Security & Compliance — Aeion Production

Production data is among the most sensitive in entertainment — unreleased scripts (worth $50M+ in leak prevention), talent PII (SSN, addresses, dates of birth), budget data (sensitive negotiations), sensitive emails (casting conversations, agent communications). Aeion ships institutional-grade controls — per-script RBAC with watermarked review links, encrypted crew PII at rest (AES-256), MPA (Motion Picture Association) Best Practices alignment, signed audit log for studio compliance, NDA-enforced reviewer access, IP geofencing for pre-release content. Designed for studio + agency security requirements.

Script Confidentiality

The single highest-value asset in production.

Crew PII Encryption

Crew and cast records hold legally sensitive PII: full legal name, date of birth, Social Security Number, tax ID (for loan-out companies), home/mailing address, phone, email, emergency contacts, bank details for direct deposit, relevant medical conditions, I-9 verification documents, union affiliations + member numbers, tax withholding forms, and loan-out company details.

MPA Best Practices Alignment

MPA Best Practices is the industry standard for content security.

Audit Log + Compliance Evidence

Every production action is logged: creates, updates, deletes, views, shares, downloads, prints, approvals, submissions, revisions, and locks/unlocks — each tied to the actor, their role, the entity affected (script, budget, schedule, call sheet, crew, cast, vendor, report, or invoice), a before/after state for updates, a timestamp, IP address, user agent, session, and a cryptographic signature.

Compliance Mapping

`

FAQ

Yes — every distributed PDF carries a visible per-viewer watermark plus an invisible per-viewer mark embedded in the document's text layer. If a leaked PDF (or its extracted text) surfaces, forensic analysis recovers the mark and identifies the original viewer — even if the visible overlay was cropped. The invisible mark identifies the digital original; it is not a pixel-domain watermark, so it does not survive a screenshot or a re-photographed screen.

No system is uncrackable, but Aeion's defenses (per-tenant encryption, RBAC, audit log, MFA-required for sensitive ops) raise the bar significantly. Sony's hack exploited weak password policies + shared admin accounts; Aeion's defaults prevent that.

Absolute. Per-tenant Postgres schemas; row-level security; no cross-tenant query possible. Customer-managed encryption keys (BYOK) on Enterprise for additional isolation.

Type 1 complete; Type 2 in audit cycle. Available to Enterprise customers under NDA.

Annual third-party pentest by reputable firm (NCC Group equivalent). Summary available to Enterprise customers.

Active program; production module vulnerabilities prioritized P1. Up to $10K per critical finding.

Enterprise tier custom engagement. Used by military training, classified entertainment projects.

Enterprise tier via AWS KMS / GCP KMS / Azure Key Vault. Revocation = effective data destruction.

Aeion Production doesn't have a dedicated encrypted I-9 store or an E-Verify export pipeline today — "I-9" is available as a generic document-type tag when uploading cast/crew paperwork, with the same protections as any other uploaded file. Run I-9 verification and E-Verify submission through your HR/compliance systems; if you need cert-grade encrypted storage or a compliant export for I-9 specifically, talk to your Aeion rep about the roadmap.

Aeion retains tax-related records 7+ years (US IRS requirement). Configurable per state + country.

Erasable items tombstoned; retention-required items (tax forms, I-9, contracts) preserved + anonymized per regulation.

Aeion carries $10M Cyber liability via reputable insurer. Customers responsible for their own E&O for production-specific risks.

Production security ready for studio audits.