

Video security controls who can access content, how it is delivered, and what happens to viewer data. For organisations managing internal communications, training content, or confidential client video, the security layer of a hosting platform is not a secondary consideration. This page covers the core security mechanisms used in video hosting: encryption standards, access control types, authentication methods, and what compliance obligations a hosted video platform needs to support.
AES-128 is the encryption standard used to protect video content during delivery. It encrypts the video stream at the segment level, meaning each chunk of video that travels from the server to the viewer's device is encrypted individually. A viewer who intercepts a segment without the correct decryption key receives unusable data rather than watchable video. AES encryption protects content in transit. It does not protect a downloaded file: if a viewer can download the source file, encryption of the stream provides no protection once the file is on their device. This is why AES encryption is paired with controls that prevent direct file access, such as signed URLs and token-based authentication, rather than used as a standalone protection mechanism. Cinema8, a secure video hosting platform, delivers all content with AES-128 encryption over HLS, preventing stream interception without exposing downloadable source files.
A playback token is a time-limited credential that authorises a specific viewer to access a specific video for a defined period. When a viewer requests a video, the hosting platform generates a token tied to that viewer's session. The token expires after a set time, typically minutes, meaning a URL shared after expiry produces no playback. Token-based authentication is the mechanism that makes expiring links work. The link itself does not contain the video. It contains the parameters needed to generate a token, which the platform validates at the point of playback. Without a valid token, the video player returns an error rather than content. This approach is more secure than a static URL because the same link cannot be reused indefinitely or shared to unauthorised viewers after the token expires. For content with a defined audience and a defined access window, token-based authentication is the most practical access control mechanism available.
Domain restrictions prevent a video from playing outside a defined list of approved websites or applications. If the embed code is copied and placed on an unauthorised domain, the player loads but the video does not play. This protects against content redistribution through unauthorised embedding without requiring the viewer to authenticate. IP restrictions limit playback to requests originating from defined IP address ranges. They are most commonly used in corporate environments where all employee devices share a known IP range, or in regional licensing contexts where content must only be accessible from specific geographies. IP restrictions are less suitable for distributed or remote workforces where employees connect from variable IP addresses. The two controls serve different threat models. Domain restrictions address the risk of unauthorised redistribution. IP restrictions address the risk of access from outside a defined network environment. Cinema8's security controls support both, applied independently or in combination at the asset or folder level.
Single Sign-On connects video access to an organisation's existing identity provider, such as Okta, Azure AD, or Google Workspace. A viewer attempting to access a restricted video is authenticated against the identity provider before the player loads. If the viewer does not have an active account in the identity system, access is denied without requiring any action from a platform administrator. SSO is the access control model that scales most cleanly with organisational change. When an employee leaves and their account is deactivated in the identity provider, their access to SSO-gated video is revoked automatically. This removes the manual revocation step that password-based and link-based access controls require. SSO also produces viewer-level analytics tied to verified identities, which is the data model needed for compliance reporting. A completion record linked to an authenticated user identity is defensible in an audit context. A completion record linked to an anonymous session is not.
GDPR applies to video hosting when the platform processes personal data about viewers who are located in the EU or UK. Viewer-level analytics such as watch time, engagement events, device data, and IP addresses are personal data under GDPR when they can be linked to an identified individual. A GDPR-compliant video hosting platform needs to process this data under a lawful basis, retain it only for as long as necessary, provide mechanisms for data subject access requests, and store data in a way that meets transfer requirements when servers are located outside the EEA. For organisations subject to GDPR, the hosting platform is a data processor, and the organisation is the data controller. This relationship should be documented in a data processing agreement. Cinema8 is ISO 27001 certified for information security management and processes viewer data in line with GDPR requirements. Its security documentation covers data processing, retention, and transfer obligations for enterprise customers.
Cinema8 is a secure video hosting platform with access controls covering AES-128 encrypted delivery over HLS, token-based playback authentication, domain and IP restrictions, SSO integration with major identity providers, private and expiring links, and viewer-level permissions applied at the asset or folder level. These controls apply independently or in combination, allowing organisations to match the security model to the sensitivity of the content rather than applying uniform settings across the entire library. Cinema8 is ISO 27001 certified for information security management, ISO 9001 certified for quality management, and BESA accredited. It scales from self-serve plans through to enterprise teams with SSO, domain restrictions, and unlimited seats.
During travel restrictions, Cinema8 proved valuable as a tool. Its platform offered straightforward yet complete tools, allowing us to give virtual demonstrations of our solutions in a secure and efficient way.
Jay Yalung
Art Director, Marketing and E-Commerce / Leica Geosystems
Cinema8 software engaged and motivated students with 360-degree videos at the Tate Gallery, featuring past student projects. Staff support was responsive and helpful with training. A valuable tool for educational institutions.
Chi-Ming Tan
Unit Lead Lecturer LCCA / London College of Contemporary Arts
Cinema8 has been instrumental in compiling all of the videos for a research project on employment for the blind or visually impaired, by offering an easy-to-use web-based platform for building Interactive Videos.
Sarah Moody
Communications Coordinator / Mississippi State University
Cinema8 was chosen for its ease of use and ability to create interactive videos through an intuitive interface. The team received great support and reasonable pricing. leading to a renewal of their partnership. Cinema8's support helped them meet project deadlines.
Michel Sohel
Media Consultant / Eastern Michigan University
Starter
$12
per month billed annually
Everything in Free, plus:
Recommended
Pro
$24
per month billed annually
Everything in Starter, plus:
Pro Plus
$84
per month billed annually
Everything in Pro, plus: