Workflow

What Does Media Security Look Like in Post-Production?

Chris Salters
Owner + Lead Editor

Chain of Custody, Access Control, and Backup Discipline

Chain of custody, access control, and backup discipline are three checks on safeguarding footage. Chain of custody protects footage that can't be replaced, access control ensures it moves through only approved hands, and backup discipline accounts for storage that can't be allowed to fail. A post-production vendor that's serious about security treats all three as one connected process.

How Does Chain of Custody Work From Ingest Through Delivery?

Chain of custody starts the moment a card comes off a camera and enters the dailies process, and doesn't end until final delivery. At ingest, footage is copied with proper checksum-validated offloading software like Hedge Offshoot, Pomfort Silverstack or DaVinci Resolve's Clone Tool. These tools ensure that files are cloned bit for bit and will notify users when something doesn't match so that data corruption and missing footage are minimized across hard drives.

Speaking of drives, production drives, backup drives, and shuttle drives need the same paper trail as digital transfers. A proper vault system ensures that each drive gets logged in on arrival, checked out to a specific person for a particular purpose, and then checked back in. Drives within the facility should be treated like original camera footage (OCF), encrypted and physically locked down with only secure access for those that need them, when they need them.

Once offloaded to the network, custody moves through organized, logged storage. Editorial relies on proxy workflows for rushes and efficiency, while watermarked dailies are available for stakeholder review, all while keeping camera originals under even tighter security.

During color and conform, the project relinks to only necessary OCF media under controlled access, and finally delivery occurs over an approved secure transfer platform like MASV. All of this with the goal to always be able to show exactly where files have been and who has them.

Who Can Access Project Media, and How Is That Enforced?

Access control means restricting project media to the people working on it, scoped down to the specific assets and asset types each person needs. In practice, that looks like unique user credentials instead of shared logins, and permissions set by role. For example, a mograph or VFX artist needs only the media for specific shots, not every raw card from the shoot.

Workstation access follows the same logic, that only approved users have access, and it goes further by keeping the computer as isolated from the outside world as possible. That may look like editorial accessing media via privileged access network storage with no open internet access.

Let's be real, the internet is a necessary element of modern post-production, so transfers to the open internet are managed through a dedicated workstation that's attached to a demilitarized zone server sitting between the internal network and the public internet. Essentially, the DMZ server acts as a buffer, keeping the internal network from touching the wild west nature of the internet.

Remote collaborators and reviews work through a proxy workflow instead of touching full-resolution originals, which keeps the highest-value files inside the facility environment at all times. Other virtual desktop methods used to remote into workstations, like Jump Desktop or LucidLink, also require unique user credentials for access.

What Backup Redundancy Should a Facility Maintain?

The industry rule of thumb, sometimes called Schofield's Second Law, is that if a file doesn't exist in at least two places, it doesn't exist. In practice that means an original plus at least one backup, stored in a different physical location than the original. For us, once media hits Sawtooth's servers, it's backed up locally and also securely sent to the cloud - three copies in all.

Redundancy also depends on the storage architecture itself. RAID configurations shouldn't be considered a "backup," though they do provide fault tolerance for failed drives. RAID levels are dependent on many factors like drive capacity, number of drives, and throughput, but RAID 5, 6, 10, 50, or 60 all provide post-production storage advantages with varying levels of safety and speed.

Where Does TPN Certification Fit Into This?

Security on its own is often a "take our word for it" conversation. When self-evaluation needs more proof to fall back on, there are third-party groups to verify standards. In the media space, that responsibility primarily rests with TPN, the Trusted Partner Network: a content-security assessment program run by the Motion Picture Association that evaluates a facility against best-known security practices and applies one of two statuses, Blue Shield (self-attested) or Gold Shield (third-party audited).

Most major studios and streamers, including Netflix, now list TPN status among their vendor security expectations. Studios can certainly keep themselves and their clients' data safeguarded without the TPN shield, but that certification provides assurance at a glance. Sawtooth Post aligns itself with TPN practices and is actively pursuing certification.

Simple Asks to Verify Processes

You don't need to understand checksums to verify a facility's process. You need to ask direct questions and listen for specific answers. Ask what software validates file transfers, and expect a named tool. Ask how backups are treated, how many copies exist, and where each one physically lives. Ask whether editorial workstations have open internet access, or whether transfers run through a separate, monitored connection. Ask for TPN status or a security assessment, if the project requires it.

A vague answer to any of these is itself informative. For a post-production vendor you can trust, you should expect specifics, not generalities.

FAQ
Questions + Answers
  • How do you verify a post vendor's security and backup claims?

    Ask for specifics rather than assurances: the name of the offload software used, the number and location of backup copies, and documentation of access controls or TPN status. A vendor with a real process will answer in concrete terms.

  • What are the most common chain-of-custody failure points in post?

    The most common gaps happen at handoffs: ingest without checksums, physical drives that move without logs, and access that isn't revoked when a collaborator finishes their portion of the work.

  • Does insurance cover the schedule delay from lost footage, not just the footage itself?

    Production insurance policies vary widely on this point, and many cover the cost of reshoots but not the cascading schedule and budget impact of a delay. Confirm delay coverage directly with your production insurer rather than assuming it's included.

  • What does TPN compliance require of a post facility?

    TPN requires a documented security management process, including risk assessments, access controls, incident response procedures, and records of prior security testing, evaluated either through self-attestation (Blue Shield) or third-party audit (Gold Shield).

  • What does DMZ mean in a post house's network setup?

    A DMZ, or demilitarized zone, is a server that sits between a facility's secure internal network and the open internet. File transfers route through it, so editing workstations connected to protected storage don't connect directly to the public web.

  • Do you make the cut?