Security model

Security is not a label. It is the controls that actually run.

There is no customer-facing Standard, Strict or Maximum mode. Authenticated viewer email and stable device identity are baseline playback requirements; the purchased plan decides which additional protection features are enabled.

Request boundaryfail closed
viewer email resolved server-side
device identity present
session valid
origin allowed
protected media response

Protection layers

Concrete controls, each with a job.

Admin enables plan features. Customers buy a plan. Runtime enforcement follows those entitlements.

Secrets stay server-side

Provider credentials, API keys and private source configuration do not belong in the browser.

Playback is short-lived

Protected sessions are scoped and expire instead of becoming permanent reusable media links.

Viewer identity is server-authoritative

Protected playback binds the authenticated viewer email to a stable application device ID. Dynamic watermarking can display that trusted identity when the active plan enables it.

Access can be revoked

When the active plan includes the control, sessions and devices can be blocked or revoked from the control plane.

What stays private

  • Storage credentials
  • Provider secrets
  • Private source configuration
  • Secret API keys

What we do not claim

No browser system can guarantee prevention of every screen recording or capture method. Unpirator focuses on enforceable access control, short-lived delivery, accountability and reducing casual redistribution.

Read the architecture