
Last updated: September 2026
Your Screens Are Connected. Here’s How We Keep Them Protected.
Digital signage screens are no longer standalone displays; they’re connected endpoints running on cloud platforms, Wi-Fi networks, and IoT ecosystems. That connectivity makes them powerful, but it also makes security a real concern.
In 2025, a widely reported incident saw digital menu boards at nearly 300 quick-service restaurants in Canada hijacked to display unauthorized messages. The breach went viral and caused significant brand damage. It was a clear reminder: any screen connected to a network is a potential target.
At EasySignage, security isn’t an afterthought. It’s built into every layer of the platform, from infrastructure and encryption to access controls and billing. Here’s a detailed look at how we protect your content, your data, and your screens.
EasySignage runs on Google Cloud Platform (GCP), the same secure-by-design infrastructure that Google uses to protect its own products and billions of users worldwide.
By partnering with GCP, we take advantage of:
Google Cloud holds industry-leading third-party certifications covering the infrastructure we run on, including:
We rely on GCP to protect sensitive workloads while meeting complex compliance requirements, so you don’t have to manage that burden yourself.
Infrastructure certifications only cover the layer underneath. EasySignage also holds its own independent certifications, audited against the same frameworks and held by EasySignage as an organisation:
This distinction matters when you are comparing signage vendors. Many platforms cite ISO 27001 or SOC 2 when the certificate actually belongs to their cloud provider. Ours are in our own name, and certificates and audit reports are available on request.
You do not have to take our word for any of this. We publish our security posture at trust.easysignage.com .
The Trust Center shows:
The control list is refreshed automatically from our compliance monitoring rather than written by hand once a year, and the page shows when it was last updated. If you are working through a vendor security questionnaire, most of it can be answered from that page before you contact us.
For an additional layer of protection, EasySignage integrates with Cloudflare , one of the world’s largest and most trusted security and performance networks.
All EasySignage web assets benefit from always-on DDoS mitigation, powered by Cloudflare’s intelligence from its global network. This protection works alongside our cloud Web Application Firewall (WAF), bot management, and L3/L4 security services to defend against cyber threats of all kinds, automatically and in real time.
Our WAF protects against common attacks that target vulnerabilities like SQL injection (SQLi), cross-site scripting (XSS), and more. With the OWASP Core Ruleset enabled by default and Cloudflare’s Managed Ruleset for emerging threats, EasySignage stays protected against both known and zero-day vulnerabilities, without requiring manual intervention.
EasySignage encrypts your data at every stage, not just when it’s moving, but also when it’s stored.
All communications between EasySignage components are protected using TLS/SSL with 256-bit encryption. This covers:
Even if data is intercepted in transit, it remains completely unreadable to unauthorized parties.
All stored data, including your content, configuration settings, metadata, and databases, is encrypted at rest using AES-256 encryption, the same standard used by banks and government agencies. This means your data is protected even at the storage level.
Every cloud-managed signage platform lives or dies on how it authenticates. EasySignage handles it in layers, from device-level authentication up to user-level access controls.
Every digital signage player is automatically authenticated when it connects to EasySignage services through Google Cloud Platform:
At the account level, EasySignage provides a full set of access management tools built for teams and enterprise deployments:
All of it is self-service. SSO, MFA enforcement, and access restrictions are configured from your own dashboard, with no support ticket and no sales call required.
With SSO, your team signs in using company credentials instead of a separate EasySignage password, and account control stays inside your identity provider. Any provider that supports SAML 2.0 or OpenID Connect works, including Microsoft Entra ID (Azure AD), Okta, OneLogin, Ping Identity, Google Workspace, JumpCloud, and Auth0.
Setup happens under Settings → Single Sign-On:
Once a domain is verified, users get in three ways: a shareable SSO login link you can put on your intranet, a Log in with SSO button on the login page, or automatic detection when they type their work email into the normal sign-in form. New users are created on first sign-in through just-in-time provisioning, so you do not have to invite people one by one.
Step-by-step instructions: Single Sign-On setup guide , with provider-specific walkthroughs for Google Workspace , Microsoft Entra / Azure AD , and OneLogin .
Verifying a domain proves you own it. Enforcing it closes the back door.
After verification, an Enforce SSO for these domains switch appears in the domain verification panel. Turn it on and:
This is the control that stops an ex-employee’s saved password, or a personal Google account created against a work email address, from remaining a route into your signage. Remove someone in your identity provider and their way into EasySignage goes with it.
You can attach multiple email domains to one SSO configuration. Each domain has to pass its own DNS verification.
EasySignage MFA uses authenticator apps (TOTP). There is no SMS and no phone number involved, and the codes still work when the phone has no signal. It works with Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden, and any other TOTP app.
Step-by-step instructions: Two-Factor Authentication guide .
Permissions are granted to teams, and each user belongs to a team. The Administrators team has full access and cannot be edited or deleted. Every other team is yours to define.
A team can be restricted to its own playlists, and screen access can be limited using tags, so a regional manager sees only the screens in their region. Administrators decide who can view content, edit playlists, publish to screens, manage users, and open analytics.
See the Teams and Users guides.
When you connect EasySignage to your own systems, API keys are created under Settings → API Keys and scoped area by area. Screens, groups, video walls, playlists, channels, zones, sync groups, schedules, folders, and media assets are each set to No access, Read only, or Full access.
A key is bound to a single account, is shown once at creation and cannot be retrieved afterwards, and can be deleted the moment you stop needing it. API access is included with the Premium plan.
See the API Keys guide .
EasySignage is a multi-tenant platform built with strict logical isolation between accounts. Every customer’s data is completely separated: your screens, playlists, media, and analytics are only accessible to your account. There is no cross-account visibility or access, ever.
Beyond infrastructure-level protections, EasySignage gives you direct control over who can access your account through built-in Access Restriction settings.
These restrictions are available under Settings → Security in your EasySignage dashboard and let you lock down account access based on specific criteria. Once enabled, only users who meet the defined rules can log in and manage your account. The same page carries the Require MFA for all sub-users switch described above, so account-wide MFA, IP rules, and country rules are all set in one place.
IP Access Restrictions let you limit account access to specific IP addresses only. Any login attempt from an unlisted IP address will be blocked immediately.
You can add up to five IPv4 addresses, entered one at a time. An Add My IP button fills in your current public address, which is the safest way to avoid locking yourself out before switching the restriction on.
Important notes:
Always ensure at least one trusted IP address is saved before enabling this feature.
Country Access Restrictions let you limit account access to users from specific countries only. Any login attempt from a country not on the list will be blocked.
Important warning:
If you enable country restrictions without adding any countries to the list, all countries will be blocked, including yours. Always add at least your own country before saving changes.
For help configuring your security settings, visit our Security Settings Guide .
These access controls are especially valuable for organizations managing signage networks across multiple locations. They add a practical layer of protection on top of EasySignage’s infrastructure-level security, making it significantly harder for unauthorized users to access your account, even if credentials are compromised.
EasySignage is built with a privacy-first approach. Here’s what that means in practice:
If you use EasySignage’s AI-powered audience analytics, you can be confident that privacy is respected:
You retain full ownership of all content, media, playlists, schedules, analytics, and account data stored within EasySignage. Your data is yours; we just help you display it on screen.
EasySignage operates an ISO/IEC 27001:2022 certified Information Security Management System and holds a SOC 2 attestation. On top of those certifications, we align our controls with the regulatory frameworks that matter for regulated deployments:
These sit alongside the EasySignage certifications (ISO/IEC 27001:2022 and SOC 2) and the GCP infrastructure certifications (ISO 27001, SOC 2, PCI DSS, CSA STAR) covered above.
For the live control list, current framework status, and to request the SOC 2 report, see the EasySignage Trust Center . For more details, see our Privacy Policy and HIPAA Compliance pages.
Beyond infrastructure, EasySignage applies security hardening at the application level:
Security isn’t a one-time setup; it requires ongoing vigilance. EasySignage maintains:
You can review your own account’s trail under Settings → Logs. It records user actions across the account, can be searched and sorted by column, and exports to CSV so you can keep it in your own retention or review process. See the Account Logs guide .
These tools give both EasySignage and its customers visibility into what’s happening across their signage network at all times.
EasySignage partners with Stripe for all billing and payment processing. This means:
For more details about Stripe security measures, please refer to Security at Stripe .
The digital signage industry is growing fast. In 2026, screens are increasingly treated like enterprise IT endpoints, and security expectations have grown to match.
Modern best practices for digital signage security include network segmentation, role-based access controls, encrypted content delivery, regular software updates, and clear audit trails. EasySignage is built with these principles at its core.
Whether you’re running a single screen in a café or managing hundreds of displays across a retail chain, EasySignage gives you enterprise-grade protection without the complexity.
For a complete technical overview of our security posture, visit our Security and Trust page, or go straight to the Trust Center for our certifications and control list.
Ready to run your screens on a platform that takes security seriously?
Sign up today and get 1 free screen forever, no credit card required.