The Time-Addressable Media Store (TAMS) turns live and file-based media into the same thing: flows of short segments, each addressed by time. It deliberately leaves security and rights to someone else. Xinsere is that someone else. TAMS keeps the timeline and the query. Xinsere holds, protects and releases the bytes, one segment at a time, only to the parties allowed to have them.
Protected data is broken into sections, each one encrypted with its own key and scattered across hundreds of storage locations. Breach a whole bucket and you recover one encrypted fragment out of hundreds, with no key and no map. Permissions live on a blockchain: immutable, auditable, every grant a block you can read but cannot rewrite. They are bound to the data automatically at publish, so no admin has to wire them up and nobody can quietly widen access.
Interactive illustration
TAMS, the open API from BBC R&D, stores media as flows of immutable, time-addressed segments in object storage. Anyone holding the storage credentials can read every segment. With Xinsere underneath, a TAMS Media Object resolves to a Xinsere handle, not a raw storage key. The timeline and query work exactly as the spec describes, and the bytes stay locked until the blockchain says yes.
<flow_id, [start_end)> returns the segments that overlap. What comes back are Xinsere handles. Nothing is decrypted.
Each segment request is checked against the on-chain permissions for this party. A yes is cached briefly; a no is never cached.
Fragments are pulled from their scattered locations, decrypted, reassembled and SHA-256-checked bit for bit. If any check fails, nothing is returned.
Four flows share one timeline: two cameras, commentary and a stats feed. Pick who is asking, choose a timerange, and play it. Each party gets exactly the streams they hold rights to, segment by segment. Then revoke the partner mid-playback and watch the next request fail.
Interactive illustration The live system runs this same sequence against real segments: real storage, real on-chain checks, real playback. Ask us for a walkthrough.
Partners, affiliates and vendors query the same store. Nothing is exported, nothing is duplicated, and every segment they pull is permission-checked and logged on-chain.
Denials are never cached, so revoking access takes effect on the very next segment request. There is no stale copy sitting in someone's bucket to chase down.
A highlights model or a captioning agent gets exactly the flows and timeranges it is granted, through the same gate, with the same audit trail as a human operator.
Segments are scattered as encrypted fragments. Compromising a storage location exposes a fraction of a fraction of a file, with no key and no map.
The TAMS timeline, the half-open timerange query and TAI timestamps all work as the spec describes. Xinsere changes where the bytes live and who can get them, not how you address them.
The protection travels with the object, not the provider. Fragments can live on any cloud or on-prem, next to the compute that needs them.
We'll walk you through the live system: ingest a feed, query it, play it as an authorized party and as a stranger, and see what comes back.