Security at DRM-X

Designed for an ISO/IEC 27001-managed service.

DRM-X 6.0 is being engineered to support a certifiable information security management system across the control plane, content operations, key custody, license delivery, customer console, and supporting cloud services.

Certification statusISO/IEC 27001-ready design in progress. DRM-X is not currently claiming ISO/IEC 27001 certification.

Identity and access

Tenant/project scope, least-privilege roles, short-lived sessions, hashed API keys, controlled service accounts, and audited privileged actions.

Keys and credentials

Wrapped content keys, production KMS enforcement, secret references, server-only Playback Grant signing, versioned key IDs, and no clear-key browser workflow.

License delivery

Signed grants, fixed algorithm validation, route-bound DRM claims, bounded challenges, per-tenant/provider rate limits, timeouts, and opaque provider responses.

Content management

Tenant-aware content metadata, dedicated key sets, controlled packaging jobs, evidence-backed validation, and separated demo/production assets.

Audit and monitoring

Request correlation, non-secret token fingerprints, security events, append-only database guards, UTC timestamps, and evidence-oriented dashboards.

Secure engineering

Documented trust boundaries, production configuration gates, dependency and image scanning targets, SBOM/release evidence, and controlled change workflow.

Certification path

Product controls are one part of the ISMS.

Certification also requires an approved scope, asset inventory, risk treatment plan, Statement of Applicability, policies, named control owners, training, supplier assurance, incident and continuity exercises, retained evidence, internal audit, management review, and an independent certification audit.