Security
How to send unreleased music without losing control of it
Practical ways to share mixes and masters before release. Stream-only links, expiry, passwords, signed-in named recipients, and knowing who opened what.
Most leaks are not hacks. They are forwards: a WAV attached to an email, a download link posted in a group chat, a file left on a borrowed laptop. Once someone has the original file, you no longer control where it goes.
You can’t make sharing risk-free. You can make it deliberate. Here is how.
Decide what the recipient actually needs
Most people who hear a song before release need to listen, not to own a file.
| Recipient | Needs | Give them |
|---|---|---|
| Artist, A&R, manager, label team | Listen, comment, approve | Access inside your workspace with their own account |
| Press, playlist curators, radio | Listen once, maybe a few times | A stream-only link that expires |
| Mastering engineer, mixer, remixer | The original files | A download, to a named person, with a record |
| Sync agent or supervisor | Listen, then possibly the stems | Stream first; send files when a placement is real |
The default should be stream-only. A download is a decision, not a convenience.
Use links that can be taken back
A link to a file in a public folder, or an attachment, lives forever. A better link:
- Streams a lower-bitrate copy rather than serving the original. Enough to judge the song; not the master.
- Expires. A week is plenty for most listening. The link should stop working on its own.
- Can be revoked. If a link ends up in the wrong place, you should be able to kill it immediately.
- Has a password, sent through a different channel from the link itself. Weak passwords should be locked out after several wrong guesses.
- Opens only for named, signed-in people. The recipient proves who they are with their own account before the music plays. Forwarding the link then doesn’t forward access, and nobody listens anonymously.
- Limits views where it makes sense.
- Tells you when it is opened, so a link that is opened thirty times by a “single” recipient is visible.
When you must send the original
- Send it to a named person, not a group.
- Prefer a short-lived download link over an attachment, and keep a record of what was downloaded and when.
- Confirm on the phone or in person for the most valuable files. A two-minute call is the cheapest security there is.
- Don’t send the full stem set if a stereo master is what the job needs.
Protect the accounts, not just the links
The files are only as safe as the accounts that can reach them.
- Turn on two-factor authentication everywhere music lives: email, cloud storage, your music tools. Authenticator apps are better than SMS.
- Use passkeys where they are offered. They are tied to the real website, so a convincing phishing page can’t capture them.
- Review signed-in devices now and then, and sign out anything you don’t recognise, especially after sessions on shared studio machines.
- Remove people when a project ends. The session player from last year’s album doesn’t need access to this year’s.
- Give the least access that works. Someone who needs to comment doesn’t need to download; someone who uploads doesn’t need to share.
Watermarks and their limits
Audible or inaudible watermarks can help trace a leak back to a copy. They do not prevent one, and they add a processing step. They are most useful for large pre-release campaigns with many recipients. For day-to-day collaboration, access control and short-lived links do more.
What “encrypted” does and doesn’t mean
You’ll see “encrypted” on nearly every service. It usually means two things: files are encrypted in transit (HTTPS) and at rest on the provider’s disks. That protects against someone intercepting traffic or stealing a disk. It does not stop someone with a valid link or a logged-in account from listening; that’s what the access controls above are for. Be wary of broad, unspecific claims; ask what is encrypted, where, and who holds the keys.
A simple policy for a release
- Team members work in a shared workspace with their own accounts and two-factor on.
- Everyone outside the team gets stream-only, expiring links that open only for them, signed in.
- Originals go only to named engineers and the distributor, by short-lived download.
- When the campaign starts, review who has access and revoke old links.
- After release, keep the audit trail. If something leaks, you will want to know which copy.