Security
Built for content security reviews
The questions a studio's security auditor asks, answered in the order they usually ask them.
Data
- Project files
- never transferred to the client
- Clipboard
- policy: off, text-only, or full
- File transfer
- disabled by default, audited when enabled
- Screen capture
- blocked on managed clients where the OS allows
Access
- Authentication
- SAML or OIDC, MFA enforced
- Device posture
- certificate-based, optional
- Session recording
- optional, per project
- Watermarking
- forensic, per session, on request
Network
- Transport
- DTLS 1.3, per-session keys
- Egress from workstation
- allow-list only
- Site connectivity
- IPsec or private circuit
- Region pinning
- per project
Audit
- Session log
- who, when, which machine, which project
- File operations
- logged when transfer is permitted
- Retention
- 13 months, exportable
- Reviews
- annual penetration test, summary published
Auditor questions
They can photograph the screen — no system prevents that, and any vendor claiming otherwise is overselling. Forensic watermarking makes the source of a leak identifiable, which is the realistic control.
No, by default. Support access requires a customer-initiated grant, is time-boxed, is recorded, and appears in the audit export.
Our platform components are assessed annually and the report is available under NDA. Your own facility remains your assessment.
Wiped on session end with a cryptographic erase of the per-session key, and the physical blocks are overwritten before reuse.