logo

Security

Fyresign offers secure, cloud-based digital signage with encrypted data, remote management, and fleet control. Built for scalability, privacy, and full control.

Security and Privacy in Fyresign: Built for Safe and Scalable Digital Signage

Fyresign is designed from the ground up with security and privacy as key components. As a cloud-native platform, it runs in a secure Kubernetes environment hosted in the EU, ensuring that all EU/EEA data remains within the region. This commitment to data localization is part of Fyresign’s core privacy strategy.

Data Encryption – At Rest and In Transit

All data stored within Fyresign, including databases and message queues, is encrypted by Google Cloud. Only authorized Google Cloud nodes can decrypt this information. Uploaded content such as images and videos is also stored in encrypted buckets and assigned unique 128-bit IDs. These files can only be accessed using exact, secure URLs.

When it comes to data in transit, Fyresign uses modern encryption standards. Communication between systems uses TLS-encrypted gRPC and HTTP protocols. Internally, services within the Kubernetes cluster communicate using mutual TLS (mTLS), signed by FyreSign’s own root certificate. This ensures a secure flow of information across the entire platform.

Secure Authentication and Access Control

Fyresign is built with focus on secure and controlled access. We use modern authentication with OAuth 2.0 and PKCE to ensure that login processes are handled securely. Access tokens are time-limited and expire after one hour, reducing the risk of unauthorized use.

Passwords are securely encrypted using bcrypt and cannot be converted back to their original format. In addition, all API endpoints are protected with access control, ensuring that only authorized users and systems can access the appropriate information.

For organizations that want a simpler and more seamless login experience, Fyresign also supports Single Sign-On (SSO). With SSO, users can sign in using their existing work account, while the organization maintains control over users and access permissions.

Protected Content Playback and Device Lockdown

The playback experience is just as secure. Players are essentially web clients locked to display only the authorized content. For Chrome OS devices, a custom Chrome app handles device authentication and ensures the player only connects to approved services. Display configurations and content updates are securely delivered via the SocialScreen API.

Admin Interface with Secure Login

All user administration is handled through a secure web portal. Logging in is protected by OAuth 2.0 PKCE and operates via a dedicated authentication service. The admin panel lets users manage content, devices, and user roles without compromising system integrity.

Fyresign combines flexibility with top-level security, so businesses can scale their signage without sacrificing control or compliance.