A complete operational reference for brand protection teams — how Hubstream structures an IP enforcement case from first alert to resolution, and what data gets captured along the way.
Every brand protection case moves through six stages — from initial alert to logged outcome. Here's how Hubstream structures that journey.
A new case enters Hubstream from one of several sources: an automated alert from a monitoring platform, a consumer or field report via Report a Fake, a customs seizure notification, or a manual entry by a team member. Each source maps to a structured intake form that captures the minimum required data to open a case.
Hubstream scores each new case by priority using configurable AI rules — factoring in product type, platform, seller history, and geographic risk. Simultaneously, OSINT enrichment runs against the seller account, domain, or email address to build a fuller profile: registration data, linked accounts, historical enforcement records, and geolocation data.
The investigator pivots from the case into Hubstream's DataSpace to run link analysis. Seller accounts, companies, individuals, addresses, and prior enforcement actions are connected into a visual network graph. Repeat offenders are automatically surfaced — even when they operate under different seller names or marketplaces. The investigator can follow any relationship thread without losing context.
From the case record, the team initiates one or more enforcement actions: a platform takedown request, a cease-and-desist referral to outside counsel, a customs escalation, or a direct law enforcement referral. Hubstream auto-generates the required documentation — case summary, evidence package, entity profile — formatted for the receiving party.
Open enforcement actions are tracked automatically. Platform takedowns are monitored for compliance; if a listing reappears within a defined window, Hubstream flags the recurrence and escalates the case. Deadlines on C&D letters trigger reminders and escalation workflows. The team never has to chase status manually.
When a case is closed, the outcome is logged — takedown confirmed, arrest made, seizure recorded, case withdrawn. All outcomes feed the trend dashboard automatically: enforcement volume by platform, recidivism rates, top offender networks, seizure value over time. Executives get a live picture of program impact without any manual report assembly.
Every entity in Hubstream's IP & Brand Protection template — what it represents, what fields it holds, and how it connects to the rest of your enforcement picture.
The central record every other entity links to. Tracks the lifecycle of a single enforcement action from intake to resolution.
A marketplace or platform seller identity linked to one or more cases. Key pivot point for identifying repeat offenders across platforms.
A website or domain associated with infringing activity — counterfeit storefronts, phishing sites, grey-market distributors.
A specific infringing product listing — the individual offer being sold, captured with its current state and evidence.
A legal entity — distributor, manufacturer, importer, or shell company — connected to the infringing supply chain.
An individual connected to the infringement — seller account owner, company director, or contact named in enforcement records.
A physical or registered address — warehouse, storefront, residential, or shipping origin — linked to entities in the network.
The brand's intellectual property being infringed — trademark, patent, copyright, or trade dress. Anchors every case to the specific right being protected.
Anything captured to support an enforcement action — screenshots, test purchase records, lab reports, shipping documents, correspondence.
A formal or informal request to a platform or registrar to remove infringing content. Tracked from submission through confirmation.
A physical seizure of counterfeit goods at a border or port. Links to the shipment, importer, and originating case for network analysis.
These are the relationship paths that reveal patterns invisible in any single system — the connections that turn isolated records into an enforcement network.
Every seller account can be linked to a real individual — by registration email, payment account, or shipping address — revealing the human behind the storefront and their full history across platforms.
Repeat offenders operate under new seller names after takedowns. Shared email, phone, address, or payment fingerprints link accounts across marketplaces — surfacing a network that appears unrelated to any one system.
A named individual connected to a company as director, owner, or signatory — tracing the supply chain from street-level seller to registered legal entity, including shell companies.
Registered, operating, and shipping addresses linked to a company — revealing warehouse locations, manufacturing origins, and the geographic scope of a distribution operation.
A physical seizure at the border connected back to the importer of record and onward to a known seller account — closing the loop between online enforcement and physical supply chain disruption.
WHOIS registration data, hosting records, and shared IP address ranges link a domain to its operator — connecting an anonymous infringing storefront to a known entity in the network.
When a new case is opened, Hubstream checks whether any linked entity — seller, person, company, address — appears in prior enforcement history, automatically flagging recidivism and escalating priority.
After a takedown is confirmed, the original listing and seller are monitored. If the same or substantially similar listing reappears — on the same or a different platform — it is linked back to the original case and auto-escalated.
The IP & Brand Protection template covers the full enforcement lifecycle. These add-ons bolt onto specific stages when your team needs a dedicated sub-workflow for high-volume or specialized activity.
An external-facing intake form that lets consumers, field agents, or distribution partners submit suspected counterfeit reports directly into Hubstream — automatically creating a case and triggering triage.
A dedicated sub-workflow for managing high-volume platform takedown requests — from submission through confirmation and recurrence monitoring — without losing track of where each request stands.
A specialized workflow for receiving, processing, and linking physical customs seizures — connecting each seizure back to known seller accounts, companies, and active cases for supply chain network analysis.
Request a demo and we'll walk you through how this workflow and data model work inside a real Hubstream environment — configured for your team's specific products, platforms, and enforcement process.