Security and compliance teams

Reviewed

Protect the record at every interface.

Public records, private workspace information and device evidence use separate access models. Keep each request limited to the caller’s role and the data required for the task.

Integration note: Use this reference with the endpoint contract and your organisation’s security review. Contact DigiBridge to discuss access and operational requirements.

Architecture principles

Reduce exposure before adding cryptography.

Public safe projection

Public routes return a deliberately limited record shape instead of serialising private workspace objects.

Server side authorization

Protected workspace routes validate the user token, workspace membership and write role for each request.

Hashed device secrets

The paired device token is returned once. The stored server value is a hash.

Signed event validation

Simulator ingestion checks the canonical payload hash and Ed25519 signature before acceptance.

Continuity and replay checks

Accepted event hashes cannot be replayed and previous event continuity is enforced.

Truth state labelling

Preview, draft, simulator and planned states remain distinct from final verification.

Verifier API

Unknown and private records share one response.

The resolver only returns records that pass the active approved preview gates. Every other state receives the same generic HTTP 404 response, so the API does not confirm the existence of a private record.

Public resolver behaviour

  • Only approved public preview fields are projected
  • Internal workspace identifiers are not returned
  • Raw evidence and raw manifests are not returned
  • Inactive record existence is not disclosed

Device interface reference

Validate the device and the signed payload.

A successful ingest means the API accepted an event from a currently paired simulator device after validating its hash, signature and chain position. It does not establish human authorship or production device integrity.

Pairing and revocation

Short lived codes pair a simulator device. Revocation blocks future sessions and ingestion.

Signature and chain checks

Canonical hash, Ed25519 signature, replay state and previous event continuity are checked.

Creator permissions

Recording scope, permissions and device setup are explained in the Mac app workflow.

Privacy by boundary

Keep creative source material outside evidence collection.

Excluded evidence categories

  • Source audio, video, stems and masters
  • Creative project files and private folder contents
  • Raw keystroke text, passwords and lyrics
  • Prompts, scripts and private typed content
  • Screenshots and screen recordings
  • Raw file names and local paths

AI review controls

Separate analysis permission from recording permission.

The planned film verification service analyses bounded process evidence. Recording consent alone does not authorise AI processing. A security review should cover permission, current account access, the information sent for analysis and the handling of withdrawal before that service is connected.

An analyst with no control tools

The verification agent is designed to read authorised evidence. It must not operate creative software, browse private files or change original records.

References and review

Findings must refer to the evidence examined and retain their method and version. Model output alone cannot confirm an incident or impose a penalty.

Limited processing scope

The intended analysis input uses permitted aggregates and opaque references. Source media, typed content, names, local paths and account email do not belong in model requests.

Availability and contractual evidence

The public v1 API does not expose AI processing. Confirm provider, region, retention, deletion and operational terms for the actual service before approving a wider integration.

Engineering references

Use established engineering references.

API threat modelling is informed by the OWASP API Security Top 10. Secure development planning can also draw on the NIST Secure Software Development Framework. These are design references only. DigiBridge does not claim OWASP or NIST certification.

Authorize at the object boundary

Validate both the caller and the workspace, asset, project, session or device they are attempting to access.

Minimise public responses

Return a dedicated public schema instead of removing a few fields from an internal object.

Fail without disclosure

Use the same inactive response for unknown and intentionally private public identifiers.

Preserve response meaning

Display the status and verification fields returned by the endpoint alongside the relevant record.

Integration review

Agree the requirements for your integration.

Questions for your security review

  • Which security evidence does your procurement process require?
  • Does the integration need organisation credentials or only public lookup?
  • What request volume and service expectations need an agreement?
  • Which tool versions and recording permissions does your workflow use?
  • How will your interface display current publication and verification status?
  • Who can review disputed findings and record corrections?

DigiBridge help

FAQs, support and sales

What can we help with?

Find a quick answer or leave a message for our team. Replies appear here.