Brightcove Security and Compliance

Brightcove Security and Compliance

Worlds Most Trusted Streaming Platform

Certifications

ISO 27001

As a global organization that serves thousands of customers around the world the equivalent of hundreds of years of video a day, securing our customer data is mission critical and information security is an area Brightcove takes very seriously.

ISO 27001 is an international standard for information security management systems (ISMS), outlining a framework to help organizations protect their information assets. It provides a systematic approach to managing sensitive company information, ensuring its confidentiality, integrity, and availability through risk management and continuous improvement. Brightcove undergoes an annual audit to maintain its certification for compliance with ISO/IEC 27001:2022.

CSA STAR Level 1

CSA STAR Level 1 is a registry for cloud service providers that demonstrating adherence to the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) and a commitment to security best practices. Brightcove is on the CSA STAR registry as a Level 1

A secure and reliable platform built for leading global organizations

Whether your videos are for general external audiences or private internal ones, Brightcove makes it easy to securely deliver high-quality video experiences to any device. With support for the most sophisticated studio-grade content protection and advanced security features like watermarking, domain and IP restrictions, and geo-restriction, Brightcove helps you deliver even the most sensitive video content with security, control, and confidence.

Cloud computing shared security model

Brightcove’s online video platform is a Software-as-a-Service (SaaS) platform built to provide both a secure and reliable foundation for a broad set of capabilities that help customers scale and manage their video content. Customer data is hosted in a multi-tenant environment, with segregation integrated into the application at the customer level. Brightcove offers the option to only store master videos in a region selected by the customer. For example: If a customer is tied to us-east-1 their masters won’t leave that region. Brightcove follows a secure platform development model including enforcing encryption standards, employee compliance with documented data security protocols, and user authentication.

Role-based access control

Brightcove implements strong user access control measures for our customers. Our studio allows customer administrators to delegate administration tasks via a “user admin” role, which allows limited user-related tasks such as the creation or deactivation of users. Administrators can configure the Brightcove Studio so that user access can be restricted to specific modules (Media, Publishing, Advertising, Analytics). This can be restricted based on an individual user’s role to limit who has access to change players, media files, metadata, and policies.

Trust and security

Security Documentation

Contact Sales to request access to our security package for comprehensive security documentation, including Brightcove’s ISO/IEC 27001:2022 certification, and more – all conveniently located in one place.

Report a vulnerability

If you believe you have found a security issue in a Brightcove product, please submit the report to our Security team by emailing [email protected]. Brightcove does not have a Bug Bounty Program in place.

READY TO GET STARTED?

Contact us to learn how we can enhance your video marketing efforts and help generate the results and ROI you need.