Systems operational live
  • Data Ingest records ingested 24h
  • Harmonization & Enrichment assets enriched 24h
  • Media & Image Hub images processed 24h
  • Metadata & Media Delivery API requests served 24h
  • Platform availability uptime 30d

Representative platform activity · updated continuously

11–14 September, Amsterdam: Meet Media Press at IBC2026 11–14 September, Amsterdam: Meet Media Press at IBC2026

Security & Compliance

Security built into every layer.

Metadata is core infrastructure for the clients who run on it, so we treat protecting it as core infrastructure too: an approved Information Security Policy, backed by real controls, not a page written after the fact.

Our policy

An approved policy, not a slogan

Media Press Group operates a formal Information Security and Business Continuity Management System, approved by the Board and applied across Media Press Group. It commits us to:

Our commitments

  • Protecting the confidentiality, integrity and availability of our own information and our clients', in line with the law and the agreements we sign.
  • Identifying and minimising threats and risks to our information and assets on an ongoing basis, using the methods set out in our Management System.
  • Reviewing this policy regularly to keep it current, and continually improving the Management System behind it.
  • Running business continuity practices that meet both client requirements and legal obligations.

The Management System is structured around:

  • ISO/IEC 27001, the international standard for information security
  • ISO 22301, the international standard for business continuity
  • GDPR, for personal data handling
  • The EU AI Act's low-risk classification, for our AI-driven metadata operations
In practice

Four layers of defence

01

Access & identity

Role-based access control restricts every account to only what it needs. A strict password policy, mandatory multi-factor authentication, and hardware security keys for administrative accounts add further layers before any sensitive system can be reached.

02

Encryption & data protection

Data is encrypted at rest with AES-256 and in transit with TLS, so metadata is protected whether it is stored or moving between systems. All client metadata is held exclusively within the EU.

03

Infrastructure & resilience

Two geographically separated data centres run in parallel with real-time replication between them, so a failure at one site does not interrupt delivery. Container images are scanned for vulnerabilities before anything reaches production.

04

Monitoring & governance

Systems are monitored continuously, with real-time dashboards surfacing anomalies as they happen. Regular internal security assessments, including simulated phishing exercises, keep the team practised against real-world threats.

Questions

Have a security questionnaire or specific requirement?

Our team can walk your security or procurement group through our controls in detail, or complete a vendor questionnaire directly.