The pillar of the screener cluster
Forensic watermarking for screeners.
What it traces, and what it cannot stop.
A visible watermark deters. A forensic watermark identifies. They are not alternatives, they are not interchangeable, and most of what is written about them is vendor copy. Here is the mechanism, the part about collusion that nobody explains, and what Frame.io and Vimeo document in their own words.
Video hosting for filmmakers · 5 GB free · Paid plans from USD 9/month
Updated September 2026
Two marks, two jobs
One deters,
the other identifies.
The word watermark covers two different technologies that do opposite things. Choosing between them is a category error. Understanding which one you are being sold is the whole buying decision.
The visible watermark deters
Text laid over the picture. Frame.io calls its version a Session-Based Watermark and documents it as displaying the viewer's name, email, IP address, date and more during playback and downloads. The viewer can see that the copy in front of them is stamped with their own identity, which is exactly the point: most casual redistribution stops there.
The forensic watermark identifies
Frame.io documents its Forensic Watermarking as an invisible pixel that is not visible to the viewer, contrasted directly against session-based watermarking, which displays viewer information on screen. It embeds session ID, user info and location data to form a unique, traceable identifier. Nobody watching knows it is there. The picture stays clean.
The cost of the visible mark is the picture. An email address burned across the frame is fine for a rough cut going to a producer and actively harmful for a distributor judging the grade, who is looking at shadow detail and skin tone through your overlay. That is the trade the visible mark makes, and it is why it cannot be the only control on a screener that someone is supposed to evaluate on its merits.
The cost of the forensic mark is that it does nothing until after the damage. It buys you nothing on the night of the screening. It buys you a name three weeks later, when a copy turns up somewhere it should not be.
No standards body publishes a definition of the pair that we could fetch and cite, so the definitions above are vendor documentation and are labelled that way on purpose: they come from Frame.io’s own help center. NAGRA, the detection vendor Frame.io names, uses the word imperceptible for the same idea on its own product page, which is marketing on a vendor’s site and should be read as such. Imperceptible is a design goal, not a measurement.
The honest limit
It does not stop a leak.
It attributes one.
If you take one thing from this page, take this. Forensic marking is an attribution technology. A vendor page that lets you leave thinking it is a prevention technology has sold you something you did not buy.
The mark does not lock the file. It does not block a download, does not block a screen recording, does not block a phone pointed at a monitor. Every one of those works exactly as well on a forensically marked file as on a clean one. What changes is what happens afterwards: there is something in the pixels that says which issued copy this one descended from.
That is genuinely valuable in a narrow way. Attribution only means anything when the pool of suspects is small enough to act on. A dozen festival programmers, five distributors, thirty journalists under embargo: that is the shape of the problem this was built for. A link sent to two hundred people is not a case you can close with a mark.
The second caveat is survivability. A mark is worth exactly what survives between the copy you issued and the copy you recovered, and real leaks are re-encoded, cropped, rescaled, screen-recorded and re-uploaded, often several times over. Whether an identifier still comes out at the end of that chain depends entirely on the implementation. Anyone quoting a survival rate without naming the test material and the exact chain of alterations is selling, not measuring. We have no verified source for such a number, so this page states none.
Detection is also a separate job from marking, and buyers routinely assume it is included. Frame.io documents that detection is not run by Frame.io: the customer obtains the leaked file, works with NAGRA, and then supplies the resulting Forensic ID back to Frame.io to retrieve the session details. That is a real workflow with a real third party in it. It is not a button.
Three things a forensic mark cannot do
It cannot prevent a copy from being made. It cannot tell you a leak happened; you find out the way everyone finds out, when someone sends you a link. And it cannot, on its own, prove who redistributed a file: a recovered identifier says which issued copy the leak descended from, which is a strong lead and not a confession.
The part nobody explains
Two recipients,
one averaged copy.
Here is the failure mode that vendor pages skip, and the reason a per-recipient mark is not just a serial number stamped into the noise.
Give two people two copies of the same film, each carrying its own mark. Those two people can compare. Line the files up frame by frame and the pixels that differ between them are, by definition, the ones carrying identity. Everything else is the movie. Average the two copies together and a naive per-person mark can be washed out entirely. Worse, depending on how the marks were assigned, the average can decode to a third recipient who had nothing to do with it. That second outcome is the one that matters most, because a scheme that frames an innocent recipient is worse than no scheme at all.
This is a collusion attack, and defending against it is a design problem rather than a strength problem. Making the mark harder to see or harder to remove does not help. What helps is choosing what each recipient’s mark looks like so that any combination of a small number of them still carries a readable signature of its parts. A collusion-resistant scheme is one built so that a copy assembled from several marked versions still traces back to the people who contributed to it, instead of dissolving or pointing somewhere false.
Whether you need to care depends entirely on your recipient list. One distributor is not a collusion problem. Forty jurors who all know each other and all hold the same film is. When you are evaluating a vendor, this is the question that separates the serious from the promotional: ask what happens when two of your recipients average their copies. A vendor who has not thought about it will answer that the mark is invisible, which is not an answer.
What the platforms actually document
Frame.io and Vimeo,
in their own words.
Every cell below is quoted or paraphrased from the vendor’s own help center, fetched on 9 September 2026 and listed in the sources. Nothing here comes from a review site, a forum or a comparison blog.

Frame.io and Vimeo cells are read from those vendors' own help centers on 9 September 2026; every URL is in the sources below. Adobe's helpx.adobe.com pages returned HTTP 403 on every attempt, so nothing on this page is attributed to Adobe's own documentation. In the uncompressed.io column, a watermark alters the displayed picture during a Vault session; the uploaded original is stored untouched, because nothing is ever re-encoded here.
Two details in the Frame.io column are material to a buyer and easy to miss. The first is the tier: both marks sit at the top of the catalogue, session-based watermarking documented as Enterprise Prime and forensic watermarking documented as supported for Enterprise Prime accounts only. If you are on Pro or Team, the forensic mark is not a switch you can find. The static text watermark you do get on those tiers is a different feature.
The second is where the mark lands. Frame.io documents its forensic watermark as applied to proxy files rather than original uploads, working only with official Frame.io clients that support HLS. So the traceable copy is the streamed proxy, not the master. A file that leaves through the download permission is not the copy the forensic mark was written into, and for a workflow whose deliverable is the file, that decides whether the feature covers your actual risk.
Vimeo deserves a straight answer too, because it is where most of this work actually sits. Nothing in the Vimeo help pages we fetched documents watermarking of any kind. What Vimeo documents is privacy settings, and the one people reach for is Unlisted. Vimeo’s own description of it is the important sentence: videos can be accessed and shared by anyone who has the video’s unique URL. That is the vendor stating plainly that an unlisted link is transferable rather than per-recipient.
One more Vimeo detail, before you assume a link tells you who watched. Vimeo documents viewer-level analytics as a CSV download in showcases that reports the team member’s email address, and states that results will only appear for logged-in team members, not for signed-out viewers. A distributor or a journalist opening a link you emailed is not a logged-in team member. That is not a criticism. Vimeo is a portfolio and delivery platform and its documentation is clear about what it is. It is simply not a screener security product, and using it as one should be a decision rather than a default.
How it works here
The Vault path,
not a security tier you negotiate into.
Six behaviours, described as behaviours. What follows is what the Vault does, not what it is built from, and the limits are stated in the same breath as the feature.
Native app only
A Vault master plays in the macOS app, not in a browser tab. That constraint is what makes the rest of this list possible, and it is a real cost: your recipient needs a Mac and the app.
Screen capture blocked
The Vault playback window is designed to be excluded from supported software capture paths. Test it on the recipient's machine, with their own sharing tools, before a sensitive round. A camera pointed at a screen still works, here and everywhere.
Session watermark
The viewing session carries visible identification with the picture, so a copy filmed off a screen is not anonymous. It is also the reason to think about who needs a clean copy to judge the grade.
Forensic per-person mark
Shipped. Each person's viewing carries its own invisible mark, so a recovered copy can be investigated rather than guessed at. Cropping, recompression and camera recordings can weaken the trace.
AES-256 at rest, short-lived links
Masters are encrypted at rest and Vault media URLs expire after two minutes, which shortens the window in which a captured URL is worth anything. It does nothing about an authorized viewer mid-session.
Tamper-evident view log
Access events are recorded, so you can build a timeline of who opened what and when. A log establishes access. It does not prove redistribution.
Two things this list deliberately does not say. FairPlay DRM is on the roadmap and has never shipped, so it is not part of the Vault today and will not be described here as though it were. And there is no published self-serve detection step: if a copy escapes, preserve it, keep the access record, and get in touch. Recovery is conditional in every implementation of forensic marking, including this one, and a page that promises otherwise is a page to distrust.
The one structural difference worth naming is that none of this costs picture quality. The player streams the exact bytes you uploaded, so a 200 Mbps master streams at 200 Mbps. Securing a film should not mean showing a director a soft proxy of their own work. The screener pillar lines every control up against the leak path it actually covers, and the security page documents the limits in full.
When to skip it
Most video does not
need any of this.
The cost of forensic marking is not mostly money. It is friction, and friction lands on the person you most want to watch your film.
Ask what you would do about a leak
If this copy appeared publicly tomorrow, would you want to know which of eleven named people it came from, and would you act on that knowledge? If yes, forensic marking earns its place. If you would shrug, stop reading here.
Count the recipients
Attribution needs a small, named list. A handful of distributors, a festival jury, an embargoed press list. If the link goes to a department, a mailing list or an unknown number of forwards, the mark will not close your case.
Price the friction honestly
A native review path means your recipient installs an app and authorizes it on a supported machine. Someone will not be able to. A distributor who cannot open the link is a worse outcome than a distributor who could theoretically have leaked it.
Otherwise, use the boring controls
A corporate explainer, a wedding film, a case study going public next week: send a password-protected link, set an expiry, leave the download switch off, and get on with the job. That is the right amount of security for most work.
No official page we could read states a screener security requirement
Search results for this topic are thick with the claim that the industry requires watermarked screeners. We went looking for an official page that says so and did not find one we could read. As of 9 September 2026, Sundance’s own submit page routes applicants through a third-party platform and states no technical specification for screener files, no requirement about secure links, watermarking, passwords or download settings. The Motion Picture Association’s own content-protection page covers piracy scale, enforcement approach and industry coalitions, and contains no screener requirements and no watermarking requirements.
So if a page tells you an industry body requires this, ask it for the URL. We have no source for that claim and will not make it. What we can tell you is that individual distributors and individual festivals set their own delivery terms, in writing, in the agreement or the submission rules you were sent. Read those. They are the requirement.
Questions
Frequently asked
Does a forensic watermark stop a leak?
No. It is an attribution technology, not a prevention technology. A forensically marked file downloads, screen-records and re-uploads exactly as easily as a clean one. What the mark changes is what you can do after a copy surfaces: recover an identifier from the pixels and learn which issued copy it descended from. If you need prevention, you are looking for access control and capture restrictions, which are different features doing a different job.
Does a forensic watermark survive screen recording or re-encoding?
It depends entirely on the implementation, and no page we could verify puts a number on it. NAGRA, the detection vendor Frame.io names, claims on its own product page that its imperceptible watermarking is robust against content ripping, scaling and transcoding; that is vendor marketing on a vendor site. Nothing we fetched documents survival through a camera pointed at a screen. Test the actual chain your leak would go through before you rely on it.
Which Frame.io plan includes forensic watermarking?
Frame.io's help center states that Forensic Watermarking is supported for Enterprise Prime accounts only, and that its Session-Based Watermark is also Enterprise Prime. Static text watermarking is documented on Enterprise, Team and Pro, which is a different feature. Frame.io also documents that the forensic mark is applied to proxy files rather than original uploads, and that detection is not run by Frame.io: you obtain the leaked file, work with NAGRA, then supply the Forensic ID back to Frame.io for session details.
Does Vimeo have watermarking?
Nothing in the Vimeo help pages we fetched documents watermarking of any kind. Vimeo documents six privacy settings instead: Public, Unlisted, Password, Embed only, Anyone at your organisation, and Private. Its own description of Unlisted is that videos can be accessed and shared by anyone who has the video's unique URL, which is the vendor saying plainly that an unlisted link is transferable rather than per-recipient.
What is a collusion attack on a watermark?
Two recipients compare their copies. The pixels that differ between them are the ones carrying identity, so averaging the two files can wash a naive per-person mark out, or make it decode to a third person who was never involved. A collusion-resistant scheme is designed so that a copy assembled from several marked versions still traces back to the recipients who contributed to it. If your screener goes to one distributor this does not matter. If it goes to forty jurors who all know each other, it does.
Do festivals or industry bodies require watermarked screeners?
We could not find an official page that says so. As of 9 September 2026, Sundance's own submit page routes applicants through a third-party platform and states no technical specification for screener files, no requirement about secure links, watermarking, passwords or download settings. The Motion Picture Association's content-protection page covers piracy scale, enforcement and coalitions, and contains no screener or watermarking requirements. Check the specific festival's own rules rather than a claim about the industry.
Do I need this for a corporate video?
Almost certainly not. A film with no embargo, no unreleased talent and no distribution deal riding on it does not need forensic marking, and the friction is real: your recipient installs an app, authorizes it and watches on a machine that meets the constraints. A password, an expiry and the download switch left off is the right amount of security for most work.
Mark the copy, then keep the picture clean
The Vault adds a native macOS review path with capture restrictions, a visible session watermark, a per-person forensic mark, AES-256 at rest, short-lived media links and a tamper-evident view log.
Sources
- 1.Frame.io Help Center: Watermarking in V4 (session-based watermark shows viewer name, email, IP address, date and more; Enterprise Prime; fetched 9 September 2026)
- 2.Frame.io Help Center: Forensic Watermarking (invisible pixel not visible to the viewer, Enterprise Prime only, applied to proxy files, detection through NAGRA; fetched 9 September 2026)
- 3.Frame.io Help Center: Enterprise Forensic Watermarking (legacy V3) (not visible to the viewer; embedded whenever the asset is played or downloaded; Enterprise only; fetched 9 September 2026)
- 4.Frame.io Help Center: Enterprise Watermark ID (legacy V3) (per-viewer identifying information transcoded onto each frame; Enterprise add-on purchase; fetched 9 September 2026)
- 5.Frame.io Help Center: Shares in Frame.io (passphrase, expiration date, comment and download permissions, Public versus Secure; fetched 9 September 2026)
- 6.Frame.io Help Center: Secure Sharing (Manage Access by email, Require Authorized Domain, Require Secure Shares; fetched 9 September 2026)
- 7.Vimeo Help Center: About video privacy settings (the six settings, and Unlisted described as accessible and shareable by anyone who has the unique URL; fetched 9 September 2026)
- 8.Vimeo Help Center: How to prevent viewers from downloading my videos (per-video and account-wide download toggles; no way to download from the embedded player; fetched 9 September 2026)
- 9.Vimeo Help Center: How to access viewer-level analytics in showcases (CSV reports a team member's email address; results appear only for logged-in team members, not signed-out viewers; fetched 9 September 2026)
- 10.NAGRA: NexGuard forensic watermarking (vendor marketing on the vendor's own site: imperceptible watermarking, robust against ripping, scaling and transcoding; fetched 9 September 2026)
- 11.Sundance Film Festival: Submit (routes applicants through a third-party platform; states no screener security or file specification; fetched 9 September 2026)
- 12.Motion Picture Association: Safeguarding Creativity (piracy scale, enforcement and coalitions; contains no screener or watermarking requirements; fetched 9 September 2026)
- 13.uncompressed.io: The Vault (capture restrictions, session watermark, per-person forensic mark, AES-256 local cache, two-minute media URLs, access record)
- 14.uncompressed.io: Security (the full security model, including what is not claimed)
