DRM-X 6.0 is under active development

One secure control plane.Every major screen.

Protect VOD and live streaming with unified licensing, policies, content keys, users, devices, storage and analytics for Widevine, PlayReady, FairPlay Streaming and Huawei WisePlay.

4DRM ecosystems
1policy model
API-firstintegration
X DRM-X Control Plane Protected
Protection overviewGlobal streaming
Production design
PolicyPremium streaming Versioned and active
Key statusEncrypted at rest Short-lived lease
WV

WidevineIn integration

PR

PlayReadyPlayback path verified

FP

FairPlay StreamingIn integration

WP

WisePlayIn development

Security-first architectureProvider isolation · key protection · auditability

ISO/IEC 27001:2022Aligned design · certification in preparation

Unified protection for
WVGoogle Widevine
PRMicrosoft PlayReady
FPApple FairPlay Streaming
WPHuawei WisePlay
One platform, four ecosystems

Reduce Multi-DRM complexity without losing control.

Your application works with one content catalogue, one policy model and one authorization workflow while provider-specific operations remain behind purpose-built security boundaries.

WVIn integration

Google Widevine

Android · Chrome · Android TV

Target workflowMPEG-DASH / CENC
PRPlayback path verified

Microsoft PlayReady

Windows · Edge · Xbox · Smart TV

Target workflowMPEG-DASH / CENC
FPIn integration

Apple FairPlay Streaming

iPhone · iPad · Mac · Apple TV

Target workflowHLS / CBCS
WPIn development

Huawei WisePlay

Huawei device ecosystem

Target workflowVOD integration

Production activation depends on vendor agreements, credentials, supported clients and platform-specific validation. PlayReady is the currently verified playback path.

Secure by architecture

Designed for ISO/IEC 27001-aligned operations.

DRM-X 6.0 is being engineered with security controls aligned to ISO/IEC 27001:2022, including access control, cryptographic protection, secure development, logging, operational resilience and supplier risk management.

Certification status

Haihaisoft is preparing its Information Security Management System for independent certification. DRM-X 6.0 is not yet ISO/IEC 27001 certified.

Provider-isolated services

Each DRM provider runs behind a separated service boundary, reducing shared exposure of SDKs and credentials.

Protected content keys

Content keys are designed to remain encrypted at rest and be released only through short-lived internal leases.

Tenant and project isolation

Organisation, project and environment boundaries are enforced throughout the control and licensing workflow.

Auditable operations

Versioned policies, administrative activity and security events are designed for traceability and review.

Signed internal requests

Timestamps, nonces and signature validation help protect service-to-service communication from replay attacks.

Production security controls

The roadmap includes production KMS/HSM integration, centralized logging, backup testing and secure operations.

Complete control plane

Manage the full protection lifecycle.

DRM-X 6.0 goes beyond license delivery to connect policies, keys, content, audiences, integrations and operational visibility.

License delivery

Route authorized device challenges through one Common License Gateway to the correct DRM provider.

Rights and policies

Create reusable, versioned profiles for expiry, offline use, output protection, concurrency and revocation.

Key management

Manage key sets and encrypted key material through a security-first service boundary.

Storage connections

Use DRM-X-hosted storage or connect customer-controlled Amazon S3 and compatible object storage.

Audience control

Manage users, groups, devices, applications and targeted blacklisting from a unified model.

Events and analytics

Review license requests, denials, usage and security events through the console or APIs.

API-first integration

Integrate playback grants, management APIs, webhooks and environment-specific credentials.

Global and China deployment

The architecture can support independently operated regional environments and provider credentials.

Provider-isolated architecture

Keep complexity behind secure service boundaries.

The shared customer-facing gateway is designed without direct access to provider SDK source code, DRM credentials, FairPlay private keys or unwrapped content keys.

Your platform

Application backendAuthentication and entitlement

Player applicationsWeb · mobile · smart TV

DRM-X common services

Playback Grant APIShort-lived authorization

Common License GatewayValidation, limits and routing

Key serviceWrapped keys and short leases

Isolated provider services
WV

Google WidevineSeparate credentials and adapter

PR

Microsoft PlayReadySeparate credentials and adapter

FP

Apple FairPlay StreamingSeparate credentials and adapter

WP

Huawei WisePlaySeparate credentials and adapter

From source to secure playback

A clear workflow for every device ecosystem.

Keep customer authentication and commercial entitlements in your platform. DRM-X converts each authorized playback decision into the right DRM license.

Discuss your workflow
01

Connect content

Use DRM-X-hosted storage or connect your own object storage.

02

Define playback rights

Choose expiry, devices, concurrency, offline and output-protection rules.

03

Prepare protected outputs

Generate compatible CENC and CBCS streaming outputs for DASH and HLS.

04

Authorize playback

Issue a short-lived Playback Grant from your trusted backend.

05

Deliver the license

The common gateway routes the challenge to the correct provider service.

06

Monitor and respond

Review events, revoke access and investigate devices or denied requests.

Built for premium streaming

Protect valuable content across modern delivery models.

On demand

VOD, OTT and subscription video

Apply reusable policies across catalogues, devices, rental windows, subscriptions and offline playback.

Live streaming

Broadcast, sports and premium events

Prepare for regional scale, live authorization, provider routing, operational monitoring and future key rotation.

Transparent launch status

Know what is verified, integrating and planned.

We are building DRM-X 6.0 openly and will update readiness as provider and interoperability testing progresses.

Current development environment

Verified foundations

  • PlayReady license and playback path
  • Common License Gateway architecture
  • Rights and License Profile management
  • Content, user, group and device models
  • Blacklist management
  • Wrapped-key and short-lived key-lease design
Active engineering work

In integration

  • Google Widevine provider service
  • Apple FairPlay Streaming provider service
  • Huawei WisePlay VOD provider service
  • Automated packaging workflows
Product roadmap

Planned capabilities

  • CPIX 2.4 and SPEKE integration
  • Production KMS and HSM connectors
  • Live content-key rotation
  • Expanded packaging automation
  • Integrated forensic watermarking workflows
  • Contractual service levels
Frequently asked questions

Clear answers for security and streaming teams.

Need to discuss a specific device, DRM provider or deployment region?

Talk to a DRM engineer
What is Multi-DRM?+

Multi-DRM uses multiple digital rights management technologies to protect the same streaming service across browsers, operating systems, mobile devices and smart TVs. DRM-X 6.0 targets Widevine, PlayReady, FairPlay Streaming and Huawei WisePlay through one control plane.

Is DRM-X 6.0 ISO/IEC 27001 certified?+

Not yet. DRM-X 6.0 is being designed with technical and operational controls aligned to ISO/IEC 27001:2022, while Haihaisoft prepares its Information Security Management System for independent certification. This page does not claim that certification has already been completed.

Does DRM-X 6.0 support VOD and live streaming?+

The platform is being built for both VOD and live workflows. Initial live support is targeted for Widevine, PlayReady and FairPlay environments, while WisePlay is initially focused on VOD.

How does DRM-X protect content keys?+

The architecture is designed to store encrypted or wrapped content keys instead of plaintext keys. Clear keys are intended to be released only to authorized internal services for short-lived operations, with production KMS or HSM integration on the roadmap.

Can we connect our own storage?+

Yes. The storage model supports customer-controlled Amazon S3 and compatible object storage, alongside a planned DRM-X-hosted Cloudflare R2 option.

When will DRM-X 6.0 be available?+

DRM-X 6.0 is under active development. Customers can join the early-access programme now to review architecture, devices, packaging, regional deployment and integration requirements.

DRM-X 6.0 early access

Plan your secure Multi-DRM deployment.

Review devices, providers, storage, packaging, policies, regional architecture and ISO/IEC 27001-aligned security requirements with Haihaisoft.