Legal

Security

Enterprise practices we use to protect MSOOCast platform workloads, customer data, and broadcast operations.

Last updated: July 19, 2026

Our security commitment

MSOOCast builds broadcast operating software for media companies, FAST operators, OTT platforms, and hospitality networks. Protecting customer content, advertising workflows, and operational data is core to how we design and run the platform.

This page summarizes our security practices. For enterprise security questionnaires, penetration-test summaries under NDA, or architecture reviews, contact contact@msoocast.com.

Infrastructure & isolation

Production workloads are hosted on reputable cloud providers with regional availability options. Customer environments can be deployed with logical isolation appropriate to the engagement, including dedicated or private-cloud configurations where contracted.

  • Network segmentation between public edges, application tiers, and data stores.
  • Encrypted traffic in transit using TLS for web, API, and management interfaces.
  • Encrypted storage for sensitive data at rest using provider-managed or customer-managed keys where supported by the deployment model.
  • Least-privilege access for infrastructure automation and operator tooling.

Application & product security

Security is built into product development and release processes:

  • Secure coding practices, dependency monitoring, and review of high-risk changes.
  • Role-based access controls for administrative and operational features.
  • Authentication options suitable for enterprise environments, including SSO where enabled under customer agreements.
  • Audit logging of privileged actions to support investigation and compliance workflows.
  • Input validation and abuse protections on public-facing endpoints.

Broadcast & media workflows

Broadcast pipelines introduce unique integrity and availability requirements. Our approach includes:

  • Controls around feed ingestion, channel configuration, and ad-insertion signaling paths.
  • Operational monitoring for service health, playout continuity, and anomaly detection.
  • Separation of production content paths from marketing and corporate systems.
  • Customer-configurable integrations with ad servers, SSPs, DSPs, and measurement partners under agreed scopes.

Access management

Internal access to production systems is limited to authorized personnel based on job function. Access is reviewed periodically, revoked on role change or termination, and protected with strong authentication practices. Customer support access, when required, follows need-to-know principles and is logged.

Vulnerability management

We monitor for vulnerabilities in our software and underlying dependencies, prioritize remediation by severity and exploitability, and apply patches on a risk-based schedule. Customers may report suspected vulnerabilities to contact@msoocast.com. Please include enough detail for us to reproduce the issue and avoid public disclosure until we have had a reasonable opportunity to investigate and remediate.

Incident response

MSOOCast maintains an incident response process covering detection, containment, investigation, remediation, and customer communication. If a security incident affects your environment or personal data we process on your behalf, we will notify you in accordance with applicable law and contractual commitments.

Business continuity

We design for resilience through redundancy, backups, and recovery procedures appropriate to the service tier. Recovery objectives and deployment topology for a specific customer environment are defined in the applicable order or statement of work.

Compliance & customer responsibilities

MSOOCast supports customer compliance programs through contractual security commitments, documentation, and reasonable audit cooperation as agreed in writing. Customers remain responsible for configuring their environments securely, managing end-user access, safeguarding credentials, and complying with laws applicable to their content and advertising operations.

Third parties

We use subprocessors and infrastructure vendors that provide hosting, monitoring, communications, and related services. We evaluate vendors for security posture and require contractual protections appropriate to the data and services involved. A current list of material subprocessors is available to enterprise customers upon request.

Contact security

Security inquiries, vulnerability reports, and enterprise due diligence requests: contact@msoocast.com. Phone: (202) 964-3643. Mail: MSOOCast LLC, 1263 Glen Ave, Moorestown, NJ 08057, USA.

Related policies: Privacy Policy and Terms of Service.