change a single line of how your product asks for a video. It also means the service refuses rather than guesses: if the expected hardware, versions, or model files are not exactly what was recorded, or the machine is already busy with your other work, it says which condition failed and stops. Every engine also ships switched off, so an installation cannot start generating until somebody turns one on and that engine's own hardware and version checks pass.
Features
Everything in the current release.
Each of these is built and working today. Nothing on this list is a roadmap item.
Nothing goes out until a person says yes
Every finished clip and model is held the moment it is produced. It is not downloadable, not shareable, and not final until someone records an approve or reject decision against it. The hold is on by default and enforced by the generation service itself, so no request, user, or calling application can slip past it; the only way to remove it is a deliberate change by whoever runs the installation. A rejected result stays closed permanently.
Watch a held clip without releasing it
A reviewer has to see the video before deciding, which is a problem if seeing it means releasing it. There is a separate viewing path that plays the exact held clip, records that it was viewed, and changes nothing about its status. Watching is not approving. The ordinary download stays blocked the whole time and opens only after an approval is recorded. This path is for video: it accepts only a clip that is currently held, and it plays straight through rather than letting a reviewer scrub frame by frame.
Broken output is thrown out before it reaches you
Generated video fails in obvious ways: a shot that never moves, the wrong number of frames, blown-out color, visible noise. Each result is decoded again on its own and screened for exactly those faults, and anything that fails is rejected before it enters your review queue. The screen was calibrated against real output from this hardware, so one known-bad clip is rejected while two known-good clips pass. It never decides whether a clip is attractive, faithful, or safe. That stays with you.
Video from a written description
Type what you want and get a short clip back. The frame size, length, and frame rate are limited to what has actually been measured on the machine doing the work, so you get either a result or a clear refusal. On the current hardware the measured envelope is one or two seconds at a small square frame size, at eight frames a second. This engine is built and has produced verified output on the workstation's own graphics card; it ships switched off until a person accepts its quality and output safety.
A 3D model from one prepared image
Hand it a single image of one object with the background already removed, or confirm the object is centered on a plain background, and get back a standard 3D file that opens in any modeling or game tool. Background removal is deliberately not automatic, so an ordinary snapshot is refused rather than silently guessed at. The result is verified before it is handed over: the file structure is read back, and the mesh is re-opened independently and confirmed to be closed and non-empty rather than a shell full of holes.
Turn an animated scene into video
If you already have an animated 3D scene with exactly one camera in it, that scene can be rendered out to video, up to twenty seconds at thirty frames a second. A scene with no camera, or with its animation split into pieces, is refused before rendering starts, so you learn about the problem in seconds instead of after a long render. A full twenty-second render has been produced and has passed automatic inspection. This path is finished and is waiting on a named person's sign-off on that render before it is switched on for customer work.
A quick look while the machine is busy
Rendering competes for the same hardware as everything else you run. A second, much lighter preview path uses no graphics card at all, so camera moves, timing, and staging can be checked while the real render waits behind other work. It simplifies materials and lighting on purpose and stamps every frame so it can never be mistaken for a finished shot.
Timed sound on an approved clip
Sound can be laid onto an already-approved twenty-second clip, with each cue landing on an exact frame rather than a rounded-off fraction of a second. Up to seven tracks are accepted, each bound to a provenance record your own platform is responsible for verifying. The picture is copied through untouched and then checked afterwards to prove it was not re-encoded along the way. This path is built and switched off, waiting on a person listening to a real mix, signing off, and a playback retest on a handset.
Each workspace is walled off from every other
Jobs, uploaded files, and finished results are stored under the workspace that created them. A request that arrives without a valid workspace is refused rather than guessed at, and a result can never be handed to a different workspace, even by asking for it directly by name.
Limits you set, before the bill exists
Ceilings on jobs per day, jobs running at once, and total stored output are checked when a job is created, not discovered afterwards. The starting values are 25 jobs a day, 3 in flight, and 5 GB stored per workspace, and all three are yours to change. Anything still waiting on review counts against the in-flight ceiling, so an unreviewed backlog cannot quietly grow.
High-risk requests stop at the door
A small fixed set of request categories is refused before any hardware is committed, covering sexual content involving minors, non-consensual intimate imagery, credential-theft impersonation, and graphic harm to a real person. This is a deliberately narrow gate on the way in, not a general safety filter, and it is one reason a person still has to approve everything on the way out.
Cancel anything, survive a restart
Cancel a queued or running job and the work actually stops, including the process performing it and anything it started, so nothing is left running in the background holding your hardware. If the machine restarts in the middle of a job, that work is picked back up rather than lost. After a set number of attempts it is marked failed with a reason instead of retrying forever.
It refuses instead of guessing
Before every job it confirms that the exact expected hardware, versions, and model files are present and that enough memory is genuinely free. If something is missing, or the machine is already busy with your other work, it says which condition failed and stops. It never falls back to a slower path or a different engine and then hands you the result as though nothing happened.
A record of what happened, not of what you wrote
Created, started, finished, viewed for review, approved, rejected, expired: each step is written into an append-only trail, along with the size and content fingerprint of the file. That lets you prove a delivered file is the exact one that was approved. What the trail deliberately never contains is your prompt or the name of the file you uploaded, and a status query does not return the prompt either.
Old media clears itself out
Results and their inputs expire on a schedule you set, starting at seven days. Clearing runs in a report-only mode first, so you can read exactly what would be removed before anything actually is. Once you switch it on, expired output and inputs that no remaining job still needs are removed, and the wording of the original request is stripped from the record that remains.
Proof
Numbers we can stand behind.
Every figure below comes from the product's own release record or test suite, not from a marketing estimate.
- The generation engine is a replaceable part, so moving to faster hardware later does not change how your own software asks for a video.
Where it runs
Surfaces and status.
Status as of 2026-09-02. Version 0.10.1 in the private repository, head change dated 2026-08-31. Real results have been produced and independently re-checked on the workstation: a verified 16-frame clip on 2026-08-29, a watertight 3D model from one prepared image in 123.06 seconds on 2026-08-29, a 200-frame check preview on 2026-08-30, and a 600-frame, 20-second scene render recorded at the current head. The repository's own automated suite was re-run in the clone on 2026-09-02 and passed. Every generation engine ships switched off in the shipped configuration, and with all of them off the service reports itself not ready by design. The README's own remaining list names human visual approval of the retained render, human quality and output-safety acceptance for video and a broader 3D fixture set, approved limits and billing values, a private delivery path, and explicit authorization to deploy. There is no customer-facing address for this product, and nothing from this repository has been deployed. Sources:.
Works with
Worth more together.
Products on this platform share one sign-in, one support queue, and one engineering standard. These pair naturally with ASL Media Worker.
ASL AI Hub
The place your team already signs in to work with models. Generation belongs next to it, behind the same single sign-in, so a person who can use one does not need a second account.
Explore →ASL Files
Approved clips and models need somewhere to live once they are released. Files gives them a home with sharing you control, instead of them sitting on the generation machine forever.
Explore →ASL Timestamp Anchor
Every result already carries a content fingerprint. Timestamp turns that into dated, independently checkable evidence that a specific approved file existed on a specific day.
Explore →ASL Vault
The credential that lets your software reach the generation service should not sit in a configuration file somebody can read. Vault holds it and hands it over only to the service that needs it.
Explore →ShopFit
If you run a store, the reason to generate video at all is usually a product page. ShopFit is where those clips end up doing work.
Explore →What is new
Recent progress.
This product ships often. The most recent verified changes, newest first.
the first verified video clip was generated on the workstation's own graphics card, 16 frames at 384 x 384 in about 252 seconds, and the automatic integrity screen was calibrated against real evidence so that one known-bad clip is rejected while two known-good clips pass.
the first real 3D result was produced and independently verified, one prepared image to a closed, non-empty model in 123.06 seconds, after a hidden dependency that tried to reach the internet mid-job was found and shut off.
a preview path that uses no graphics card shipped, producing a 200-frame, 20-second check preview in 14.41 seconds while the card was occupied by other work.
to.
scene rendering exposed and fixed a real timing defect, where animation was being read in at the wrong frame rate and produced byte-identical output; the corrected path now stamps its timing into the result so an older, unproven render can be rejected on sight. The most recent change, dated.
, records a full 600-frame, 20-second render that passed automatic inspection with 561 distinct frames and is now waiting on a named person's visual approval. Sound mixing with frame-exact cue placement was completed in the same period and is switched off until someone listens to a real mix, signs off, and retests playback on a handset.
Pricing
Pricing for ASL Media Worker is quoted after a short conversation about your situation, because the right scope differs from one team to the next. There is no charge for that conversation.
Ask about pricingQuestions buyers ask
Straight answers.
What does it cost?
Pricing is not published yet, because the limits it would be based on are still being agreed. What already exists is the machinery pricing needs: per-workspace ceilings on jobs per day, jobs at once, and stored output, all counted and enforced at the moment a job is created. If you want to talk about what a plan would look like for your volume, that conversation is open now.
We already use an online generator. Why change?
The difference is where your material goes and what you can prove afterwards. Here the image and the finished file stay on hardware you control, and the path that delivers a result keeps no copy of its own. You also get a record of which engine version produced a file and who approved it, which most online tools simply do not give you.
What actually happens to my footage and my images?
Uploaded files and generated results are stored on your generation machine, under the workspace that created them, and are never handed to another workspace. The audit trail records what happened to each file, never your prompt and never the file's name. Everything expires on a schedule you set, starting at seven days, and clearing runs in a report-only mode first so you can read what would go before anything does.
Is it ready?
Not for customers yet, and we will not pretend otherwise. What has been proven on real hardware is real: a verified video clip, a verified 3D model built from one prepared image, a full 20-second scene render, and a lighter preview path that works while the graphics card is busy. Every engine still ships switched off. What remains is human sign-off on the retained render, quality scoring against the full prompt set, agreed limits and pricing, and authorization to switch it on.
What happens to our files if we stop paying, or if you disappear?
The generated files and the uploads are already on your machine, in ordinary folders, in ordinary formats. A standard 3D file and a standard video file open in any tool. Nothing has to be exported out of a service you no longer have access to, because the media was never held somewhere else in the first place.
How much do we have to move to get started?
Nothing. There is no library to import and no back catalog to migrate. Work arrives one job at a time: you send a description or a single prepared image, and the result comes back. If you decide against it a month later, you stop sending jobs and your existing files are unaffected.
Can it post finished clips automatically?
No. Every result is held until a person approves it, and that hold is on by default and enforced by the generation service, so nothing a request or a calling application sends can bypass it. It is a setting rather than a law of physics, and only whoever runs the installation can turn it off deliberately; we would rather say that plainly than pretend it cannot be done. A reviewer can watch a held clip through a separate viewing path that records the viewing and changes nothing, so seeing it never accidentally releases it.
Will it slow down the machine our team already uses?
It is built to give way. One job runs at a time by default, and before starting anything it checks whether enough memory is genuinely free. If your other work is using the machine, it refuses and says so instead of starting and fighting for resources. There is also a light preview path that uses no graphics card at all, so scene and timing checks can carry on while the heavy work waits.
Can we ask it to generate anything?
Within limits, and the limits are deliberately at both ends. On the way in, a small fixed set of high-risk categories is refused before any hardware is committed. On the way out, everything is held for a person. The gate on the way in is narrow on purpose and is not a general safety filter, which is exactly why the human decision on the way out is not optional by default.
What should I know before I rely on it?
We would rather you hear this from us than discover it later. As of 2026-09-02:
- It is not open to customers yet. Several approval steps remain, including a named person signing off on the retained full render, human quality and output-safety acceptance for video and a broader 3D fixture set, agreed limits and billing values, and explicit authorization to switch it on.
- Every generation engine ships switched off. Turning one on is a deliberate step by whoever runs the installation, after that engine's own hardware, version, and model-file checks pass. Until then the service reports itself not ready on purpose.
- Human approval is on by default and cannot be bypassed by a request, a user, or a calling application, but it is a setting: whoever runs the installation can deliberately turn it off. We will not claim it is impossible to disable.
- Text-to-video clips are short. The envelope measured on the current hardware is one or two seconds at a small square frame size, at eight frames a second. Longer and larger output needs different hardware, not different code.
- A higher-capacity text-to-video engine is written and version-pinned but has never been run: no machine here has a card it supports. Even that engine tops out at about five seconds.
- 3D input is not an ordinary snapshot. The object must already be cut out, or the caller must confirm it is centered on a plain background. Background removal is deliberately not automatic, so an unprepared photograph is refused.
- 3D output is one object from one prepared image, colored per vertex with no texture image, and has been proven on a single verified result from a fixed test image. Quality across a wide range of real images is not yet established.
- The watch-without-releasing path is for video only. A 3D result waiting for approval has no equivalent preview route today, and the video stream plays straight through rather than supporting seeking or frame-accurate scrubbing.
- Text-to-video quality has not yet been scored against the full 20-prompt set. The machine has been busy with other authorized work each time the scoring run was attempted, and the run correctly refused to start rather than fight for memory.
- Scene rendering and sound mixing are finished and switched off, waiting on a person to look at and listen to real output, sign off, and in the sound case retest playback on a handset.
AI video and 3D that stay on your hardware
Generate video and 3D models on hardware you own, with every result held for a person to approve.
Prefer email? contact@autosecurelogin.com