A submission season, not a single send
Film festival screener hosting.
The problem is not the festival. It is your own sprawl.
A film in a festival campaign goes to submission platforms, programmers, press, sales agents, juries and partners. By month four most filmmakers cannot say how many links exist, who holds them, or which cut each person watched. This is how to run the season so you can answer all three.
Video hosting for filmmakers · 5 GB free · Paid plans from USD 9/month
Updated September 2026
The root error
There are two kinds of link,
and you must never mix them.
A festival campaign issues two completely different things, and almost every filmmaker issues them from the same place with the same settings. They have different security postures, different lifetimes and different owners. Separating them is the single change that makes the rest of the season manageable.
The submission copy
It goes into a platform and out of your control. You upload it or paste a link into a submission form, and from that moment the platform governs who inside the festival sees it and for how long. Treat it as semi-public: a clean export, no embargo assumptions, no expectation that you can pull it back. Sundance's own Submit page, for example, routes submissions through FilmFreeway and sets no screener security requirement at all.
The private screener
You issue it to a named person, for a stated purpose, with an end date. It belongs to you the whole time. A programmer who asked for a second look, a sales agent, a jury member, a journalist under embargo, a festival partner: each gets their own, and each can be closed independently when the reason for it expires.
The mixing happens innocently. You make one unlisted link for the submission platform, then paste the same link into an email to a programmer, then into a message to a sales agent, then into a press kit. Four months later that one URL is in more inboxes than you can name, and if it turns up somewhere it should not, you have no way to narrow the list.
It is worth reading what an unlisted link actually is, in the platform’s own words rather than in the way filmmakers use it. Vimeo’s help centre states that unlisted videos will not appear in public search results, and that they can be accessed and shared by anyone who has the video’s unique URL. That is an official statement that the link is transferable. It is a perfectly reasonable instrument for a submission copy. It is the wrong one for anything with an embargo on it.
One number worth knowing before you export the submission copy
The practical part
Keep a link inventory:
who has what, and until when.
This is the most useful thing on this page, and it costs you a spreadsheet. A filmmaker who keeps a running record can revoke intelligently and can answer a leak question in an afternoon. A filmmaker who does not, cannot do either, at any price, on any platform.
Eight columns, one row per link issued. A spreadsheet is genuinely enough. The value is not the tool, it is that the record exists on the day you need to answer a question about a copy you did not authorise.
Two habits make the record hold. Fill the row at the moment you issue the link, never at the end of the week, because the detail you will want later is the one you did not think worth writing down. And issue one link per person rather than one link per stage: a single screener shared with a jury of five is one row and five unknowns, while five rows is a list you can act on.
Whether the platform helps depends on which one you use, and the documentation is worth reading before you rely on it. Vimeo documents viewer-level analytics as a CSV download in showcases, reporting the team member’s email address, and states that results will only appear for logged-in team members and not for signed-out viewers, on an Advanced or Premium plan or an Enterprise plan with the Events feature added. A festival programmer opening a link from an email is not a logged-in team member. That is not a criticism of Vimeo, it is an argument for keeping your own record regardless of the platform.
The cut you send
A film changes across a season,
a programmer on an old one is a real failure.
Between the first submission deadline and the last festival of the run, most films change: a re-grade, a sound pass, a trim that fixes the second act. The failure mode is quiet. Nobody writes to tell you they watched the version you replaced two months ago.
The structural fix is to keep versions on one film rather than spawning a new link for every cut. On uncompressed.io versions, per-version approvals and timecoded comments are shipped: a new cut sits alongside the previous ones on the same film, a decision is recorded against the version it was made about, and a note lands on the frame it refers to instead of in a paragraph that says “around the forty minute mark”. Pair that with the version identifier in your inventory and the question of what somebody watched stops being a guess.
The picture matters more here than in almost any other kind of sharing, because a programmer is judging the photography. The player streams the exact bytes you uploaded, with no transcode anywhere, so a 150 Mbps export plays at 150 Mbps and the grade a colourist signed off is the grade on the programmer’s screen. Browser playback is H.264, HEVC and AV1. An 8K master plays when the viewer’s hardware decodes it, which is a real caveat on an unknown machine in an unknown office. Camera RAW is a different matter entirely: it never streams and never plays in a browser, so the screener you send is always an export.
1
Film, many versions
New cuts live on the same film, with a per-version approval on each, rather than a new link per revision.
0
Transcodes
The player streams the exact bytes uploaded. The screener is the export you made, not a platform's re-encode of it.
3
Browser codecs
H.264, HEVC and AV1. 8K plays when the viewer's hardware decodes it.
5 TB
Per file
The per-file upload ceiling, subject to the storage your plan has available. Verified in product code, 9 September 2026.
Proportion
Match the security to the stage,
not to your anxiety.
A submission copy going to a first-round programmer is low stakes. A screener going to a journalist two weeks before a premiere is high stakes. The same controls applied to both means you either over-engineer the first or under-protect the second.
Start from what is actually possible, because the marketing in this category is worse than the technology. Screen recording cannot be prevented in a browser. The W3C’s Encrypted Media Extensions specification says it directly: this specification does not define a content protection or Digital Rights Management system. Nothing published by the standards body describes a browser API that stops a viewer recording their own screen. Anyone who tells you a web link cannot be captured is selling you something.
What is possible is a set of controls that shift the odds and, more importantly, change what happens after a copy escapes. A visible session watermark deters, because a viewer who can see their own name burned into the frame behaves differently. A forensic per-person mark attributes after the fact, from a recovered copy. A short-lived link closes the window rather than leaving one open forever. A view log tells you whether the thing was even watched, which is more often the useful answer.
Capture blocking on uncompressed.io applies to the native macOS Vault path only. A browser link, here or anywhere, cannot prevent a screen recording: the W3C's Encrypted Media Extensions specification states that it does not define a content protection or Digital Rights Management system.
Say the honest thing out loud
The thing that catches people out
A festival abroad wants subtitles,
and it is asked late.
This is the practical failure of a festival season far more often than a leak is. A selection committee outside your language asks for a subtitled version, usually with less notice than you would like, and the burned-in copy you made for one territory is the wrong file for the next one. A sidecar subtitle file is easier to swap per territory than a burn-in, because a burn-in is a re-export and a permanent decision while a sidecar is neither. uncompressed.io has a captions feature: the track is produced by a speech-to-text model and it is editable. That is the whole claim, and the practical point stands regardless of which tool you use, so record which language track went with which link in your inventory. The burned-in versus sidecar decision and the captions guide cover the mechanics.
After the season
Revoke, archive,
keep the manifest.
A festival run ends, and the links do not. The end-of-season sweep is twenty minutes of work that a campaign without an inventory cannot perform at all.
Revoke everything still live
Filter the inventory to the rows marked live and close each one. Then verify it the way you verify a backup: open one of your own dead links in a private window and confirm it is actually gone. A revocation you did not check is a belief, not a fact.
Collapse to one authoritative cut
The festival run usually produces a final version. Make it the current one on the film so anybody arriving later gets the cut you want them to see, rather than whichever link they were forwarded.
Archive the master, keep the export online
The film that people click is the export. The master is the thing you would be unable to remake. Cold storage is the cheaper home for the second one, on the plans that carry it.
Keep the manifest
Do not delete the inventory when the season ends. It is the record of who saw what and when, and it is the only document that can answer a question about a copy that surfaces a year later. Keep it with the film's paperwork, not in a browser tab.
Where the film lives afterwards is a storage question rather than a security one. Pro is $25 a month or $250 a year with 500 GB hot. Max is $75 or $750 with 1.5 TB hot plus 1 TB cold. Studio is $250 or $2,500 with 2 TB hot plus 2 TB cold. Bandwidth is not metered on any of them, which is the part that matters during a run: a film that suddenly gets watched by forty programmers in a week does not cost more than one that gets watched by nobody. The hot and cold arithmetic sizes the archive side properly.
The short version
Two link types and one record,
the rest is proportion.
If you take one thing from this page, take the inventory. It costs nothing, it works with any platform, and it is the difference between answering a leak question and shrugging at it. If you take two, take the separation of the submission copy from the private screener, because that is what makes the inventory possible in the first place.
Everything after that is a judgement about stakes. Most festival campaigns do not need watermarking at all, and this page is not going to invent a festival rule to sell you one, because no festival body page we could retrieve states such a rule. When there is a commercial embargo on the film, the controls that exist are worth using, and the honest description of them is that they deter, attribute and limit the window rather than make a copy impossible. The screener security guide goes control by control through what each one stops and what defeats it.
Questions
Frequently asked
Do film festivals require watermarked screeners?
This page will not tell you that they do, because no official festival page we could retrieve says so. What we can state is one checked example: as of 9 September 2026 the Sundance Film Festival's own Submit page sets no screener security requirement at all, and routes submissions through FilmFreeway instead. Read the submission page of every festival you enter, because the requirement that matters is the one that festival publishes, not a rule of thumb from a forum.
What is the difference between a submission copy and a private screener?
The submission copy goes into a platform and leaves your control: you upload or link it once, and the platform governs it from there. A private screener is issued by you to a named person, for a stated window, and you can revoke it. They have different security postures and different lifetimes. Treating them as the same link is the root error of a badly run season.
Can I stop a programmer screen recording my film in a browser?
No. The W3C's Encrypted Media Extensions specification states plainly that it does not define a content protection or Digital Rights Management system, and no browser API documented anywhere stops a viewer recording their own screen. What you can do is make a recording traceable and short-lived: a visible session watermark deters, a per-person forensic mark attributes a recovered copy, a short-lived link closes the window, and a view log tells you whether it was opened at all. On uncompressed.io the Vault path goes further and blocks screen capture, but that is a property of the native macOS app, not of a browser link.
How do I know which cut a programmer actually watched?
Only by recording it. A film changes across a season, and a programmer watching a four-month-old cut is a real failure that nobody tells you about. Keep versions on one film rather than scattering new links, record the version identifier next to each recipient in your inventory, and use per-version approvals so a decision is attached to the cut it was made about.
Does an unlisted link keep my film private?
Not in the sense most filmmakers assume. Vimeo's own help centre states that unlisted videos will not appear in public search results, and that they can be accessed and shared by anyone who has the video's unique URL. That is an official statement that an unlisted link is transferable rather than tied to a recipient. It is fine for a first-round submission copy. It is the wrong instrument for a press screener before a premiere.
Can I see which named person watched a link?
It depends on the platform, and the documentation is worth reading before you rely on it. Vimeo documents viewer-level analytics as a CSV download in showcases, reporting the team member's email address, and states that results will only appear for logged-in team members and not for signed-out viewers, on an Advanced or Premium plan or an Enterprise plan with the Events feature added. A festival programmer opening a link you emailed is not a logged-in team member. On uncompressed.io the equivalent is a tamper-evident view log.
Do I need the full Vault setup to submit to festivals?
Most filmmakers do not. A submission platform plus one carefully issued unlisted link is genuinely enough for a first-round submission of a film with no commercial embargo on it. The full Vault programme is for the stage where a leak costs you a sale or a premiere: a sales agent, a jury under embargo, press before the release date. Spend the effort where the stake is, not everywhere.
One master, one log, one cut per person
Vault keeps the master on the native macOS path with screen capture blocked, a session watermark, a per-person forensic mark, AES-256 at rest, short-lived links and a tamper-evident view log. Storage is the only meter; bandwidth is not metered.
Sources
- 1.Sundance Film Festival, Submit (fetched 9 September 2026: states no screener security requirement, directs applicants to FilmFreeway, and states that multi-episode submissions must be delivered as one single and continuous video file or link, not to exceed 10 GB in size)
- 2.Vimeo Help Center: About video privacy settings (fetched 9 September 2026: unlisted videos will not appear in public search results and can be accessed and shared by anyone who has the video's unique URL)
- 3.Vimeo Help Center: How to access viewer-level analytics in showcases (fetched 9 September 2026: user-level analytics via CSV in showcases, results only for logged-in team members and not signed-out viewers, requires Advanced, Premium, or Enterprise with the Events feature)
- 4.W3C: Encrypted Media Extensions specification (fetched 9 September 2026: this specification does not define a content protection or Digital Rights Management system)
- 5.uncompressed.io: the Vault (product page, verified)
- 6.uncompressed.io: pricing and storage (product page, verified)
