Blog / Security / Self-Hosted Digital Signage Data with Brix Edge

Self-Hosted Digital Signage Data with Brix Edge

Brix Edge keeps your documents on your own server while Brix runs the screens. Who needs it, what it stores, what it costs and how to run it.

Security
On this page
  1. Who uses it
  2. What stays on your server
  3. How you check it yourself
  4. What it costs
  5. Run it
  6. When it is not the right fit

Brix Edge is a small, free server you run on your own network so your documents never go to the Brix cloud. Each screen asks Brix Edge for its own document and shows it; Brix stores only the screen's id and your server's address. Brix Edge is open source under the MIT licence, needs no licence key and makes no outbound connection, so it adds no recurring cost of its own. The screens still need a Brix plan.

Who uses it

  • Government and defence suppliers with controlled drawings or data that must stay inside their network.
  • Banks and financial firms whose security review approves a system by what it stores.
  • Manufacturers showing released work instructions and drawings at each station.
  • Healthcare and labs with protocols that include personal information.
  • Any team that runs its own servers and wants documents to stay on them.

The need is the same in each case: the screen shows the current released document, and nothing outside the building holds a copy.

What stays on your server

  • The documents, their file names and the folders they live in.
  • The file that says which screen shows which document.
  • The access log: one JSON line per request (time, address, token, status, bytes, file served), written by software you run. Send it to your SIEM.

Brix holds the screen's id and an address template such as http://brix-edge.plant.example:8787/drawings/{{screen.id}}. No file name, part number or document enters Brix. The screens are sealed: Brix takes no screen capture of them and refuses one if a screen sends it.

What stays in Brix: the CMS, scheduling, screen management and the players. Brix Edge is not a self-hosted copy of Brix.

How you check it yourself

None of this needs an account or a call to Brix.

  • Read the source. Five files, no dependencies: github.com/BenLoveitt/brix-edge.
  • Run the tests. node --test runs 26 tests. One fails the suite if any outbound network call appears in the source.
  • Block its internet access. Nothing changes.
  • Set a canary. Map a token no screen is given. If brix_edge_canary_requests_total moves, something other than your screens is asking, and the log has its address.
  • Build it yourself from a release tag you have read. Brix Edge does not update itself.

What it costs

Brix Edge is free: MIT licence, no key, no fee, and it runs on a server you already own. The screens are billed like any other Brix screen: $8 per screen per month, or $6 billed annually. Setup is done with our team.

Run it

Docker:

  1. Clone the repository and check out a release tag you have read.
  2. docker build -t brix-edge:0.1.0 .
  3. docker run -d -p 8787:8787 -v /srv/drawings:/data/drawings:ro -v /srv/stations.json:/data/stations.json:ro brix-edge:0.1.0
  4. docker exec brix-edge node src/edge.mjs verify. Exit 0 means every station has a document.

stations.json maps each screen id to a folder or file. A folder serves released.pdf if present, otherwise the newest PDF.

Windows Server with IIS: no Node, no container, nothing of ours on the server. The windows/ folder holds one web.config and scripts to install, test and check for canary hits. Run the installer in an elevated Windows PowerShell 5.1.

When it is not the right fit

When a policy forbids any cloud service near the screens, including the service that tells a screen what to play. Brix is a cloud service. Brix Edge keeps the documents on your network; it does not make Brix run offline from the internet.

Talk to us to set it up. Background: sensitive documents on screens without the cloud.

Try Brix free for 7 days

$6 per screen per month billed annually ($8 month to month). No card needed.

Start free trial