Security
Security
Three locks on the video, and one plain answer about who holds the keys, the passwords and the viewer accounts.
Three locks
Set up for you, recorded, and working while your team stays on content.
- 1Encrypted, and short livedEvery title is encrypted. A playback link expires in five minutes, and in two on a live channel, so a copied link stops working.
- 2Checked at the edgeEvery manifest, segment and key request is authorised before a byte moves. Anything that does not match is answered with a 404.
- 3Counted devicesAn account registers a limited number of devices, three by default, so one household does not become one neighbourhood.
Where the keys live
Apart from the video, issued per request, and on your own infrastructure.
The key never travels with the file. A player asks for it at playback and receives it only after the entitlement check passes. The keys, the gateway credentials and the viewer accounts sit in your own vault, on hardware you own.
There is no licensed DRM licence server on this platform today. The mechanism is AES-128 with per-request authorisation, which is a weaker claim than a studio DRM and it is the claim we make.
After you leave
You keep the hardware, the data, the customers and the content.
The infrastructure is written down as code and handed over with a guide your team can follow. There is no fee to take your own data out, and no part of the stack is licensed back to you.
No certification yet
We hold none and we claim none, so here is what a buyer may inspect instead.
- 1The infrastructure codeTerraform, the Ansible roles and the pipeline configuration, read by your own engineers.
- 2The edge configurationThe rules that gate every manifest, segment and key request, and the catch-all that refuses the rest.
- 3A walkthroughOur engineers take your engineers through both, and answer in the room.
- 4Card dataPayment runs on the gateway's own hosted page, which keeps PCI-DSS scope with the gateway.