Unannounced campaigns
Sharing video under an NDA.
What the clauses ask for, and what the delivery has to do.
A client's legal department sends an NDA. Nobody translates it into a way of handing over a file. This page connects the four clause types you meet most often to the mechanics of delivery, and says plainly which of them software can help with and which it cannot.
Video hosting for filmmakers · 5 GB free · Paid plans from USD 9/month
Updated September 2026
Clause by clause
What an NDA usually
asks of a file handover.
Confidentiality agreements vary, but the same four kinds of clause turn up in most of the ones a production company signs for an unannounced campaign. None of them mentions software. Each one implies something concrete about how the cut leaves your building.
Read this first
This is a practical guide to the mechanics of confidential delivery. It is not legal advice, and it does not tell you what your agreement requires. Your own counsel reads your NDA and decides that. What follows is only the part nobody else writes down: how the wording lands on the way you actually hand over a file.
Disclosure limited to named people
Sometimes a list of individuals, sometimes a defined need-to-know group inside the agency. Either way the obligation is per person, and a delivery that cannot tell one person from another cannot meet it. This is the clause that rules out anything where the URL is the credential.
A duty of care over copies
You are expected to look after the material while you hold it, and to keep it from spreading further than agreed. Every extra copy is another place that duty applies to, and copies you handed over are copies you no longer govern. The way to keep the duty small is to keep the number of copies at one.
Return or destruction at the end
At the end of the engagement, or on request, the material comes back or goes away. This is the clause that catches people, because a file emailed to eleven people cannot be destroyed on request. You can ask, and you will never know. A single hosted copy with access withdrawn is a request you can actually satisfy, in an afternoon, and demonstrate afterwards.
Notification if something goes wrong
If the material gets out, you tell the other side, usually promptly and usually with detail. That obligation is unmeetable without a record. If you cannot say who had access and when, you cannot say anything useful about how a copy escaped, and the conversation starts from your word alone.
Read together, the four clauses describe one delivery shape rather than a list of features. Material goes to specific people, in as few copies as possible, for a defined period, with a record of who had it. Everything below is what that shape looks like in practice.
The mechanics
The delivery patterns that fit,
and the ones that cannot.
Four ways people send a confidential cut, lined up against the four clause types. The first two fail on access control and on destruction. The third fails on the named-individual requirement, which is the one most people miss because the link feels private.
The patterns are generic and the clause types are the common ones, not rules. Read both against the wording of your own agreement, with your own counsel.
The third column is worth dwelling on, because it is what most teams already do and it looks responsible. A single unlisted or passphrase-protected link is a real improvement over an attachment. It is still one credential shared by a group, so it satisfies a need-to-know clause only for as long as everybody behaves, and it collapses the moment you need to remove one person from the round.
The checklist
Run it on the day you start,
and the day it wraps.
Access control on a confidential campaign is not a setting you choose once. It is two short routines, one at each end of the job, and the second one is the one everybody skips.
Agree the list before the first link
Ask the client for the names, in writing, and ask who inside the agency is included by role. Keep that message. It is the document that says who was supposed to have access, and everything after it is either on the list or an exception you approved.
Issue one link per person
Not one link for the group. One each, so a name can be removed without disturbing the others, and so a link that turns up somewhere it should not be points at a person rather than at a team.
Set expiry to the review window
The end of the round, not forever. Most confidentiality failures are stale access: a link from a March review still working in September, sitting in an inbox that has since been forwarded, archived or handed to a new employee.
Revoke on the day someone leaves the project
A freelancer who wraps, a producer who moves accounts, a client-side marketer who changes jobs. Revoke that day, not at the end of the campaign. When the campaign does end, revoke everything, then check your own link in a private window and confirm it is dead.
The part that protects you
Being able to show
you were careful.
If material from an unannounced campaign appears somewhere it should not, the question is not only who leaked it. It is whether the vendor handled it properly. That question lands on you, and it is answered with records or not at all.
Say this plainly to yourself before the job starts: the evidence matters more to you than to the client. The client owns the material and has the agreement. You are the party who may one day have to demonstrate that access was limited, time bound and withdrawn on schedule. A view log is not surveillance of your client’s staff. It is your own file note, written automatically, while you had other things to do.
Three records cover it. Your list of who was issued a link and when, which is just the message you already sent. A log of who opened the material and at what time, which the platform keeps if it keeps anything. And the revocation record showing when access ended. On uncompressed.io that middle record is a tamper-evident view log, and links are short lived by design, so the third record largely writes itself.
Watermarks belong in the same conversation, with the same honesty. A visible session watermark carries identifying information on screen while someone watches. A forensic mark is invisible and is recovered later from a copy that escaped. Frame.io describes its forensic watermark as an invisible pixel and says detection is not something it runs: the customer has to obtain the leaked file and work through NAGRA to recover the identifier. uncompressed.io ships a per-person forensic mark on Vault masters alongside the session watermark. In both cases a recovered mark is evidence pointing at an account, not proof of who redistributed anything, and it is worth saying so to an agency before they assume otherwise.
The honest part
What no platform can do,
and should not promise.
Sooner or later an agency or a client-side legal team asks for a technical guarantee that nobody can record the video. The right answer is that no web platform provides one, and giving that answer wins the conversation rather than losing it.
The specification usually invoked is Encrypted Media Extensions. Its own text says it does not define a content protection or digital rights management system, and that it defines a common API for interacting with such systems instead. On the other side, MDN documents the Screen Capture API as the way a page asks the user to share a screen, with a consent model attached. Neither document describes a way for a page to exclude its own content from being recorded. Browser video is recordable, and anyone telling a client otherwise about a browser link is describing something the web platform does not document.
Native applications are a different surface, and the distinction matters when you write it into an email. A Vault master on uncompressed.io does not open from a browser link at all: it plays in the native macOS app, where screen capture is blocked. That is a property of the native app path, not of a link, and describing it as though a web page were doing the work would be exactly the false promise this section exists to prevent. Below that, everything else still applies: the master is encrypted at rest with AES-256, links are short lived, sessions are watermarked, and the per-person forensic mark is in place.
And a camera pointed at a monitor defeats all of it. Every control on this page reduces the number of ways material spreads casually and improves what you can say afterwards. None of them stops a determined person with a phone. An agency that understands that will trust the rest of what you tell them.
Two ways to run it
The controls that exist,
and where the tiers sit.
If the agency already works in Frame.io, the vocabulary below is the one they will use. The tier gating is worth knowing before a call, because the two controls an NDA conversation usually lands on are the two that sit at the top of the price list.

Frame.io behaviour read from Frame.io's own help center on 9 September 2026, cited below; tier names are Frame.io's. helpx.adobe.com returned HTTP 403 the same day, so nothing here is attributed to Adobe's own documentation. Frame.io's static watermark, a separate feature, is documented on Enterprise, Team and Pro.
If the agency already lives in one platform, stay there for everything else
An agency standardised on a review platform its whole client roster uses has a genuine switching cost: templates, integrations, habits, and a hundred people who know where the comment button is. One confidential campaign is not a reason to move all of that, and anyone telling you otherwise is selling. The version that works is narrower. Keep the platform you have for the ninety per cent of work that is not embargoed, and run the one unannounced campaign on a tighter path, with per-person links and a log, for the weeks it is actually sensitive.
Design for what happens
Reviews happen on a phone,
on the train.
Every delivery plan is written for an attentive reviewer at a desk. That is not who watches your cut, and pretending otherwise is how confidential material ends up in ordinary places.
The commute review
A creative director watches on a personal phone, on a train, with the sound off, because that is the twenty minutes they have. Any workflow that only functions on a colour-managed desktop will simply be routed around, and the routing around is what leaks.
The 11pm forward
A producer forwards a link to a freelance editor at eleven at night because the deadline is Tuesday. This is not misconduct, it is the job. Per-person links make it visible and reversible instead of invisible and permanent, and they let you add the freelancer properly in ninety seconds.
The client's own team
The largest group with access is usually on the client side, and it grows without anyone telling you. Brand, legal, regional marketing, an agency of record you have never met. Ask for the list, ask again when it changes, and assume the leak surface is wider than your own staff.
The practical response to all three is the same. Make the legitimate path easy enough that nobody invents a shortcut, keep the number of copies at one, and keep a record of who was added and when. On uncompressed.io the working surface for that is the review room: versions stacked in one place, timecoded comments from every stakeholder, and an approval recorded against the version it was given for. An agency has to work inside a confidential delivery, not just watch one, and a workflow that only secures the file while making the review worse does not survive contact with a Tuesday deadline.
Questions
Frequently asked
Does an NDA require a specific platform or feature?
The agreements described here do not name products. They describe obligations: who may see the material, how copies are looked after, what happens at the end, and what you do if it gets out. A platform can make those obligations easier or nearly impossible to meet, but only your own counsel can say what your agreement requires. This page is a guide to the mechanics, not legal advice.
How do you satisfy a destruction clause for a video file?
By never creating the copies in the first place. If the only copy lives in one hosted library and every viewer watched it there, ending access is a decision you make once and can show you made. If the file was emailed, the same clause asks eleven people to delete it from their mailboxes, their backups and their phones, and you have no way to confirm any of it.
Can I stop the agency from screen recording the cut?
Not in a browser. The W3C's Encrypted Media Extensions specification states that it does not define a content protection or DRM system, and MDN's Screen Capture API documentation describes capture and its consent model, not a way for a page to opt its own content out. A native application can block capture on the platform it runs on, which is what the uncompressed.io Vault path does on macOS, and a camera pointed at a monitor still defeats every one of these.
Is a passphrase on the link enough for a named-individual clause?
A passphrase controls the URL, not the person. It usually travels in the same message as the link, and anyone who has it can open the video. If the clause limits disclosure to named individuals, the delivery has to be per person: one link each, revocable one at a time, with a record of who received which.
What evidence should I keep during a confidential campaign?
Who was given access, when they were given it, and when it was withdrawn. That record matters more to you than to the client, because you are the party who may have to demonstrate care. A tamper-evident view log plus your own list of who was issued a link covers both halves.
Could the platform itself use our footage to train AI?
On uncompressed.io, no. Files are never sold and never used to train AI. That is a clause in the Terms, with a 30-day notice rule attached to changes, which is the form the commitment has to take to be worth anything in a confidentiality conversation. If you use a different platform, read its terms for the same clause before you upload an unannounced campaign to it.
Our agency runs every client on one review platform. Should we move for one NDA job?
Probably not. A review platform that a whole client roster already uses carries a real switching cost in habits, integrations and training, and one confidential campaign is a poor reason to move all of it. The reasonable version is to keep the tool you have for everything else and use a separate, tighter path for the material that is actually embargoed.
One link per person, revocable, logged
Vault masters play in the native macOS app with screen capture blocked, a session watermark and a per-person forensic mark. Links are short lived, the master is encrypted at rest, and the view log is tamper evident.
Sources
- 1.Shares in Frame.io, Frame.io Knowledge Center (passphrase, expiration date, comment and download permissions, Public versus Secure shares, visibility on or off; fetched 9 September 2026. helpx.adobe.com returned HTTP 403 the same day, so nothing on this page is attributed to Adobe's own documentation)
- 2.Secure Sharing, Frame.io Knowledge Center (Manage Access by email address, and the account settings Require Authorized Domain, Require Secure Shares and Default Share Access Type; fetched 9 September 2026)
- 3.Watermarking in V4, Frame.io Knowledge Center (Session-Based Watermark displays the viewer's name, email, IP address, date and more, and is Enterprise Prime; Static Watermark is Enterprise, Team and Pro; fetched 9 September 2026)
- 4.Forensic Watermarking, Frame.io Knowledge Center (an invisible pixel, Enterprise Prime accounts only, applied to proxy files rather than original uploads, with detection run by the customer through NAGRA; fetched 9 September 2026)
- 5.Encrypted Media Extensions, W3C ("This specification does not define a content protection or Digital Rights Management system"; fetched 9 September 2026)
- 6.Screen Capture API, MDN Web Docs (documents getDisplayMedia and the user consent model; no mechanism for a page to exclude its own content from capture is documented; fetched 9 September 2026)
- 7.NexGuard forensic watermarking, NAGRA (the detection vendor Frame.io names; vendor's own marketing page, describing the technology as imperceptible; fetched 9 September 2026)
- 8.Security on uncompressed.io (Vault playback in the native macOS app, screen capture blocked, session watermark, per-person forensic mark, AES-256 at rest, short-lived links, tamper-evident view log)
- 9.uncompressed.io Terms (files are never sold or used to train AI, with a 30-day notice rule)
