A digital signage security questionnaire is the list of questions your IT or security team sends a signage vendor before anyone signs. It usually covers ten areas: sign-in, access control, encryption, hosting and data location, the players on your network, logging, backups and recovery, incident handling, independent assurance, and contract terms such as the data processing agreement and exit.
Below is each area, the questions buyers ask, what a good answer looks like, and the evidence to request.
What risks is IT checking for?
A signage system is a cloud account that many people sign in to, plus a small computer behind every screen on your network. The real risks are ordinary ones:
- A former employee still signs in and changes what a store shows.
- A shared admin password is used by five people, so nobody knows who changed what.
- A player on the guest Wi-Fi is the weakest device in the building.
- Someone puts an internal document on a screen that faces the public.
- The vendor closes and the content cannot be taken out.
A good questionnaire asks about each of these in plain terms. A long list copied from a data-centre audit gets long answers that do not help you decide.
1. Sign-in and identity
Questions buyers ask:
- Does the product support single sign-on (SSO) with our identity provider, such as Microsoft Entra ID, Okta or Google Workspace? Which standard: SAML 2.0 or OpenID Connect?
- Is SSO included on every plan, or only on an enterprise tier?
- Can we require SSO for everyone on our email domain, so a local password stops working?
- Can we require two-factor authentication (MFA) for every user?
- Can access follow our HR data, for example a person's job title and location in Okta, so nobody raises a ticket to get access?
What a good answer looks like: the vendor names the standard it supports, says who sets it up (you, or their services team for a fee), and says what happens to existing passwords when SSO is required. Ask whether the vendor verifies that you own the email domain before a connection goes live. Without that check, another customer could claim your domain.
If your policy says SAML only, ask the vendor before the RFP goes out. Many signage products support OpenID Connect, which Entra ID, Okta and Google Workspace all offer, and your identity team may accept it.
2. Roles and access
Questions buyers ask:
- Can a store or site manager see and change only their own screens, while head office sees the whole network?
- Can we build our own roles from individual permissions, or only pick from fixed ones?
- Can content wait for approval before it goes on a screen, and can approval have more than one step?
- Can billing staff see invoices without seeing screens or content?
- Can local teams edit the text on a design but not the logo?
What a good answer looks like: access is granted at a place in your organization (a region, a store, a floor) and covers everything under it. Locks on designs are enforced by the server, not only hidden in the interface. See digital signage user permissions by location for how the hierarchy usually works.
3. Encryption
Questions buyers ask:
- Is data encrypted in transit? Which TLS versions are accepted?
- Is data encrypted at rest, including backups?
- Are credentials for connected accounts (for example a Microsoft 365 or Google connection) encrypted separately?
- Is our data encrypted with a key specific to us, not shared with other customers?
What a good answer looks like: TLS 1.2 or higher on every connection, including the connection between the player and the cloud; encryption at rest on the database, the file store and the backups; and a clear yes or no on a customer-specific key. Customer-managed keys are rare in signage. If you need one, make it a separate, explicit question.
4. Hosting and data location
Questions buyers ask:
- Where is the service hosted, and by which provider?
- Can we choose the country or region where our data is stored?
- Is the software multi-tenant? How is one customer's data kept from another's?
- Is there an on-premises or private-cloud version?
What a good answer looks like: the vendor names the hosting provider and the regions it offers, and says which of those is backed by a contractual jurisdiction and which only sets the storage location. Those are different promises. For multi-tenancy, ask how a request for another customer's data is refused.
5. The players on your network
This section is specific to signage, and it is the one generic questionnaires miss.
- Which devices run the player, and is any of them tied to this vendor only?
- What network access does a player need: domains, ports, protocols, bandwidth? Does it work behind a proxy?
- Does the player open any inbound port?
- How do players get software updates, and can we control when?
- Can staff at the site exit the player, change its settings or plug in a USB stick?
- What does a screen show when the internet drops?
What a good answer looks like: a written list of the domains and ports the player uses, so your network team can write the firewall rule once. Players that only connect outwards over HTTPS are the easiest to approve. Put players on their own network or VLAN, not the guest Wi-Fi. Ask for the offline behaviour in writing: content cached on the device keeps playing, and a screen with nothing cached shows a fallback rather than an error.
6. Logging and audit
Questions buyers ask:
- Does the product record who changed what, and when, including sign-ins and failed sign-ins?
- Can anyone edit or delete an entry in the log?
- How long is the log kept, and can we export it?
- Can we see what played on each screen, and when (proof of play)?
What a good answer looks like: an append-only audit log kept for years, not days, with an export you can hand to an auditor.
7. Backups, recovery and uptime
Questions buyers ask:
- How often is data backed up, and how far back can it be restored?
- What are your recovery point and recovery time objectives (RPO and RTO)?
- Is deleted content recoverable by us, without a support ticket?
- Is there a public status page? How are outages and maintenance announced?
- Do you offer a contractual uptime SLA with service credits?
What a good answer looks like: specific numbers for restore window, RPO and RTO; a recycle bin for mistakes; and a status page you can check without asking. If an SLA with credits is a must for you, say so in the RFP. Many signage vendors, especially at per-screen prices, do not offer one.
8. Incident handling and vulnerability management
Questions buyers ask:
- How will you tell us about a security incident that affects our data, and how fast?
- How do we report a vulnerability to you? Is there a security.txt?
- How are security fixes found and applied, and how fast for a critical one?
- Who at the vendor can access our data, and is that access logged?
What a good answer looks like: a named security contact, a published way to report a problem, and a written commitment on how quickly you will be told.
9. Independent assurance
Questions buyers ask:
- Do you hold SOC 2 Type II or ISO 27001? Can we see the report or certificate?
- Has an independent firm tested the product (a penetration test)? Can we see a summary?
- Will you fill in our standard form (for example SIG, CAIQ or HECVAT)?
What a good answer looks like: a clear yes with the document, or a clear no with what the vendor offers instead. A vague answer here is a warning sign. Many smaller signage vendors have no SOC 2 report. Decide in advance whether that is a pass or fail for your organization, and weigh it against the risk of the data involved: most signage content is posters and menus, not personal data.
10. Privacy, AI and contract terms
Questions buyers ask:
- Will you sign our data processing agreement (DPA), or share yours?
- Which sub-processors handle our data? Is the list published?
- If the product uses AI, is our data used to train models for anyone else?
- What insurance do you hold (cyber, professional indemnity), and what is the liability cap?
- When we leave, how do we export our content, reports and logs, and when is our data deleted?
What a good answer looks like: a DPA ready to send, a public sub-processor list, a plain statement on AI training, and an exit process with a date by which data is deleted. Large buyers often add payment terms (for example net 60), insurance minimums and a liability cap as pass-or-fail terms. Put those in the RFP, not after the demo.
How do you run the review without stalling the project?
- Send the questionnaire with the RFP, not after you pick a vendor. A fail on a must-have after the pilot wastes everyone's weeks.
- Mark each question Must or Should. Keep Must to the questions that would stop the purchase.
- Ask for evidence on the Musts: a screenshot, a document or a setting you can test in a trial account.
- Test the answers during the pilot. Turn on SSO and two-factor, create a store-level role, and check the audit log shows it.
- Record the gaps you accept, and who accepted them.
For the rest of the buying process, see the digital signage RFP template and the questions to ask a digital signage vendor.
How Brix answers these questions
Brix publishes its answers on the security page. In short:
- Sign-in: SSO through OpenID Connect (Entra ID, Google Workspace, Okta, Auth0 and others), set up by you on any plan. Domains are verified by DNS before a connection goes live. You can require SSO for your domain and require two-factor for everyone. Passkeys are supported.
- Access: an Owner role plus roles you build from individual permissions (or duplicate and change), access granted at places in your organization tree, multi-step approval, and design locks enforced by the server.
- Encryption: TLS on every connection, including player to cloud. Stored credentials for connected accounts are encrypted before they are stored.
- Hosting: on Cloudflare's network. You choose US, EU (Frankfurt), Oceania or Asia-Pacific at sign-up. Only the EU option is a contractual jurisdiction; the others set where data is stored.
- Logging: an append-only audit log kept for three years, exportable to CSV. Proof of play is included and off by default.
- Recovery: the database can be restored to any second in the last 30 days. Deleted items go to a recycle bin for 30 days. Screens keep playing from their cache when the internet drops. There is a public status page.
- Privacy: a DPA on request and a published sub-processor list. Data reached through connected apps is not used to train AI models.
Where Brix is not the answer: SSO is OpenID Connect only, with no SAML. Brix has no SOC 2 report or ISO 27001 certificate, no on-premises version and no contractual uptime SLA. If any of those is a Must in your policy, Brix will fail that row, and you should know before the demo.
Send your questionnaire to [email protected] and we answer it line by line, or book 30 minutes to go through your acceptance criteria.