
Platform architecture
From camera to mirror in one glance.
A guest steps in front of the Manifest Mirror and sees themselves somewhere else — same face, same posture, different world. Everything between that glance and that image is the platform: six layers that capture, generate, display, operate, match and follow up.
The stack
Six layers, one system.
Each layer is a product in its own right, and each one assumes the others exist. The mirror is the endpoint people meet; the rest is what makes a hundred endpoints behave like one medium.
Manifest Mirror
The physical interface: a mirror-format display with a front-facing camera, running a locked-down browser in kiosk mode. It handles attract, consent, the session and the hand-off to the phone.
Learn moreManifest Engine
The intelligence layer. A real-time generative video engine transforms wardrobe, setting and lighting while identity lock keeps the face, proportions and expression of the person in front of the glass.
Learn moreManifest Studio
Where brand worlds are built. A world is ten moments; a moment is a scene, a garment reference, a prompt and an ambient video, tested on a real mirror before it is published.
Learn moreManifest OS
Operations across venues: fleet health, central configuration, content distribution, kiosk lock and remote diagnostics. Session policy is set once and applies everywhere.
Learn moreManifest Market
The matching layer between brands with worlds and venues with footfall. Campaigns are booked onto mirrors by location and time, and reported on in sessions rather than impressions.
Learn moreManifest Agents
The follow-up layer. A recording is a moment with intent attached; Agents connect it to the relevant next step through the email delivery and the phone remote, with consent first.
Learn moreSignal path
What happens in ninety seconds.
The guest experiences one continuous image. Underneath, the session moves through four stages, and none of them asks the guest to install anything.
-
Attract and consent
The mirror runs its attract loop from local precache, so it keeps working even when the venue network does not. A touch or a scan starts the session. Before the camera opens, the guest sees the AI notice and gives consent.
-
Capture and pair
The front camera opens and the frames stream to the Engine over a secured connection. Scanning the on-screen code at qr.manifestmirror.com pairs the guest's phone, which becomes the remote for moments, outfits and looks.
-
Generate with identity lock
The prompt stack assembles brand world, moment and look, with identity preservation placed first and last. The Engine returns continuous video, not a still, and the mirror displays it sub-second — close enough to feel like a reflection.
-
Deliver and forget
The recording is assembled server-side and sent to the address the guest entered on their phone. Recordings are deleted automatically after seven days, email deliveries after thirty. Nothing is kept on the unit.
A medium earns attention by giving something first. The architecture exists to make that exchange fast enough to feel like nothing happened at all.
Manifest Media manifesto
Design decisions
Three choices that shape the whole system.
Latency, identity and control. Each of them was decided early, and each of them rules out a simpler architecture.
Outfit-only mode keeps the real room behind the guest
Real time
A reflection cannot buffer
People test a mirror by moving. If the image lags behind the shoulder, the illusion breaks and the session is over before it started. Everything upstream is built to protect the loop between movement and image.
- Continuous video. The mirror shows a live stream, not a sequence of generated photographs.
- Sub-second response. Turn, lift an arm, tilt your head — the world follows in the same glance.
- Two modes. Outfit only keeps the real background for try-on; full world replaces setting and lighting as well.
- Format-aware. The same world renders correctly in 9:16, 3:4, 1:1, 4:3 and 16:9 without being re-authored.
Wardrobe and setting change; the face does not
Identity lock
Your face stays your face
The failure mode of generative video is that the guest becomes somebody else. Identity lock is the constraint that runs through every prompt the Engine assembles, before the brand world and after it.
- Preserved. Face, skin tone, age, expression and body proportions.
- Transformed. Wardrobe, setting, lighting and atmosphere.
- Reviewed. Brand worlds pass human review in Studio before they reach a venue.
- Declared. Guests are told that the image is AI-generated before the camera opens.
Pairing by QR keeps the glass free of keyboards
Control surface
The phone is the remote
A mirror covered in fingerprints is a worse mirror. Pairing moves the interface to a device the guest already trusts and already knows how to use.
- No app. The remote is a web page opened by scanning a code — nothing to install, nothing to update.
- Switch mid-session. Moments and outfits change while the session runs, so one visit covers several looks.
- Private input. The email address for the recording is typed on the guest's own screen, not on a public display.
- Queue-friendly. The next guest can read the instructions while the current session is still running.
At a glance
The platform in one table
Defaults as shipped. Session length, looks and formats are configured centrally and can differ per venue.
| Rendering | Continuous real-time generative video |
|---|---|
| Latency | Sub-second, tuned to feel like a reflection |
| Identity | Locked: face, proportions and expression preserved |
| Session | 90 seconds by default, adjustable centrally |
| Modes | Outfit only (real background kept) or full world |
| Formats | 9:16, 3:4, 1:1, 4:3, 16:9 |
| Looks | Nine UI themes: Gold, Platinum, Noir, Atelier, Pulse, Blueprint, Bridal, Concierge, Play |
| Remote | Phone paired by QR at qr.manifestmirror.com |
| Delivery | Recording sent by email after the session |
| Retention | Recordings deleted after 7 days, deliveries after 30 |
| Kiosk | PWA in fullscreen with offline precache of all assets |
| Connectivity | Single power and single network connection per unit |
| Operations | Central configuration, remote diagnostics, multi-mirror concurrency |
Configuration
Set once. Or set per venue.
Runtime configuration is the difference between a demo and a medium. The platform separates what an operator decides for the whole fleet from what a venue decides for its own floor.
Global policy
- Session length. Changed once and applied to every paired unit, behind a password.
- Content distribution. Worlds and moments are pushed to the fleet and precached before they go live.
- Retention. Deletion windows for recordings and deliveries are enforced by the platform, not by staff.
- Kiosk lock. Units stay in fullscreen, with no route out of the experience on the glass.
Venue choices
- Look. One of nine UI themes, matched to the room rather than to the brand of the platform.
- Format. Portrait for windows and lobbies, landscape above counters, square on a booth.
- Mode. Outfit only where the real room sells, full world where escape sells.
- World. Which brand worlds are available at that site, and in which order they appear.
Public spaces, unattended units, ordinary internet
Security posture
Built for an unattended room
A mirror stands in a public space and runs without supervision. The platform assumes that, and treats every session as a short-lived, verifiable lease rather than an open door.
- Origin allow-lists. Only known venue origins may open a session against the Engine.
- Rate limits per IP. Traffic is bounded so a single source cannot occupy the fleet.
- Session leases. Sessions expire on their own; an abandoned mirror returns to attract mode by itself.
- No third-party trackers. No ad-tech, no analytics brokers, no scripts from outside the platform.
Go deeper
Three ways into the stack
Identity & AI
The prompt stack, what the model may change and what it must keep, transparency notices and guardrails.
Explore
Hardware
Unit families, the five formats, camera height, lighting and what installation day actually involves.
Explore
Privacy & compliance
Consent before camera, ephemeral sessions, deletion windows, and the data lifecycle written for a DPO.
ExploreQuestions
Architecture, answered
Partly, and deliberately. The kiosk application is a PWA that precaches its assets, so attract mode, the interface and the venue's look keep running through an outage. Live generation and email delivery need the connection, because the transformation is produced upstream rather than on the unit.
The platform is built for concurrency across a fleet: each unit holds its own session lease and its own configuration, and venues with several mirrors run them side by side. Capacity for a specific site is planned with you before installation.
No. Frames stream through for the duration of the session, the recording is assembled server-side, and the unit keeps nothing after the guest walks away. Recordings are deleted automatically after seven days and email deliveries after thirty.
Manifest Engine orchestrates leading real-time video foundation models rather than tying the platform to one of them. The orchestration — the prompt stack, identity lock, the mode selection and the review process — is ours, and it is what makes the output consistent from world to world.
Session length is a central, password-protected setting. Ninety seconds is the default because it fits three moments and a recording while keeping a queue moving, but an operator can raise or lower it for the fleet or for a single site.
A world is built and reviewed in Manifest Studio, tested on a real unit, then published through Manifest OS to the venues that should carry it. Distribution and precache happen before the world goes live, so nothing downloads in front of a guest.
Brand worlds shown across this site are demonstration concepts built for the Manifest Mirror platform; they do not imply a commercial relationship with the brands depicted.