DRM video protection for your streaming service
DRM video protection on Flicknexs: signed URLs, geo-fencing, watermark and referer lock ship standard; Widevine, FairPlay and PlayReady on request.
Flicknexs protects video with signed playback URLs, country rules, per-title access rules and a player watermark from the admin, and arranges studio-grade DRM through the delivery layer on request for enterprise customers.
Trusted by industry leaders
50+ OTT platforms powered by Flicknexs
Quick answer: DRM video protection encrypts each stream and hands the decryption key only to a licensed, verified player, so a copied file plays nowhere. Flicknexs ships signed URLs, geo-fencing, per-title access rules and a logo watermark on every plan, and arranges Widevine, FairPlay and PlayReady through the delivery layer on request as part of an enterprise plan.
Flicknexs provides drm video protection as part of its white-label OTT platform. Flicknexs protects video with signed playback URLs, country rules, per-title access rules and a player watermark from the admin, and arranges studio-grade DRM through the delivery layer on request for enterprise customers.
Why DRM video protection is a layered question, not a checkbox
A streaming catalog is worth exactly as much as the rights attached to it, and every rights holder who licenses you a film, a match or a course will ask the same question before signing: how do you stop the file from leaving? For most operators the honest answer is layered. You stop the casual copy with expiring links and a country check, you make a ripped copy traceable with a visible mark, and for the small set of titles where a studio contract demands it, you add encryption with a license server. That last layer is what people mean by DRM, and it is the layer most often oversold.
Flicknexs treats those layers separately because they cost different amounts and solve different problems. Signed URLs, geo-fencing, per-title access rules and the player logo watermark are in the platform code and switch on from the admin without any extra contract. Encryption with Widevine, FairPlay and PlayReady is not in the platform code. It is arranged through the delivery layer on request as part of an enterprise plan, scoped title by title with the rights holder requirement in hand. This page says plainly which is which so you can answer a distributor without guessing.
The technical standard behind browser DRM is the W3C Encrypted Media Extensions specification, which defines how a web player asks a content decryption module for a key and how that module talks to a license server. The Apple developer documentation for FairPlay Streaming and the Android developer documentation for Widevine cover the native app side. Reading those three sources before you sign a distribution deal is worth an afternoon: they explain why the same protected stream needs three key systems, why some older TVs cannot play the highest security level, and why DRM never stops a camera pointed at a screen.
What protects a Flicknexs stream, layer by layer
Seven of these eight rows are in the platform code today and switch on from the admin. The last row is the encryption layer, and it is arranged through the delivery layer on request.
Signed URLs
A storage setting turns on signed playback URLs with a time-to-live, so every link expires.
Geo-fencing
Block or allow countries platform-wide and per title, checked when playback is requested.
Per-title access rules
Each video, episode or audio item carries its own plan, purchase and free-preview rules.
Logo watermark
The player overlays your logo with a chosen position, opacity and click-through link.
Referer protection
Hotlink protection at the delivery layer rejects requests from unapproved sites, configured on request.
Adaptive HLS
Streams are packaged as adaptive-bitrate HLS with a master playlist per title.
Device logging
Analytics records the devices and platforms each account uses for playback sessions.
DRM on request
Widevine, FairPlay and PlayReady arranged through the delivery layer as part of an enterprise plan.
Source: Flicknexs platform documentation and architecture specification, 2026-09-03.
How DRM video protection works on Flicknexs
Protection happens at three points: when the admin decides who may watch, when the player asks for a stream, and when the delivery layer serves the segments. Here is what each piece does.
The admin decides entitlement before any URL exists
Every title in the Flicknexs admin carries access rules: which subscription plans include it, whether it is sold per view, how many free-preview minutes a visitor gets, and which countries are blocked or allowed. When a viewer presses play, the platform checks the account against those rules first. A viewer who fails the check never receives a playback URL, so there is nothing to copy. This is the cheapest and most effective layer, and it is on every plan.
Signed URLs make every playback link temporary
With the signed-URL flag turned on in storage settings, the platform issues a playback URL that carries a signature and an expiry. The time-to-live is a number you set. After it passes, the same link returns a refusal from the delivery layer. A viewer who copies the link out of the browser and pastes it into a forum has handed out something that dies in minutes, not a permanent door into your library.
Geo-fencing refuses playback outside licensed territory
The platform looks up the viewer country from the request IP through a geolocation service and compares it with the platform-wide block list or allow list, then with the per-title lists on that video, series or audio item. A blocked viewer gets a refusal message rather than a stream. Rights holders who license by territory usually accept this as the enforcement they asked for, provided you also explain the VPN limit covered further down.
The logo watermark marks what a screen recorder captures
In player settings you upload a logo, choose a corner or center position, set its opacity and add a link. The player draws it over the video on web and in the apps. It is a visible brand mark, not an invisible per-viewer identifier, so it does not tell you which subscriber recorded a clip. What it does is make a recording obviously yours when it turns up on a social feed, which is what takedown requests need.
Adaptive HLS delivery is the packaging DRM attaches to
Transcoding produces an adaptive-bitrate HLS output with a master playlist listing each rendition. The player picks a rendition to match the connection. When encryption is arranged for a title, the delivery layer encrypts those same segments and points the player at a license server for Widevine, FairPlay or PlayReady. Because HLS is already the platform format, adding the encrypted variant does not change how you upload or publish.
DRM itself is arranged through the delivery layer on request
The Flicknexs platform code does not contain a license server, key management or content decryption module integration. For customers on an enterprise plan whose contracts require encryption, Flicknexs arranges DRM through the delivery layer on request. The scoping covers which titles, which key systems, which of your apps must play them and the license terms of the DRM providers. Until that scoping is agreed, no title is encrypted, and the page will never tell you otherwise.
How to set up video protection in the Flicknexs admin
Work through these five steps in order on a test title first. Each one is reversible from the same screen.
- 1
Turn on signed URLs and choose a time-to-live
Open Settings, then Storage. Switch the signed-URL flag on and enter a time-to-live in seconds. A short window such as a few minutes suits films and live events; a longer window suits long lectures where a viewer may pause for an hour. Save, then open a test title in a private browser and confirm playback still works.
- 2
Set the platform-wide country rules
Open Settings, then Geo-fencing, and switch it on. Decide whether you run a block list or an allow list. Distributors with a licensed territory list usually prefer allow. Enter the countries, save, and check the refusal message a blocked viewer will see. That message is the one your support desk will be asked about, so make it plain.
- 3
Add per-title rules for the sensitive titles
Open a video, series or audio item and find the access section. Assign the plans that include it, set a pay-per-view price if it is sold separately, enter free-preview minutes, and add title-specific block or allow countries if the license for this title differs from your platform default. Per-title lists sit on top of the platform list; they never loosen it.
- 4
Upload the player watermark
Open Settings, then Player, and upload a logo file with a transparent background. Pick the position, usually a lower corner, and an opacity low enough not to distract but high enough to survive a compressed screen recording. Add the link that a click on the logo should open. Play a title on web and in a device app to confirm the mark shows.
- 5
Request referer protection and, if required, DRM
Two protections live at the delivery layer rather than in the admin. Ask the Flicknexs team to configure hotlink protection so only your domains and apps can request segments. If a rights contract requires encryption, send the title list and the contract clause; the enterprise team will scope Widevine, FairPlay and PlayReady through the delivery layer and quote it.
Limits, tradeoffs and what DRM video protection does not do
These are the questions a rights holder or a lawyer will ask. The honest answers save you a renegotiation later.
DRM is not built into the platform code
There is no license server, key management or decryption module in the Flicknexs codebase. Encryption with Widevine, FairPlay and PlayReady is arranged through the delivery layer on request as part of an enterprise plan, and it is scoped and quoted per customer. Pages or salespeople who tell you otherwise are wrong. Operators on F1 through F3 get the signed-URL, geo-fencing, access-rule and watermark layers; encryption is an enterprise conversation.
The watermark is a logo, not a viewer identifier
The overlay is your brand mark with a position, opacity and link. It is the same for every viewer. It does not embed a per-session code, so it cannot tell you which account leaked a recording, and Flicknexs does not describe it as a forensic mark. If a studio contract demands per-viewer marking, raise that in the same enterprise scoping conversation as encryption, because it is a delivery-layer capability, not a platform feature.
No protection stops a camera or a capture card
Encryption stops the file from being decrypted outside a licensed player. It does not stop a phone pointed at a television, and on lower security levels it may not stop a capture card between a set-top box and the screen. Signed URLs and geo-fencing narrow who can press play. None of these layers make piracy impossible; they make it slower, riskier and easier to take down.
Geo-fencing is by country and can be fooled by a VPN
The country check uses the request IP. A viewer on a VPN that exits inside an allowed country will pass. Rules are per platform and per title only; there is no separate rule set per device app, so a country blocked on web is blocked on Android TV too. Most license contracts accept IP-based enforcement as commercially reasonable, but read your clause before promising more.
Referer protection needs a request, and it has a list to maintain
Hotlink protection is configured at the delivery layer rather than from the admin, so it is set up on request. Every domain and app that should play your video must be on the approved list, and a new marketing microsite that embeds the player will fail until it is added. Keep the list in your launch runbook alongside the DNS records.
A film distributor working through the layers
A worked example for an independent film distributor with a catalog of two hundred titles licensed across a dozen territories.
The distributor holds streaming rights for most of its catalog in twelve countries and for a smaller set of forty recent titles in only three. On an F2 plan with web, Android and iOS apps, the team switches signed URLs on with a ten-minute time-to-live, sets the platform allow list to the twelve licensed countries, and adds a tighter three-country allow list on each of the forty restricted titles. Nothing else changes for uploads or publishing, and playback on a test account in a blocked country returns the refusal text they wrote.
The player watermark goes on at low opacity in the bottom right with a link to the storefront. When a clip from a new release appears on a social platform two weeks after launch, the logo is visible in the recording, and the takedown request is accepted the same day because ownership is obvious. Analytics shows the account that watched the film had six logged devices across three platforms, which is enough for support to reset that password and ask the subscriber to confirm the devices.
One studio licensor then requires encryption on its eight titles before renewal. The distributor moves to an enterprise plan and asks Flicknexs to arrange Widevine, FairPlay and PlayReady through the delivery layer for those eight titles only, listing web, Android and iOS as the apps that must play them. The rest of the catalog stays on the standard layers. Scoping produces a per-title list, the key systems per app and a quote; the distributor sends the licensor that document as evidence and renews.
Pre-launch checklist for protected titles
Run this list on a staging title before the catalog goes live.
- Signed-URL flag is on in storage settings and the time-to-live matches the longest realistic pause on your content.
- A copied playback link pasted into a private browser after the time-to-live returns a refusal, not a stream.
- Platform geo-fencing is on and the allow or block list matches the territory schedule in your license agreements.
- Every title with a narrower territory has its own per-title country list, checked against the contract for that title.
- A test account routed through a blocked country sees the refusal message you wrote, on web and in one device app.
- The player watermark is visible in a compressed screen recording of a dark scene at your chosen opacity.
- Referer protection has been requested and every domain and app that embeds the player is on the approved list.
- Titles whose contracts require encryption are listed, with the apps that must play them, for the enterprise scoping.
- Support staff know how to read the logged devices report and what to do when one account shows many devices.
- Free-preview minutes on each title are set deliberately, because a preview plays before any purchase check.
How protection interacts with the device apps and your revenue
Protection is not a separate product; it rides along with the apps and the paywall you already run.
The standard layers behave the same across web, Android, iOS, Android TV and Fire TV because entitlement, signed URLs and geo-fencing are decided by the platform before the app receives a stream. The watermark is drawn by the player in each app. When encryption is arranged for a title, the app side matters: each key system belongs to a device family, so the enterprise scoping names which apps must play the encrypted titles and confirms coverage per app rather than assuming it. The video CDN page explains what the delivery layer does with signed requests and referer checks, and the geo-fencing page covers the country rules in full detail.
On the revenue side, protection is what makes the paywall mean something. A pay-per-view title with a rental window only earns if the stream cannot be lifted and reshared, so signed URLs and the access rules on the video paywall page are the same feature seen from two angles. Subscribers who share an account show up as many logged devices in the video analytics page reports, which is the signal to act on before revenue leaks. If a licensor requires encryption on a title you sell per view, the enterprise scoping should confirm that purchase flow on each app before you announce the release.
Which plan includes DRM
Standard layers
Signed URLs, geo-fencing, per-title access rules and the player logo watermark are part of every plan, from the web-only Professional plan through F4 Enterprise. Referer protection at the delivery layer is configured on request on any plan. Encryption with Widevine, FairPlay and PlayReady is not a line on our pricing page; it is arranged through the delivery layer on request as part of an enterprise plan, and the cost depends on the titles, the key systems and the DRM provider license terms, so it is quoted during scoping rather than listed.
Pricing & billing
F4 Enterprise includes 2 TB of storage and 20 TB of bandwidth monthly and adds dedicated support to everything in F3; Samsung, LG, Roku and Apple TV apps are add-ons on any plan. See our pricing page for current plan and pricing details. That is the plan where DRM scoping normally starts, because the same plan carries the widest app coverage. Plans are flat fees and Flicknexs takes no commission on your revenue; payment-gateway fees are between you and your gateway. See our pricing page for current plan and pricing details.
Annual savings
Yearly billing on F1 to F4 costs less per month than monthly billing; see our pricing page for current plan and pricing details. Whichever plan you pick, the protections that are in the platform code cost nothing extra and switch on from the admin the day you sign up.
Conclusion: what to do next
Already on Flicknexs
If you already run on Flicknexs, open storage settings and confirm the signed-URL flag is on, then check geo-fencing against your current license schedule. Those two changes take a few minutes and close the two most common gaps we see in support tickets. Upload the player watermark next. If any contract requires encryption, send the title list to your account contact and ask for the enterprise scoping conversation.
Choosing a platform
If you are choosing a platform, ask every vendor the same three questions: which protections are in the product code, which are arranged through their delivery partner, and which key systems each of their apps can play. Insist on written answers. A vendor who says DRM is built in should be able to show a license server setting in the admin. Flicknexs will show you the four standard layers in the admin and a scoping document for the rest.
Before a rights call
Read the companion pages before a rights conversation. The geo-fencing page covers country rules, VPN limits and the per-title lists in depth. The video CDN page explains signed requests, referer checks and the bandwidth allowance per plan. The video paywall page shows how rental windows and pay-per-view prices depend on these protections. Together they give you the complete answer a distributor expects.
Frequently Asked Questions
Everything you need to know about DRM on Flicknexs.
There is no DRM line on our pricing page. Encryption with Widevine, FairPlay and PlayReady is arranged through the delivery layer on request as part of an enterprise plan, and the cost is quoted during scoping because it depends on title count, key systems and provider license terms. The standard protections cost nothing extra on any plan.
Flicknexs arranges Widevine, FairPlay and PlayReady through the delivery layer on request for enterprise customers. None of the three is built into the platform code, so no title is encrypted until scoping is agreed. The standard protections that are in the code are signed playback URLs, geo-fencing, per-title access rules and a player logo watermark.
Each key system belongs to a device family, which is why three systems exist. When encryption is arranged, the enterprise scoping lists the apps that must play the encrypted titles and confirms coverage per app rather than promising all of them. The standard layers, entitlement, signed URLs, geo-fencing and the watermark, behave the same in every app.
Every plan includes the signed-URL flag with a time-to-live, platform-wide and per-title geo-fencing, per-title access rules with plan, pay-per-view and free-preview settings, and the player logo watermark. Referer protection at the delivery layer is configured on request. For most independent catalogs these layers satisfy the license clause without encryption.
No. It is a visible logo overlay with a position, opacity and link that is the same for every viewer. It marks a recording as yours, which speeds up takedowns, but it does not identify the subscriber who recorded it. Per-viewer marking would be a delivery-layer capability to raise in the enterprise scoping conversation.
When the flag is on, each playback URL carries a signature and an expiry set by the time-to-live in storage settings. After expiry the delivery layer refuses the request. A link copied out of the browser and posted elsewhere stops working within the window you chose, so a leaked URL is not a permanent door.
Yes, that is how scoping normally works. You list the titles whose contracts require encryption and the apps that must play them; those titles are arranged through the delivery layer and the rest of the catalog stays on the standard layers. Most distributors encrypt a small studio-licensed subset rather than everything.
Many territory clauses accept IP-based country enforcement as commercially reasonable, but geo-fencing and DRM answer different questions. Geo-fencing decides who may start playback; DRM stops the file from being decrypted elsewhere. Read the exact clause, and if it says encryption, plan the enterprise scoping rather than relying on country rules.
The playback request is refused before any stream URL is issued and the viewer sees the refusal message set in the admin. Nothing is downloaded. Because the check runs on the platform, the same refusal appears on web and in the device apps, so support gets one consistent report rather than a different symptom per app.
Every plan includes bandwidth, and our pricing page states the allowance for each plan. Encrypted segments are served like any other, so the traffic counts against the same allowance. The DRM arrangement itself is quoted separately during enterprise scoping; our pricing page lists no DRM figure.
Yes. Access rules are per title, so a free title can sit outside any plan with free-preview covering its full length. Geo-fencing and the watermark still apply unless you change the per-title country list. Signed URLs are a platform-wide flag and stay on, which is harmless for a free title.
It depends on the title count, the key systems and the DRM provider license process, so Flicknexs gives a timeline in the scoping document rather than a standard figure. Prepare the title list, the contract clause and the app list in advance; that removes most of the back and forth before work begins.