Security

StreamSign is built with enterprise security at its core. We protect your data, your content, and your screen fleet with practical security controls, governance features, and tenant isolation.

Encryption

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Authentication tokens are stored in HttpOnly secure cookies.

Authentication

Support for enterprise authentication options such as SSO, MFA, and passkeys where enabled for the organization.

Access Control

Role-based access control for content, player, administrative, and reporting workflows, with custom-role support in eligible environments.

Approval Workflows

Multi-step content approval workflows ensure no content reaches your screens without proper review and authorization.

Audit Logging

Audit history for authentication, content, and administrative actions, with retention and export behavior based on your environment.

Infrastructure

Hosted on AWS with isolated tenant data, automatic backups, and redundant systems. DynamoDB for database, S3 + CloudFront for content delivery.

Data Isolation

Full multi-tenant isolation ensures your organization's data is completely separated from other customers at every layer.

Incident Response

Operational monitoring, alerting, and incident-response procedures for security and platform events.

Compliance & Standards

We are committed to meeting the security and compliance requirements of enterprise organizations:

  • GDPR and privacy requests: Data deletion and export processes are available through the documented support paths
  • Security controls: Authentication, authorization, and audit features are built into the product surface
  • Operational review: Enterprise customers can review architecture, hosting, and security posture during commercial diligence
  • Application security: Engineering practices are informed by common web-security baselines such as OWASP guidance

Responsible Disclosure

If you discover a security vulnerability in StreamSign, we encourage responsible disclosure. Please report security issues to:

Security Team: security@aqili.ai
Please include a detailed description of the vulnerability and steps to reproduce. We will acknowledge your report within 48 hours.