COMPLIANCE // EU SOVEREIGNTY

Security architecture for screenplays: EU hosting, GDPR compliance, data protection.

Stories and concepts in development are the most confidential material that production companies, broadcasters and streaming providers hold. CineCockpit treats them accordingly: complete data isolation per organisation, hosting exclusively within the EU, and no vendor lock-in on AI models. Data delivers the finding. People deliver the judgement. Both depend on the underlying data being stored securely.

SEC // 01

EU Hosting & GDPR

Operated exclusively in ISO-27001-certified data centres within the European Union. Full GDPR compliance with a data processing agreement under Art. 28.

DE / AT / CH
SEC // 02

Isolated instance per organisation

No cross-tenant data mixing. Each organisation receives a strictly separated database and its own data lake. On-premises deployment available on request.

ISOLATION LEVEL: STRICT
SEC // 03

Provider-neutral models

No vendor lock-in. European open-weight models or proprietary enterprise interfaces, depending on your requirements. Switch providers without data migration or reinstallation.

EU MODELS PREFERRED
SEC // 04

Zero-retention guarantee

No client material is ever used to train AI models. Non-retention of prompts and internal documents is contractually guaranteed.

CONTRACTUALLY GUARANTEED

DETAIL // EU HOSTING

Infrastructure built within the European legal framework.

All data resides exclusively on servers within the European Union. No third-country transfers, no US cloud providers with an uncertain legal standing. The hosting partner holds ISO 27001 certification and is engaged as a data processor under GDPR Art. 28.

For production companies working with broadcasters or streaming providers in the Europe, this infrastructure decision is often a contractual prerequisite, not an optional configuration. CineCockpit connects social APIs, platforms, communities and databases, all within this framework, provider-neutral and replaceable at any time.

ISO-27001-certified data centres DE / CH
Data processing agreement (Art. 28 GDPR) as standard
No third-country transfers, no US cloud providers
On-premises deployment for specific requirements
INFRASTRUCTURE ARCHITECTURE // PER INSTANCE EU-ONLY
Schematic of the isolated instance architecture: data input, analysis pipeline, engine core and secured output
[01]
Dedicated database instance Complete logical and physical separation. No shared schema.
[02]
Private data lake (asset vault) Object storage for stories, screenplays, treatments and pitch decks. Encrypted at rest and in transit.
[03]
Network isolation / private VPC No publicly accessible database interface. Access only via authenticated API layer.
[04]
AI model connector (replaceable) The model connector is modular. Switch providers without reinstallation or data migration.
[05]
On-premises option (on request) Full self-managed deployment on your own infrastructure. Container-based, no cloud dependency.

DETAIL // DATA PRINCIPLE

Every use enriches the data record. The system improves with each run.

When a story or concept is matched against databases and open sources, the result is written back into its data record. Follow-up analyses draw on a more complete finding. This flywheel principle ensures that the quality of story and screenplay analysis grows with every run, without any manual upkeep.

All data records remain entirely within the isolated data lake of the respective organisation. No other organisation sees the enriched content. The flywheel turns exclusively for your own catalogue.

01
Story is created or imported Screenplay, expose, treatment, concept or research upload
02
Matched against databases and open sources Metadata registers, knowledge graphs, demand signals, community corpora -- all without personal reference
03
Finding is written back into the data record Comparables, audience signals, market context -- automatically enriched, with source attribution
04
Follow-up analyses start with more complete data Each run builds on the previous one. The system improves without manual maintenance

ALL DATA REMAINS IN THE ISOLATED INSTANCE OF YOUR OWN ORGANISATION

DETAIL // AI MODEL SOVEREIGNTY

Zero-retention and free choice of model.

Zero-retention on all AI requests

The AI models in use have no ability to store requests or document content, or to use them for their own training. Stories and concepts remain in the tool for development of stories and creative concepts, not with the model provider.

This is contractually secured with every model provider deployed. It is a condition for any provider selection, not a mere configuration option.

NO PROMPT LOGGING AT THE PROVIDER
NO TRAINING ON CLIENT DATA
CONTRACTUALLY GUARANTEED

Provider-neutral and replaceable models

CineCockpit does not tie itself to a single AI provider. The model interface is modular and provider-neutral. Each organisation can choose between European open-weight models and proprietary enterprise interfaces, depending on internal security policies and operational requirements.

For organisations with elevated protection requirements, running a self-hosted model on your own infrastructure is also possible. Switch providers without data migration or reinstallation.

EUROPEAN OPEN-WEIGHT MODELS (PREFERRED)
PROPRIETARY ENTERPRISE INTERFACES (OPTIONAL)
SELF-HOSTED ON REQUEST

DETAIL // DATA PROTECTION

No raw personal data. Sources reviewed before activation.

CineCockpit does not collect individual user data from public platforms. Sentiment information comes from aggregated, publicly available sources and is processed exclusively in summarised form. The system connects social APIs, platforms, communities and databases, neutrally and without naming the respective operators in the visible finding.

Every external data source undergoes a review for legal usability, GDPR compliance and data quality before activation. Sources that are unclear or carry legal risk are not activated.

PERMITTED Aggregated reviews, public metadata registers, publicly published crew profiles.
NOT COLLECTED Individual posts, private user profiles, location data, personal communications.
REVIEW PROCESS Legal admissibility and GDPR compliance are verified before each source is activated.
DATA CATEGORIES // USABILITY STATUS GDPR-COMPLIANT
Public work and metadata registers (film/TV) No personal data, aggregated by title
Entity resolution via open knowledge graphs Publicly licensed authority data, no personal reference
Demand and search interest signals Aggregated trend indicators only, no user profiles
Public review and community corpora GDPR-compliant, no raw personal data
Streaming demand indicators Publicly available ranking and popularity data

DETAIL // COMPLIANCE

Contractual safeguards. No compliance gaps.

DATA PROCESSING AGREEMENT

Processing under Art. 28 GDPR

Every instance is operated with a standardised data processing agreement. Processing purposes, retention periods and sub-processors are fully documented.

PRIVATE CLOUD / ON-PREM

Deployment on your own infrastructure

For organisations with their own IT security policies, a fully self-managed deployment is possible: container-based, with no dependency on external cloud services.

ACCESS CONTROL

Role-based permissions

All access to stories, analyses and dossiers is role-bound. Audit logs provide traceability without exposing personal data of third parties.

"Screenplays and story ideas are the most valuable asset in any development process. A platform that works with them has to meet the same security requirements as an encrypted vault drive."
Executive Producer, DACH

EXPLORE FURTHER

More about the platform

Discuss the security architecture in detail.

In the demo we walk through your specific compliance requirements: data processing agreement, on-premises options, model selection.

Request a demo