Cloud-Enabled Studios logo

About Us

bg image

Partner Collaboration

Prevent Asset Leakage & Improve Efficiency

Isolated and auditable production environments for studio partners to minimize IP/code leaks while maximizing seamless collaboration with the main office.

Partner Collaboration
painpoints
Hard to Balance between Security and Performance
Outsourcing game production is difficult to manage and at high risk of asset leakage.
01

The outsourced R&D environment has high asset leakage risks

02

Long UE launching time, due to lack of accessing DDC cache, results in serious waste of labor costs

03

We have to make a hard trade-off between security controls, risk of data leakage and low R&D efficiency

Cloud-Enabled Studios Partner Collaboration Solution

provides an isolated and auditable production environment for outsourcing partners to minimize IP/code leaks while maximizing seamless collaborations with customers.

scenarios
Tailored Design for Different Scenarios
Tailor the design for different scenarios, there is no one-size-fits-all
what is vdi as a service image

Ad-Hoc, Temporary Outsourcing

For ad-hoc outsourcing tasks, we usually hire a small team. Small teams usually do not have strong IT skills to protect their work. They might just work in any environment that comes with weak security protection. In this situation, we suggest deploying a well-controlled workstation in the cloud and authorizing those workers to access it remotely. Because there is no work on artists’ local workstations, this will greatly improve the protection of work assigned and reduce the opportunities for data leakage.

what is vdi as a service image

Mid-Term Outsourcing

Vendors normally work from a partially trusted environment. The partner normally manages the work environment alone, and game studios can not 100% trust its technical measures and processes. In such a partner environment, a project-based VLAN isolation should be implemented and equipped with a basic vulnerability scan and XDR capability. When we have those basic controls, the studio should be confident in deploying some non-sensitive data and cache into the partner’s facilities. A leased line or S2S VPN between the studios’ environment and partners’ facilities can be set up. Tight controlled, well-planned firewall rules (port, protocol, application,…) should be deployed.

what is vdi as a service image

Strategic Long-Term Outsourcing

In such a long-term partnership situation, the studio and partner are not only contracted in a project–based scenario. There could be investment and management-level relationships. The studio can fully trust the security measures and controls taken by the vendor. Studio and vendor can discuss a common ground for all sorts of security controls. Given the above situation, the studio can deploy most R&D facilities into a partner facility, such as Perforce Edge, to achieve the greatest efficiency and user experience. We can also feel peace of mind in enabling partners to develop games on their physical workstations. For a well-controlled outsourcing, by leveraging hybrid cloud, you can:

  • Connect partner site to core R&D‘s cloud environment easily
  • Build a local server farm for high-speed cache
  • Turn off office internet access, route to cloud’s well-controlled internet GW
what is vdi as a service image

Build Your Core R&D Environment in the Cloud

By leveraging the cloud, building a partner-oriented R&D core anywhere in the world is very straightforward. We can deploy development workstations, various CICD tools, core assets, and code depots there. Furthermore, we must provide a tightly controlled internet outbound access capability and route all partners’ internet traffic to this exit to ensure no data leakage. With the connection from the partner to the core R&D environment, they can also leverage the security measures required in the core part, such as Vulnerability Scan, SIEM, and centralized access control.

solution
Improve the Efficiency with Geo-Dist DDC, Global Perforce, Data Sharing (anyDrive)
what is vdi as a service image
Secure
  • Fine granularity authorization and permission control, SSO
  • Controlled Internet access and inbound-only file sharing (anyDrive) to prevent data leakage
  • Avoid data leakage through GWS access control, authority control, and public network access control
  • Isolate core R&D depot and Partner depot to prevent data leakage
what is vdi as a service image
Fully Customizable Solution

what is vdi as a service image
High Efficiency

Enable partner productivity on par with core R&D via Geo-distributed DDC, anyDrive, and P4Anywhere.

When we count on outsourcing for your game production, we naturally need to care about their productivity. There are three basic tools to boost the productivity.
what is vdi as a service image
Make Sure the Partner Can Access the DDC Cache

DDC is a critical component that has a dramatic impact on productivity. DDC is normally built from a central daily build system and updated by users centralized there. Geo-distributed DDC can help distribute the DDC from the central site to the branch site and remote users. This will save 10-60 minutes per workday for every remote, branch, and partner artist.

what is vdi as a service image
Make the Perforce Depot or Git Depot Available to Partners

Sharing a common baseline is critical to avoid chaos and to make your game development milestone predictable. We can set a proxy or Edge in a partner environment and control what contents to replicate to the partner environment. The lease-line or site-to-site VPN will facilitate this replication at a low cost. We can tailor the design to your specific situation, and furthermore, P4Insights and P4Booster can manage those extensions to the partner site in a holistic approach.

what is vdi as a service image
Build a System to Make Asset Exchange Easy

When you extend your business to partners, assets, or any data, exchange is a common scenario. As a common scenario, we often must provide an easy inbound-only data transfer tool to avoid data leakage. By leveraging CES Drive, you can easily implement a fine-granularity-controlled data exchange system. It provides fine security control and a fast exchange capability, such as 20MB/s.

solution
Apply Tight Security Control

When you extend your connection to a partner site, security is normally a big concern for most studio owners. Per the extensive practice from the Cloud-Enabled Studios team, a set of security controls had been applied, such as micro-segmentation, identity AAA, access control, network boundary protection, data SOD, and protection, etc. Here is a comprehensive list of typical controls managed by Cloud-Enabled Studios security experts:

what is vdi as a service image
Security Controls (Invisible to Users)
  • SIEM, complete log
  • VPC/Security group micro-segment
  • Data Encryption in transit, Data Encryption at rest
  • Internet exit control, No data passing to any SaaS service
  • CSPM curated Cloud Access control
  • Regular Vulnerability Scan
  • Bastion-agent-based host maintenance
  • Disk encryption, Snapshot & backup
what is vdi as a service image
Security Controls (Visible to Users)
  • NGFW access control, IDS
  • Single sign-on
  • anyDrive read-only access control
  • Whitelist-based outbound internet access control, no inbound internet access
Make an Enquiry

Fill out the information below and our global sales team will reach out to you to find out how we can work together.

By checking this box, I agree to receive communications via email regarding news, promotions and offers relating to Tencent CES (Cloud-Enabled Studios) from Tencent America LLC.
I have read and agree to the Terms of Service *
I have read and acknowledge the Privacy Policy *