Security
Aggregates only. Nothing else to protect.
The safest data is the data you never hold. PiracyIntel keeps a count of watchers per title and market, and nothing that could identify a person or reproduce a title.
What we hold
Three facts before the questionnaire.
No content, ever
We measure movement, not media. No film, episode, clip or file is stored, cached or served by any PiracyIntel system.
No personal data
Signals are aggregated to title and market before they reach the console. There is no per-person record to hold, and none is collected.
Aggregate demand only
What remains is a count of watchers per title, per market, per day. That is the whole dataset, and it is what the console, the reports and the API read.
Controls
How the service is run.
- Hosting
- The console and the API run on Cloudflare at the edge, with the data store in a European data centre we operate. Backups are encrypted and kept for thirty days.
- Access
- Every seat is a named login. Console workspaces are isolated per client; a key or a session cannot read another workspace. Enterprise adds single sign-on over SAML or OIDC.
- Transport
- TLS everywhere, HSTS on every hostname, and a content security policy on this site that allows nothing but itself.
- Keys
- API keys are scoped to read, bound to one workspace, and rotated from the account menu. Rotation revokes the old key at once.
- Staff
- Operator access to production is by hardware key, logged, and limited to the people who run the service.
- Retention
- Demand history is kept for the depth we publish: four years by market, 90 days daily per title. Lead-form submissions are kept only as long as the conversation.
Enterprise
Security review and DPA.
Enterprise plans include a security review with your team, a data processing agreement, and a data-provenance memo for compliance desks that run due diligence before a purchase.
Questionnaires, the DPA and the provenance memo go to
contact@piracyintel.comOr request a briefing and ask for the review in the message.