What stays private
- Storage credentials
- Provider secrets
- Private source configuration
- Secret API keys
There is no customer-facing Standard, Strict or Maximum mode. Authenticated viewer email and stable device identity are baseline playback requirements; the purchased plan decides which additional protection features are enabled.
Protection layers
Admin enables plan features. Customers buy a plan. Runtime enforcement follows those entitlements.
Provider credentials, API keys and private source configuration do not belong in the browser.
Protected sessions are scoped and expire instead of becoming permanent reusable media links.
Protected playback binds the authenticated viewer email to a stable application device ID. Dynamic watermarking can display that trusted identity when the active plan enables it.
When the active plan includes the control, sessions and devices can be blocked or revoked from the control plane.
No browser system can guarantee prevention of every screen recording or capture method. Unpirator focuses on enforceable access control, short-lived delivery, accountability and reducing casual redistribution.
Read the architecture