Skip to content

Who can read your script

Access levels, sharing, expiry, and plainly what the encryption does and does not protect against.

An unreleased screenplay is the most sensitive thing on a production. This is exactly what ScenePaper does with yours.

By default, nobody outside your production

A script belongs to a project, which belongs to your Production House. Nobody outside it can read a script, and being on your team is not by itself enough — access is granted per script.

Access levels

When you grant someone access, you choose how much they get:

- Full — the entire screenplay. - Sides — only the pages for the scenes they are in. This is what most actors should get, and it is the default worth reaching for. - Department — scoped to a department's needs. - Call sheet — only what a call sheet would show them. - None — explicitly no access.

Grants are per person and can be revoked at any time. Revoking takes effect immediately; it does not wait for a session to expire.

Distribution and expiry

Sending a script out is separate from granting access to it. A distribution is a delivery with its own lifetime — it can be revoked, or extended if someone needs longer. That means "I sent the second act to a possible DP" does not have to become permanent access.

A read log

Every read of a script is recorded — who, when, and by what route. If a screenplay leaks, the log is the only thing that narrows down where from.

Encryption, described accurately

Screenplays are encrypted at rest with AES-256-GCM. The stored bytes are not readable without the key, so a stolen database backup or a discarded disk does not hand anybody your script.

Being straight about the limit, because this is the part people get wrong: the key is held by the server, not by you. That means ScenePaper can decrypt your screenplay in order to show it to you — and so, in principle, could somebody who compromised the running server, or the operator of the service.

This is not end-to-end or zero-knowledge encryption and we will not describe it that way. It protects against stolen storage. It does not protect against us. If your screenplay is sensitive enough that operator access is unacceptable, that is a real consideration and you should weigh it honestly.

What you can do

- Grant sides rather than full access unless someone genuinely needs the whole thing. - Revoke when a person leaves the production, rather than at wrap. - Use distributions with expiry for anyone outside the core team. - Check the read log if something feels wrong.

Back to the Story Room, or on to breaking down your script.

Didn't answer your question? Contact support.

PRODUCTIONSCENEPAPER
SCENE1
TAKE1
ROLLA
DIRECTORYOUR NEXT PRODUCTION