How Filmustage Protects an Unreleased Script

Encryption, access control, forensic watermarking, SOC 2 Type 2, and TPN — what each one actually proves, and where you can verify every claim yourself.

How Filmustage Protects an Unreleased Script

In January 2014, Quentin Tarantino gave an early draft of The Hateful Eight to six people. One of the actors passed it to an agent, and within days a 146-page screenplay was circulating across Hollywood. Tarantino shelved the film and filed a copyright claim seeking damages of more than $1 million.

No firewall failed. No server was breached. A PDF moved from one trusted person to another, and then it kept moving. That is the risk any pre-production platform actually has to answer for — and this article sets out how Filmustage answers it, what our credentials do and do not prove, and where you can verify every claim without taking our word for it.

In short
- Unreleased material leaks through workflow — forwarded files, unaudited shared drives, and stolen credentials used to log in legitimately. Not through exotic attacks
- SOC 2 Type 2 is the independently audited part of our security posture. TPN Blue Shield is a published self-assessment against MPA best practices; TPN states outright that it issues no certifications, and we describe ours accordingly
- Uploaded scripts are never used to train or fine-tune models, on any plan. All AI features run inference-only
- Material is stored on US-based cloud infrastructure , encrypted in transit and at rest
- Forensic watermarking, export restrictions, and PDF lock stamp the name of the person viewing or exporting a script across every page, so any leaked copy is attributable to an individual
- Every statement here is checkable on the Trust Center , in the Help Center , or in the Privacy Policy . The SOC 2 Type 2 report and our yearly penetration test reports are available under NDA

Where scripts actually leak

Unreleased material leaks in three ordinary ways: someone forwards a file they were trusted with, a copy sits in a shared folder nobody has audited in a year, or an attacker signs in with a valid credential and walks through the front door. Perimeter breaches are the rarest of the three, and even those only cause damage because the material inside had no controls on it.

The industry's own data says the same. In April 2026 the Trusted Partner Network — the content security initiative owned by the Motion Picture Association — published the TPN STAR Report, the first analysis of large-scale assessment data across the content supply chain. In the first quarter of 2026, TPN issued more Security Alerts than in the whole of 2025. The recurring weaknesses were compromised credentials, inconsistent multi-factor authentication, insecure cloud configuration, and slow patching. The worst-performing control areas were vulnerability management, cryptography, endpoint hardening, and access management.

TPN president Terri Davies described the finding as a persistent disconnect between how secure organizations believe they are and how their controls perform day to day. That gap, not a shortage of technology, is where pre-release material is lost — which is why the questions worth asking a vendor are operational rather than ceremonial.

Diagram of three script leak paths: forwarded file, unaudited shared drive, and stolen credential
Three routes an unreleased script takes out of a production. Only the third involves anything a firewall would notice.

What SOC 2 Type 2 and TPN actually prove

Two credentials come up in nearly every studio vendor review, and they prove different things.

SOC 2 Type 2 means an independent auditor examined our systems across a period of months and confirmed that controls — access management, monitoring, incident response — operated consistently over that whole window, not on the day of the audit. The report and the letter of attestation are both available on request.

TPN is the Motion Picture Association's content security program. It maintains the MPA Content Security Best Practices and runs the registry studios consult when sourcing vendors. Here is the part worth stating plainly, because plenty of vendors blur it: TPN's own FAQ says it does not certify facilities. It provides self-reporting and assessment functionality, and content owners use that data to reach their own risk-based decisions. Since the questionnaire for MPA Content Security Best Practices v5.3.1, the program runs on four tiers — Blue (self-assessed, published on the platform), Silver (assessed by an accredited third party, with a remediation plan), Gold (all best practices remediated and reviewed by TPN), and Gold Star (best practices plus additional recommendations).

So when any vendor tells you it is "TPN certified," it is describing something the program says does not exist. Our own status is Blue Shield, TPN's label for that entry tier, and what it honestly tells you is narrower and still useful: we answered the MPA questionnaire in full and published those answers where content owners can read them. We renew that self-assessment every year, so what you read on the TPN platform reflects our current environment rather than a snapshot from three years ago. Independent verification comes from two places instead: a SOC 2 Type 2 audit, and penetration testing carried out yearly by an independent security firm, with findings tracked through to remediation. Both reports are available under NDA.

CredentialWhat it provesWho verifies it
SOC 2 Type 2Controls operated consistently across a multi-month observation windowIndependent auditor
TPN Blue ShieldFull answers to the MPA Content Security Best Practices questionnaire, published to content ownersSelf-assessed, published on the TPN platform
TPN Silver / Gold / Gold StarThird-party assessment plus progressive remediation of findingsTPN-accredited assessor, reviewed by TPN
Yearly penetration testAttack scenarios simulated against live systems, findings tracked to remediationIndependent security firm
Key takeaway

A badge answers "was this vendor assessed." It does not answer "are the controls on today." The TPN STAR Report found the industry's weakest areas are exactly the ones needing continuous attention — access management, patching, cryptography. Ask for evidence of the second question, from us and from anyone else.

The security review checklist, and our answers

These are the questions a studio or production security review puts to a software vendor. Run them against anyone you are evaluating. Our answers are below, each with somewhere you can check it.

QuestionFilmustageWhere to verify
Is our material used to train AI models?No. Scripts, images, and video are never used to train, fine-tune, or improve models. This applies on every plan, not only enterprise. AI features run inference-only: content is processed to produce the output you asked for, then never enters a training set.Help Center, Privacy Policy
Where is material stored?US-based cloud infrastructure, encrypted in transit and at rest.Help Center, Trust Center
How is the data classified?Script Data is defined as its own category in our Privacy Policy rather than folded into generic user content.Privacy Policy
Who can export a copy, and is it traceable?Export access is configurable per team, project, and collaborator. Exports and on-screen views carry a forensic watermark with the name of the person viewing or exporting the file.Help Center, live demo
Can we cut off access when someone leaves our production?Yes, and at two levels. Remove the collaborator from the project, or tighten their settings individually — export access and watermarking are configurable per collaborator.Help Center, live demo
Is there independent verification?SOC 2 Type 2 report, letter of attestation, and yearly penetration testing by an independent security firm.Trust Center, under NDA
Can we see the actual controls?Yes. Infrastructure, organizational, product, internal procedure, and data privacy controls are published individually, not summarized.Trust Center, Controls

Traceability: the control most tools skip

Encryption protects a file from strangers. It does nothing about the person who was legitimately given access and then forwarded the PDF — the exact failure mode of 2014. Traceability closes that gap: every copy carries the name of the person who produced it, so a leaked page answers the only question that matters after a leak. Not how did this get out, but who.

In Filmustage this is content protection, configured by a project or organization owner:

  • Export access — allow all exports, restrict to PDF only, or block exports entirely
  • Forensic watermark — tiled across PDF exports and across the on-screen view in the browser. It carries the identity of the person looking at the file or exporting it, next to an optional custom notice such as CONFIDENTIAL — do not distribute . Every copy is therefore individually attributable: two people opening the same script see two different documents
  • PDF lock — restrict editing and copying in exported files, with a password-to-open option available at export time
Filmustage content protection settings showing export access, forensic watermark options and PDF lock
Content protection at project level — export access, watermark surfaces, viewer identity, custom notice, and PDF lock. Anything not overridden here is inherited from the team default.

Settings inherit downward across three levels — team, project, and individual collaborator — and whoever exports can tighten a single export further on top of what the owner set. A director can hold looser settings than a location scout on the same project, without anyone maintaining two versions of the script. Content protection is available on plans from $149/month, or on any paid plan active for three or more consecutive months.

Exported screenplay PDF cover page with a repeating CONFIDENTIAL watermark across the page
The same protection on the way out. The exported PDF carries the tiled notice set by the owner and the name of the person who generated the export, alongside the project name, version, scene count, and export date — so a copy in circulation can be traced to one person and one moment.

The practical consequence is worth stating plainly: there is no such thing as an anonymous copy. A page photographed on a phone and sent to a journalist still carries the name of whoever exported it, and the export date narrows the window to a single day. That changes behavior before it ever has to be used as evidence — people handle a document differently when it has their name on every page.

How to verify all of this yourself

Nothing above should be taken on trust, which is the point of publishing it.

  1. Read the controls. The Trust Center lists every control individually across infrastructure, organizational, product, internal procedures, and data privacy.
  2. Read the commitments. The Help Center security documentation covers encryption, storage, and the model training position. The Privacy Policy defines Script Data and sets out retention.
  3. Request the evidence. The SOC 2 Type 2 report, letter of attestation, our yearly penetration test reports, and our internal policies are available under NDA through the Trust Center, or by writing to [email protected] .
  4. See the controls working. Ask for a walkthrough of content protection on a live project — watermark, export restrictions, and inheritance are quicker to judge in five minutes than in any document.

Bring a script in under your own rules

Upload a screenplay, run the breakdown, and decide who can export it before anyone else sees a page.

The bottom line

A security review is not looking for a logo. It is looking for evidence that controls run every day and that a leaked page can be traced back to a person. The 2026 industry data is blunt about this: the failures are operational — credentials, access, patching — not exotic.

So the honest version of "studio-grade" is boring and checkable. Independent audit where independence matters. Published self-assessment where the standard is a questionnaire, described as exactly that. Watermarking and export control where the real risk is a trusted person with a PDF. We would rather be precise about which of those we have than round it up, and everything above is written so you can confirm it without asking us.


Frequently asked questions

  • Does Filmustage use uploaded scripts to train AI models?

  • What is TPN Blue Shield, and is it a certification?

  • What does SOC 2 Type 2 prove that Type 1 does not?

  • Can a leaked script page be traced back to the person who leaked it?

  • How often is Filmustage tested by an outside party?

  • Where is our material stored, and for how long?


📚
Related reading
- Filmustage Trust Center — the full control list, SOC 2 Type 2 documentation, and the request form for reports under NDA
- Filmustage security — encryption, storage, the no-training commitment, and how payments and authentication are handled
- What is content protection — how forensic watermarks, export access, and PDF lock work, and how the team, project, and collaborator levels combine
- Set content protection for your team — the organization-wide default every project inherits
- Add content protection when you export — tightening a single export, including a password to open the file

From Breakdown to Budget in Clicks

Save time, cut costs, and let Filmustage's AI handle the heavy lifting - all in a single day.

Book a demo

Schedule a call with us to help you optimize your filmmaking flow for your needs.