Skip to content
Planning a business-critical broadcast? Business-critical broadcast? Talk to a video expert

Security Policy

Updated May 13, 2026

Security is foundational to everything we build at Castr. Protecting our broadcasters’ content, their data, and the integrity of their broadcasts is a responsibility we take seriously every day.

This page describes how we keep the platform safe, how you can help us, and what we expect from everyone who uses Castr.

How we protect the platform

We rely on a layered set of measures across our infrastructure, our application, and the tools we put directly into our broadcasters’ hands.

Infrastructure and availability

We deliver every stream through a multi-CDN network that includes Akamai, Fastly, and Amazon CloudFront, so a problem with any single provider never silences a live broadcast.

  • More than 40 global ingest locations route each broadcaster’s encoder to the nearest healthy edge, shrinking both the failure surface and the attack surface.
  • Redundant streaming infrastructure backs a 99.9% uptime commitment for the kind of events where downtime is unacceptable.
  • DDoS mitigation is built into the network edge that fronts our dashboard and streaming endpoints, absorbing volumetric attacks before they reach our application.
  • We continuously monitor streaming performance, application health, and platform traffic so anomalies are caught and addressed quickly.

Application security

  • All traffic to Castr is encrypted in transit over HTTPS, and our HSTS configuration ensures modern browsers never connect to us over an unencrypted channel.
  • We set browser-side security headers across our properties — including protections against clickjacking, MIME-type sniffing, and referrer leakage — to reduce the surface area available to common web attacks.
  • Content Security Policy directives on our dashboard prevent it from being embedded in unauthorized iframes, a frequent clickjacking vector for SaaS applications.
  • Production systems and customer data are accessible only to authorized Castr personnel with a documented operational need.

In your dashboard

  • Password protection lets you lock any stream or video so only the people you invite can watch.
  • Geo-restrictions let you allow or block playback by country or region to honor licensing and broadcast rights.
  • Domain whitelisting keeps your stream from being lifted and re-hosted on sites you didn’t approve.
  • Watermarking burns customizable branding into your video to deter unauthorized recording and re-distribution.
  • Paywall enforcement ties playback to verified payment, turning your security perimeter into a revenue layer for premium content.

For your data

  • We operate under a published Privacy Policy and GDPR Policy.
  • We honor requests from any Castr user to access, correct, or delete the personal information we hold about them, regardless of where they live.
  • We don’t sell personal information — yours or your viewers’. Full stop.

Running a formal security review for a larger rollout? Enterprise video streaming covers how Castr scopes controls, data handling, and procurement documents with your team before purchase.

Your contribution to security

If you have sharp eyes for security — whether you’re a researcher, a broadcaster who noticed something off on your account, or a viewer who spotted something suspicious in a stream — we want your help, and we’ll treat your report with discretion.

Reporting a vulnerability

If you believe you’ve found a security issue in our website, dashboard, player, API, or supporting infrastructure, please report it to us at [email protected].

When you report, please include:

  • A description of the issue and where you found it
  • Steps to reproduce, or a working proof of concept
  • The potential impact as you understand it
  • The name or handle you’d like to be credited under, if any

We acknowledge every report we receive, keep you informed as we investigate, and aim to resolve confirmed issues as quickly as their severity warrants.

Prohibited actions

To keep Castr safe for every broadcaster and every viewer, the following activities are not permitted on our platform or against our infrastructure:

  • Broadcasting content you don’t have the rights to, including pirated, infringing, or otherwise unauthorized material.
  • Using Castr to facilitate or commit illegal activity, including fraud, doxxing, harassment, or the coordination of criminal acts — whether or not the activity directly involves a stream.
  • Bypassing or attempting to bypass access controls — passwords, geo-restrictions, domain restrictions, paywalls, or watermarking — on your own content or anyone else’s.
  • Manipulating Castr’s platform mechanics, including creating fake or duplicate accounts to abuse free trials, inflating viewer counts with bots, gaming referral or promotional programs, or otherwise misrepresenting activity on the platform.
  • Misusing customer or viewer data, including scraping, harvesting, or repurposing data accessed through the platform.
  • Spamming, phishing, or harassing other Castr users, broadcasters, or viewers.
  • Distributing malware, illegal content, or material that incites harm through streams hosted on Castr.
  • Attacking Castr infrastructure, including DDoS, brute-force attempts, or anything intended to degrade service for other broadcasters.
  • Unauthorized scraping or crawling of our site, dashboard, APIs, or streaming endpoints outside the integration points we publish.
  • Reverse-engineering or tampering with Castr’s player, encoder integrations, or any other component of the platform, except where applicable law allows.

Violations are addressed under our Terms of Service and Content Restrictions and may result in account suspension, termination, or referral to rightsholders or law enforcement.

If you have any inquiries, contact us.