vxDRM Gateway
Self-contained MultiDRM key and license server that runs on your own infrastructure — no mandatory cloud connection, no per-stream license fees. Deploy standalone to protect content from any packager and serve licenses to any CDN, or fully embedded within the vxApps ecosystem.
Break the cloud dependency loop.
Cloud-based DRM creates a single point of failure and a cost structure with no ceiling. Here's the alternative.
The Challenge
Most OTT platforms route every license request through a cloud-based DRM vendor — creating a hard dependency on third-party uptime, unpredictable per-stream costs, and lock-in that compounds with every new channel or service. When the DRM cloud goes down, your streams go dark. When subscriber volumes grow, the bill grows with them — often without a ceiling. Operators have little visibility into key issuance, session behavior, or security events, and integrating with non-standard CDN architectures typically requires expensive professional services from the DRM vendor — regardless of which CDN you actually use.
The vxDRM Gateway Approach
vxDRM Gateway is a self-contained MultiDRM platform that runs on your own hardware — no mandatory cloud connection, no per-stream license calls to an external service. It can be deployed standalone, protecting content from any packager and serving licenses to any CDN, or fully embedded within the vxApps ecosystem alongside vxOTT Gateway and vxTranscoder. It is CDN-agnostic by design: it integrates seamlessly with vxCDN Server and works equally well with any third-party CDN via standard token and session APIs. A single REST API unifies Widevine, FairPlay, PlayReady, and Mcast DRM, with built-in geo-blocking, device filtering, and concurrent stream control giving your team full operational visibility — regardless of the stack around it.
Built for operational independence.
Four principles behind every vxDRM Gateway deployment — standalone or fully integrated.
Standalone or Embedded
Deploys independently of the vxApps stack — protecting content from any packager, serving licenses to any CDN. When used with vxOTT Gateway or vxTranscoder, integration is native and requires zero additional configuration.
CDN Agnostic
Works seamlessly with vxCDN Server and any third-party CDN via standard token and session APIs. No CDN lock-in — your delivery layer stays independent from your protection layer.
Flexible Multi-Instance
Each instance can be configured as a combined key+license server, a dedicated key server, or a license-only endpoint. Instances can be distributed across regions, stacked for redundancy, or separated by key domain — independently scaled.
Security & Auditability
Rule-based security notifications, output protection enforcement, TEE-based licensing (Widevine L1/L3). Full auditability of every license issuance event — across all instances from a single management view.
Built for real DRM operations.
Three configurations where vxDRM Gateway replaces cloud license fees, enforces subscriber-level control, or scales key delivery globally.
Multi-DRM. One key server. Zero per-stream fees.
All major DRM systems unified behind a single REST API, with CPIX-based key exchange for any third-party packager.
FairPlay
HLS delivery to all Apple devices. License issuance via CPIX or native vxApps integration, with key rotation supported.
Widevine
L1 + L3 levels with TEE-based licensing. Android, Chrome, Chromecast, and most Smart TVs. Certified Widevine Integration Partner.
PlayReady
SL2000 + SL3000 security levels. Windows, Xbox, and legacy STB support for broad device reach.
Also supported: ClearKey HLS and Mcast DRM (CENC · AES-CTR / AES-CBC) for multicast OTT delivery.
Full protection stack, spec'd out.
vxDRM Gateway exposes a comprehensive set of DRM, authentication, and key management controls. The exact feature set per deployment is agreed individually — contact us to tailor a configuration to your workflow.
The protection engine of the StreamVX signal chain.
vxDRM Gateway sits between your packaging layer and your delivery layer — issuing keys and licenses without adding hard dependencies in either direction.
vxOTT Gateway / vxTranscoder
Native integration — zero additional configuration when packaging or transcoding through the vxApps stack.
CPIX API
Standard key exchange for any third-party packager or origin, independent of the vxApps ecosystem.
vxCDN Server
Native vxApps integration, or serve licenses to any third-party CDN via standard token and session APIs.
Geo-Distributed Setup
A central key+license server feeds regionally distributed license-only instances, each independently scaled.
On-Prem · Hybrid · Air-Gapped
Runs on your own hardware with no mandatory cloud connection — or in a hybrid / cloud-proxy configuration.
No vxApps Stack Required
Protects content from any packager and serves licenses to any CDN — fully independent operation.