Protecting your course from piracy: what works and what is theatre
Piracy is not stopped by a switch. Here are five layers that raise its cost and tie every copy to a person, plus an honest account of what no platform can do.
· فريق دورة
In short
No platform can stop a screen recording. What does work: gating on entitlement, short-lived signed links instead of permanent URLs, a watermark carrying the viewer's identity, a device limit on the account, and an append-only view log. These layers do not make copying impossible; they make it expensive and traceable.
A trainer once asked me: "How long until my course gets leaked?" The honest answer was that his course had already been leaked before he asked, and he had no idea. He was not missing a lock. He was missing a trace.
This article is about the difference. Five layers that genuinely work, and a plain statement of what no platform on earth can do, because a false promise is more dangerous than a known gap.
Why "how do I prevent piracy" is the wrong question
The question is built to produce a wrong answer. Absolute prevention is impossible: anyone running a screen recorder gets a copy, anyone pointing a phone at the screen gets a copy, and the browser exposes no API that stops either. A platform promising otherwise is selling you reassurance, not protection.
The useful question is: what does leaking cost, and will I know who did it? Those are two variables you can genuinely control. And most leaks need no technical skill at all: a link posted in a group, a file downloaded and re-uploaded, one account used by ten people. Three simple behaviours, each with a different remedy.
Layer one: entitlement before technology
Before any talk of links and encryption there is one question: who is entitled to this content?
Entitlement comes from a purchase or from a grant you issue, it is stored on the learner's record, and every layer above builds on it. This is not administrative trivia. If entitlement is open or vague, no lock above it means anything. I have seen academies buy expensive protection while the lesson URL itself worked for any visitor.
Start here: open your learner records and ask, of any lesson, who can open this right now and why. If that question has no single clear answer, piracy is not your problem yet.
Layer two: a link that expires, not one that lives forever
This is where the common mistake sits. A video on public storage has a permanent URL: whoever obtains it opens it whenever they like, forwards it to whoever they like, and there is no way to pull it back. One link copied by one learner is enough to make your course available to an entire group.
The alternative is a short-lived signed link: the content sits in private storage that serves no permanent URLs at all, and when an entitled learner opens their lesson a personal link is minted that expires within minutes. Copy it, forward it, and it arrives dead.
Small difference to explain, large difference in effect: a stolen link is worthless minutes later. That alone closes the most common leak route there is: re-posting the URL.
Layer three: make the content carry the viewer's identity
If screen recording cannot be prevented, let the leaker record their own identity along with it.
The watermark displays the viewer's name, email, phone and live viewing time over video, images and files. Anyone recording their screen records their own details in the same frame. It does not stop them technically, but it changes their arithmetic completely: the copy they are about to share carries their name.
To be precise: this is a display layer, not a mark burned into the file. Anyone who obtains the file another way is not followed by it. The real value is on the normal path (watching inside the platform), which is the path 95% of people take.
Alongside it: the download button appears only when you allow that specific file to be downloaded, and when you disallow it the PDF viewer's toolbar disappears with it, closing the save-by-another-route hole.
Layer four: the device limit, and what it actually means
One account shared by ten people is the leak nobody feels is a leak. A device limit addresses it: each account has an allowed number of devices (two by default), the most recently used devices stay, and a new device pushes out the oldest.
The effect is practical: passing one account around a large group becomes genuinely annoying, because each person keeps evicting the last.
And here is where most people get it wrong: this is not a concurrent-viewing limit. It caps how many devices are bound to the account, not how many windows are open at the same instant. Also worth knowing before the support tickets arrive: clearing browser data or using a private window counts as a new device.
Layer five: a trace you can go back to
The four layers above reduce the probability. This one answers the question after the fact.
The content view log records what was viewed in an append-only way, so you have a trace to consult when you suspect something, instead of an impression and a guess. When you ask "who opened this lesson this week", the question has an answer.
Live sessions get one more layer: recordings are not published the moment a session ends. They stay withheld until the trainer releases them, so you review the recording before your learners see it.
What no platform can do, plainly
This is the most important section in the article, and the one other platforms are quietest about.
- There is no DRM. Content is not encrypted in a way that prevents playback outside an approved player.
- Nothing prevents screen recording or screenshots. Whoever records their screen gets a copy. Full stop.
- A device limit is not a concurrent-stream limit. Explained above.
- The watermark is not burned into the file. Explained above.
Why say this out loud instead of staying quiet? Because a trainer who builds a decision on a false promise discovers the truth at the worst possible moment. Candour here is not weakness: it is the difference between a vendor who wants your signature and a partner who wants you to stay.
Table: which layer handles which behaviour
| Behaviour | Layer that handles it | Effect |
|---|---|---|
| Posting the lesson link in a group | Short-lived signed link | Genuinely closed |
| Downloading a file and re-uploading it | Per-file download control | Closed unless you allow it |
| Sharing one account around a group | Device limit | Becomes annoying and impractical |
| Screen recording | Viewer-identity watermark | Not prevented, but attributable |
| Suspicion with no evidence | View log | Becomes a question with an answer |
Three common mistakes
First: investing in the lock before the entitlement. Advanced protection over open access is an armoured door in a paper wall.
Second: expecting absolute prevention. Anyone pricing and planning on the assumption that content will never escape is heading for disappointment. Build on the assumption that a small share will leak, and put the value of the subscription in what cannot be copied: follow-up, grading, live sessions, the certificate, the community.
Third: allowing downloads without thinking. Every file you allow to be downloaded leaves the protected circle permanently. Ask of each one: does the learner genuinely need this outside the platform?
Where to start
Protection on Dwrrah is available on every plan and works with no setup. What you configure is per-file download permission, the device limit, and turning the watermark on.
And if what you sell is a fully recorded course, put its value in what cannot be copied: follow-up sessions, graded assignments, a verifiable certificate. The content may escape; those do not.
You can try all of it during the free trial before committing to anything.
Frequently asked questions
Can any platform stop screen recording?
No. Anyone running a screen recorder, or pointing a phone at the screen, gets a copy, and the browser exposes no API that prevents it. Anyone promising total prevention is selling you a fiction. The realistic goal is to raise the cost of leaking and make every copy attributable.
What is the difference between a signed link and a permanent one?
A permanent URL works for anyone who obtains it, forever. A signed link is minted for an entitled learner at the moment they open the lesson and expires within minutes, so copying it into a group delivers a dead link. Small difference to explain, large difference in effect.
Is the watermark burned into the video file?
No. It is a display layer over the content carrying the viewer's name, email, phone and the time they watched. Anyone recording their screen records their own identity with it, which is the deterrent. It is not burned into the file, so it does not travel with a copy obtained another way.
Does a device limit mean a concurrent-viewing limit?
No, and this is where most people get it wrong. A device limit caps how many devices are bound to the account, with the most recently used pushing out the oldest. It does not measure how many windows are open at the same instant. Clearing browser data or using a private window also counts as a new device.
Where does protection actually start?
With entitlement, not with technology. The first question is who deserves access to this content. Entitlement comes from a purchase or from a grant you issue, it is stored on the learner's record, and every layer above it builds on that. If entitlement is open, no layer above it means anything.