Skip to content
Content Protection

vxDRM Gateway

Self-contained MultiDRM key and license server that runs on your own infrastructure — no mandatory cloud connection, no per-stream license fees. Deploy standalone to protect content from any packager and serve licenses to any CDN, or fully embedded within the vxApps ecosystem.

Widevine · FairPlay · PlayReadyMcast DRMOn-Prem · Hybrid · Air-GappedCDN AgnosticCPIX API
4
DRM systems behind one REST API
Widevine · FairPlay · PlayReady · Mcast
L1 & L3
Widevine security levels
TEE-based licensing
0
Mandatory cloud calls
Self-hosted key & license server
Any
CDN compatibility
StreamVX or 3rd-party

One Gateway. Every DRM.

The Case for DRM Independence

Break the cloud dependency loop.

Cloud-based DRM creates a single point of failure and a cost structure with no ceiling. Here's the alternative.

The Challenge

Most OTT platforms route every license request through a cloud-based DRM vendor — creating a hard dependency on third-party uptime, unpredictable per-stream costs, and lock-in that compounds with every new channel or service. When the DRM cloud goes down, your streams go dark. When subscriber volumes grow, the bill grows with them — often without a ceiling. Operators have little visibility into key issuance, session behavior, or security events, and integrating with non-standard CDN architectures typically requires expensive professional services from the DRM vendor — regardless of which CDN you actually use.

The vxDRM Gateway Approach

vxDRM Gateway is a self-contained MultiDRM platform that runs on your own hardware — no mandatory cloud connection, no per-stream license calls to an external service. It can be deployed standalone, protecting content from any packager and serving licenses to any CDN, or fully embedded within the vxApps ecosystem alongside vxOTT Gateway and vxTranscoder. It is CDN-agnostic by design: it integrates seamlessly with vxCDN Server and works equally well with any third-party CDN via standard token and session APIs. A single REST API unifies Widevine, FairPlay, PlayReady, and Mcast DRM, with built-in geo-blocking, device filtering, and concurrent stream control giving your team full operational visibility — regardless of the stack around it.

Platform Capabilities

Built for operational independence.

Four principles behind every vxDRM Gateway deployment — standalone or fully integrated.

Standalone or Embedded

Deploys independently of the vxApps stack — protecting content from any packager, serving licenses to any CDN. When used with vxOTT Gateway or vxTranscoder, integration is native and requires zero additional configuration.

Any PackagerAny CDNvxOTT GatewayvxCDN Server

CDN Agnostic

Works seamlessly with vxCDN Server and any third-party CDN via standard token and session APIs. No CDN lock-in — your delivery layer stays independent from your protection layer.

vxCDN Server3rd-Party CDNTOKEN & SESSION APIs

Flexible Multi-Instance

Each instance can be configured as a combined key+license server, a dedicated key server, or a license-only endpoint. Instances can be distributed across regions, stacked for redundancy, or separated by key domain — independently scaled.

REGION A
REGION B
REGION C

Security & Auditability

Rule-based security notifications, output protection enforcement, TEE-based licensing (Widevine L1/L3). Full auditability of every license issuance event — across all instances from a single management view.

AUDIT LOGTEE · L1
License issued · Widevine L1
Key rotated · CPIX
Geo-block · request denied!
Concurrent limit enforced
Deployment Scenarios

Built for real DRM operations.

Three configurations where vxDRM Gateway replaces cloud license fees, enforces subscriber-level control, or scales key delivery globally.

AI-generated illustration01OTT Platform — Break Cloud Dependency

OTT Platform — Break Cloud Dependency

A streaming platform handling hundreds of live channels and a growing VOD library is paying per-stream DRM fees that scale unpredictably. By deploying vxDRM Gateway on-premise, the operator replaces cloud license calls with a self-hosted key and license server. Integration with vxOTT Gateway is native; third-party packagers connect via the CPIX API. The result: fixed infrastructure cost, no single vendor dependency, and no service interruptions caused by external outages.WidevineFairPlayPlayReadyCPIXvxOTT Gateway
Content Protection

Multi-DRM. One key server. Zero per-stream fees.

All major DRM systems unified behind a single REST API, with CPIX-based key exchange for any third-party packager.

Apple

FairPlay

HLS delivery to all Apple devices. License issuance via CPIX or native vxApps integration, with key rotation supported.

iOSiPadOSmacOStvOS
Google

Widevine

L1 + L3 levels with TEE-based licensing. Android, Chrome, Chromecast, and most Smart TVs. Certified Widevine Integration Partner.

WindowsAndroidChrome
Microsoft

PlayReady

SL2000 + SL3000 security levels. Windows, Xbox, and legacy STB support for broad device reach.

WindowsXboxSTB

Also supported: ClearKey HLS and Mcast DRM (CENC · AES-CTR / AES-CBC) for multicast OTT delivery.

Specifications

Full protection stack, spec'd out.

vxDRM Gateway exposes a comprehensive set of DRM, authentication, and key management controls. The exact feature set per deployment is agreed individually — contact us to tailor a configuration to your workflow.

01 · Security

DRM Security

Google Widevine (L1, L3)Apple FairPlayMicrosoft PlayReadyClearKey HLSMcast DRMCENC Common EncryptionAES-CTR / AES-CBC ModesRule-Based Security Events
CONTENTCENC · AES-CTR / CBCWidevineFairPlayPlayReadyMcast DRMONE KEY SERVER · EVERY DRM
02 · Access

Authentication & Access

Token AuthenticationBasic AuthenticationCallback AuthenticationBio- & Geo-BlockingDevice Filtering / AuthOutput ProtectionConcurrent Stream ControlSession Control per Subscriber
PLAYER+ TOKENLICENSE-LEVEL CHECKSTOKENGEODEVICESESSION 2/3LICENSEGRANTEDEVERY REQUEST TIED TO A VERIFIED SESSION
03 · Keys

Key Management

Key Generation — Client-SideCPIX API SupportWidevine Common EncryptionKey Rotation SupportIndividual Key per ComponentMulti-Key SupportTEE Licensing (Trusted Exec.)Widevine Levels 1 & 3
PACKAGERCPIXKEY SERVERKEY · VIDEOKEY · AUDIOKEY · SUBSROTATED · MULTI-KEY · PER COMPONENT
04 · Integration

Playback & Integration

Live StreamingVOD on DemandDASH / CMAF / HLS ABRHTTP RESTful APIWeb GUI ManagementAPI Proxy / Multi Key-ServerOffline / Hybrid / Cloud-ProxySeamless vxApps Integration
WEB GUI{ REST API }LIVEVODDASH·CMAF·HLSOFFLINE · HYBRID · CLOUD-PROXY · vxAPPS
Architecture

The protection engine of the StreamVX signal chain.

vxDRM Gateway sits between your packaging layer and your delivery layer — issuing keys and licenses without adding hard dependencies in either direction.

Packagers & Encoders
vxApps · 3rd-Party
vxDRM Gateway
Key + License Server
Multi-DRM Output
4 DRM Systems
vxCDN Server
or 3rd-Party CDN
CDN / End User
Delivery
Core Pipeline

vxOTT Gateway / vxTranscoder

Native integration — zero additional configuration when packaging or transcoding through the vxApps stack.

Key Exchange

CPIX API

Standard key exchange for any third-party packager or origin, independent of the vxApps ecosystem.

Distribution

vxCDN Server

Native vxApps integration, or serve licenses to any third-party CDN via standard token and session APIs.

Multi-Instance

Geo-Distributed Setup

A central key+license server feeds regionally distributed license-only instances, each independently scaled.

Deployment

On-Prem · Hybrid · Air-Gapped

Runs on your own hardware with no mandatory cloud connection — or in a hybrid / cloud-proxy configuration.

Standalone Mode

No vxApps Stack Required

Protects content from any packager and serves licenses to any CDN — fully independent operation.

READY?

Let's talk
Take control of your content protection.

Our engineering team will map vxDRM Gateway to your specific workflow — no sales deck, no generic pitch.