TPN Compliance Pack
A snapshot of your content-security controls, mapped to what a TPN (MPA Trusted
Partner Network) assessor looks for. Hand the export to an assessor, or use it to see what to shore up.
Control areas
In place
Access control & least privilege
Role-based access (RBAC) with capability checks and scoped role portals.
Roles, per-route gates, scoped subdomains, login lockout, step-up OTP.
In place
Content watermarking & forensic tracking
Tiled watermark burn (Tiers 1-4) + forensic client burn + leak tracing.
Watermark pipeline + /admin/forensics (read a leaked frame back to a token).
In place
Audit logging of content access
Every content view / download / delivery is logged with who, when and IP.
80 content-access events in the last 90 days.
In place
Secure transfer & delivery
Signed short-TTL URLs, delivery lock, passphrase gate, Cloudflare WAF.
Media served via expiring presigned URLs; per-shot delivery lock.
In place
Asset tracking & chain of custody
Production tracking + versioned delivery packages tie every element to its show.
Shot/version lineage + delivery packages with manifests.
Action
Access reviews & offboarding
Periodic access reviews + a terminate/offboard flow.
No access review recorded yet - run one below.
In place
Encryption at rest
Transport is HTTPS; sensitive ID/financial fields are field-encrypted (Fernet).
Field-level encryption ON for PAN/Aadhaar/bank/UPI/IFSC (AES via Fernet); keys rotate via reencrypt_all.
Partial
Per-project security level
Each show can be marked standard / high / strict for tighter handling.
0 show(s) at high/strict level.
Access review
Record a periodic access review (TPN expects these). It snapshots the active headcount as evidence.
Per-project security level
| DONUT | standard | |
| YEM | standard |