Security
Effective as of October 1, 2026
Innocrux hosts other organisations’ video libraries. For a broadcaster or a studio, the content is the business, so this page sets out what protects it — and what the division of responsibility is, because some of it is ours and some of it is the customer’s.
1. Content protection
Content protection is the part of platform security specific to streaming, and it is the part most often tested. Innocrux applies these controls:
- Multi-DRM. Widevine, FairPlay and PlayReady, so protected playback works across browsers, mobile, smart TV and set-top boxes without falling back to an unprotected stream on any major device.
- Token authentication. Playback URLs are issued against short-lived tokens, so a copied manifest URL stops working rather than becoming a permanent open door.
- Geo-blocking. Delivery can be restricted by territory, which is what makes it possible to honour rights windows that differ by market.
- Concurrent-stream limits. Per-account concurrency caps, which is the practical control against shared credentials.
- Forensic watermarking. Session-level marking that lets a leaked copy be traced back to the account it came from.
These are configurable per title, per territory and per audience segment. A customer licensing content under a studio agreement will usually be required to enable most of them; which ones apply is set during deployment and can be changed afterwards.
2. Encryption
Traffic between viewers, the platform and its APIs is encrypted in transit over TLS. Stored content and the data about it are encrypted at rest. DRM licence keys are held in the key management of the respective DRM system rather than alongside the media they protect.
3. Access control
Access to the platform is role-based: a customer decides who at their organisation can publish, who can configure monetization, who can read analytics and who can administer users. Roles are the mechanism by which a customer limits its own blast radius, and we encourage using them rather than giving everyone an administrator account.
Innocrux personnel access customer environments only where it is necessary to operate the service or to resolve a support request, under least-privilege access that is granted for the task and removed afterwards.
4. Separation between customers
Each customer’s content, configuration and audience data are logically separated. One customer cannot read another’s library, viewer records or analytics. Where a customer operates as a reseller with its own tenants, the same separation applies between those tenants.
5. Infrastructure
The platform runs on managed cloud infrastructure, with delivery over CDN. It also supports private CDN and on-premise GPU transcoding, which means a customer with regulatory or contractual constraints can keep encoding and delivery on hardware it controls, in a jurisdiction it chooses, rather than accepting ours.
6. Monitoring and incident response
The platform is monitored for availability, errors and abnormal patterns such as unexpected concurrency or distribution of playback requests. Where we identify a security incident affecting a customer’s data or content, we will notify that customer without undue delay, tell them what we know and what we are doing, and keep them updated until it is closed.
We would rather tell a customer about an incident early and be wrong about its scope than be certain and late.
7. Resilience
Content and platform data are backed up, and restoration is tested. Specific recovery objectives form part of the commercial agreement rather than a published commitment, because they differ by deployment — a 24/7 linear channel and an on-demand catalogue do not need the same guarantees.
8. Shared responsibility
Some of the controls that decide whether a service is secure are not ours to operate. Innocrux is responsible for the platform, its infrastructure, the protection features above and the separation between customers. The customer is responsible for who it grants access to, for the strength and handling of those credentials, for which protection features it enables, for the rights position of what it streams, and for the obligations it owes its own viewers.
A platform with DRM available and DRM switched off is not a protected platform. The configuration is the customer’s decision and we will advise on it, but we cannot make it for them.
9. Certifications
Innocrux does not currently publish a third-party security certification such as SOC 2 or ISO 27001 on this page. Where a certification is required as part of a procurement process, contact us and we will tell you honestly what we hold, what is in progress and what we can evidence instead — a completed security questionnaire, architecture documentation, or the configuration of a specific deployment.
We would rather answer that question directly than imply an attestation we cannot produce.
10. Reporting a vulnerability
If you believe you have found a security issue in the Innocrux platform or this website, write to [email protected] with enough detail to reproduce it. We will acknowledge the report, investigate, and tell you the outcome.
Please report privately and give us a reasonable opportunity to fix the issue before disclosing it. Do not access, modify or exfiltrate data belonging to a customer or a viewer while testing, and do not run load or denial-of-service tests against production. We will not pursue a researcher who follows those limits in good faith.
11. Contact
Security questions, questionnaires and incident queries: [email protected]. Tech Innocrux Private Limited, No. 28, Padma Street, VGN Avenue, Mogappair, Chennai – 600 037, India.