Skip to content
digitalsign.co

Security

Last updated October 2, 2026

DigitalSign is operated by Nead, LLC. This page summarizes how we protect the service and your data. For our commitments in contract form, see the Terms of Service, Data Processing Addendum and SLA.

Hosting and infrastructure

  • The application and database run in the European Union (Germany). Media is stored with Cloudflare R2 and delivered over Cloudflare's network.
  • All traffic to the app, the API and the players uses HTTPS (TLS).
  • Our full list of service providers is published at sub-processors, with 30 days' notice before we add one.

Protecting data

  • Credentials are never stored in plain text. Sign-in links, sessions, API keys and SCIM tokens are stored only as one-way hashes. Secrets you give us, such as data-connection credentials, single sign-on client secrets, webhook signing secrets and two-factor secrets, are encrypted with AES-256-GCM before they are saved.
  • Media files are private: screens and browsers receive short-lived signed links.
  • Webhooks we send are signed (HMAC-SHA256) so you can verify they came from us.
  • We don't use your content or data to train AI models.
  • Card payments are handled by Stripe; card numbers never reach our servers.

Access control

  • Six roles (Owner, Admin, Designer, Publisher, Location Manager, Viewer), per-person permission adjustments, and access limited to specific locations.
  • Optional approval chains before content goes live (Pro).
  • Passwordless sign-in by single-use email links, with optional two-factor authentication from an authenticator app on every plan.
  • On Enterprise: single sign-on with SAML 2.0 or OpenID Connect, the option to require it, automatic provisioning and deprovisioning with SCIM, and a policy requiring two-factor for email sign-in.
  • Screens authenticate with their own device tokens, which can be revoked at any time by unpairing.

Audit and accountability

  • Changes to screens, content, schedules, members, roles, billing and security settings are recorded in an append-only audit log, along with sign-ins and provisioning events.
  • Enterprise customers can search and filter the full history and export it as CSV or through the API.

Availability and backups

  • Screens keep playing their cached content if the internet connection or our service is interrupted.
  • Every component is checked every minute; live and 90-day uptime is public on our status page. Enterprise plans include a 99.9% uptime SLA with service credits.
  • The database is backed up nightly to storage with a different provider from our servers, and backups are kept for 35 days.

Your data, your control

  • Owners and admins can export everything (records, members and media) as a ZIP at any time from Settings.
  • An owner can delete the organization. It is locked and billing stops at once, and everything is permanently erased after 30 days unless restored.

Certifications and questionnaires

We don't hold SOC 2 or ISO 27001 certification today. We're glad to complete your security questionnaire and to sign our DPA, which includes the EU Standard Contractual Clauses. Email [email protected].

Reporting a vulnerability

If you believe you've found a security issue, email [email protected] with the details and steps to reproduce. Please give us reasonable time to fix it before disclosing it, and don't access other customers' data or degrade the service while testing. We'll acknowledge your report within two business days.