Security
How we protect your account, your content and the screens you run on DigiSignWall.
Last updated:
Encryption
All traffic between browsers, players and our infrastructure uses TLS 1.2 or higher. Stored content and database contents are encrypted at rest. HSTS is enabled, so browsers refuse to connect over plain HTTP.
Access control
Accounts support role-based permissions, so an operator who only schedules content cannot change billing or invite users. Enterprise plans add SSO via SAML or OIDC, IP allowlisting and enforced two-factor authentication. Every administrative action is written to an audit log you can review.
Tenant isolation
DigiSignWall is multi-tenant. Every query is scoped to a tenant identifier, and media is stored under per-tenant prefixes so one customer’s content is never addressable from another account. White-label resellers get the same isolation between their own downstream tenants.
Player security
Players authenticate with a pairing code and hold a device-scoped credential rather than user credentials, so a stolen screen cannot be used to sign into the admin console. Content is cached locally and continues playing if the network drops. A revoked device stops receiving content immediately.
Infrastructure and availability
We run on established cloud providers with automated backups and monitored, alerting infrastructure. Backups are tested by restore. Enterprise plans carry a 99.9% uptime commitment.
Responsible disclosure
If you believe you have found a vulnerability, email emailus@digisignwall.com with steps to reproduce. We will acknowledge within two business days and keep you updated until it is resolved. Please give us a reasonable window to fix the issue before disclosing it publicly, and do not access other customers’ data, degrade the service or run automated scans against production while testing.
We will not pursue legal action against researchers who follow this policy in good faith.
Reporting an incident
If you suspect your account has been compromised, change your password, revoke affected sessions from the admin console and contact emailus@digisignwall.com immediately.