Security & Compliance — Aeion Production
Production data is among the most sensitive in entertainment — unreleased scripts (worth $50M+ in leak prevention), talent PII (SSN, addresses, dates of birth), budget data (sensitive negotiations), sensitive emails (casting conversations, agent communications). Aeion ships institutional-grade controls — per-script RBAC with watermarked review links, encrypted crew PII at rest (AES-256), MPA (Motion Picture Association) Best Practices alignment, signed audit log for studio compliance, NDA-enforced reviewer access, IP geofencing for pre-release content. Designed for studio + agency security requirements.
Script Confidentiality
The single highest-value asset in production.
Crew PII Encryption
Crew and cast records hold legally sensitive PII: full legal name, date of birth, Social Security Number, tax ID (for loan-out companies), home/mailing address, phone, email, emergency contacts, bank details for direct deposit, relevant medical conditions, I-9 verification documents, union affiliations + member numbers, tax withholding forms, and loan-out company details.
MPA Best Practices Alignment
MPA Best Practices is the industry standard for content security.
Audit Log + Compliance Evidence
Every production action is logged: creates, updates, deletes, views, shares, downloads, prints, approvals, submissions, revisions, and locks/unlocks — each tied to the actor, their role, the entity affected (script, budget, schedule, call sheet, crew, cast, vendor, report, or invoice), a before/after state for updates, a timestamp, IP address, user agent, session, and a cryptographic signature.
Compliance Mapping
`
FAQ
Yes — every distributed PDF carries a visible per-viewer watermark plus an invisible per-viewer mark embedded in the document's text layer. If a leaked PDF (or its extracted text) surfaces, forensic analysis recovers the mark and identifies the original viewer — even if the visible overlay was cropped. The invisible mark identifies the digital original; it is not a pixel-domain watermark, so it does not survive a screenshot or a re-photographed screen.
No system is uncrackable, but Aeion's defenses (per-tenant encryption, RBAC, audit log, MFA-required for sensitive ops) raise the bar significantly. Sony's hack exploited weak password policies + shared admin accounts; Aeion's defaults prevent that.
Absolute. Per-tenant Postgres schemas; row-level security; no cross-tenant query possible. Customer-managed encryption keys (BYOK) on Enterprise for additional isolation.
Type 1 complete; Type 2 in audit cycle. Available to Enterprise customers under NDA.
Annual third-party pentest by reputable firm (NCC Group equivalent). Summary available to Enterprise customers.
Active program; production module vulnerabilities prioritized P1. Up to $10K per critical finding.
Enterprise tier custom engagement. Used by military training, classified entertainment projects.
Enterprise tier via AWS KMS / GCP KMS / Azure Key Vault. Revocation = effective data destruction.
Aeion Production doesn't have a dedicated encrypted I-9 store or an E-Verify export pipeline today — "I-9" is available as a generic document-type tag when uploading cast/crew paperwork, with the same protections as any other uploaded file. Run I-9 verification and E-Verify submission through your HR/compliance systems; if you need cert-grade encrypted storage or a compliant export for I-9 specifically, talk to your Aeion rep about the roadmap.
Aeion retains tax-related records 7+ years (US IRS requirement). Configurable per state + country.
Erasable items tombstoned; retention-required items (tax forms, I-9, contracts) preserved + anonymized per regulation.
Aeion carries $10M Cyber liability via reputable insurer. Customers responsible for their own E&O for production-specific risks.