Blog / Security / Sensitive Documents on Screens Without the Cloud

Sensitive Documents on Screens Without the Cloud

Why some organisations cannot put documents in a cloud signage system, who they are, and how a Brix screen shows them without Brix storing a copy.

Security
On this page
  1. Why a document stays on your network
  2. Who needs this
  3. The two ways to do it
  4. What to ask a signage vendor
  5. Where Brix fits

To show a sensitive document on a screen without putting it in the cloud, the screen must load it itself from a server on your own network. The signage system must store no copy, thumbnail or screen capture of it. Most cloud signage systems do the opposite: they store what they play.

Why a document stays on your network

A signage system normally stores what it plays. Upload a PDF and a copy lives in the vendor's storage, with thumbnails, previews and sometimes screen captures. For some content that is not allowed:

  • Contract terms. A customer agreement or export rule says the file stays inside your network.
  • Regulation. Controlled technical data, patient information or legal material has rules about where copies may exist.
  • Security policy. A new place that holds every document is a new system to review, audit and insure.
  • Risk. Every extra copy is one more that can leak, and one more to delete on request.

Who needs this

  • Manufacturers: work instructions, drawings and revision-controlled procedures at each station.
  • Aerospace, defence and their suppliers: controlled drawings.
  • Healthcare and labs: protocols and rosters with personal information.
  • Finance and legal: internal policy and case material.

The need is the same everywhere: the screen shows the current released version, and nothing else holds a copy.

The two ways to do it

  • Self-hosted signage. You run the whole signage system on your own servers. Nothing leaves your network, but you install, patch and back it up yourself.
  • A cloud system that points at your server. The cloud system stores only the page address. Each screen opens the page directly from your network, so the document never passes through the vendor.

The second way keeps the vendor's scheduling and screen management, but only works if the vendor also stops its own copies, previews and captures.

What to ask a signage vendor

  • Does your cloud open the page to make a preview or thumbnail? It should not.
  • Does the screen send you pictures of what it shows (live previews, health checks)? Can you switch that off per screen, and does your server refuse a picture if one arrives?
  • Can the address carry each screen's own id, so my server picks the document per station?
  • Does the screen need to reach the internet, and for what?

Where Brix fits

Brix is a cloud service that can show documents it never stores. Two settings work together, and our team sets them up with you.

  • On-network pages. Add the document as a web page at an address on your network, for example http://docs.plant.internal/station/{{screen.id}}. A private IP, or a name ending .local, .internal or .home.arpa, makes it an on-network page. Brix stores the address only: no preview, no thumbnail, no cached copy. {{screen.id}} becomes each screen's own id, so your server decides which document each station shows.
  • Sealed screens. A sealed screen sends Brix no screen capture, and Brix refuses one if it arrives. Without the seal, a screen showing an on-network page can still send a picture of it, so use both.

The screen shows your server's page live, as a browser does. To pick up a new version with nobody at the screen, have the page refresh itself, for example with a meta refresh tag. A Brix screen does not open a PDF file from your network: serve the document as an HTML page, or from a document system that shows it as one.

The document, its file name and the rule that picks each station's document stay on your network. The page address, scheduling, screen management and the players stay in Brix.

  • Cost: included in the one plan, $6 per screen per month billed annually, or $8 billed monthly.
  • Setup: done with our team. Book a demo to start.
  • Not the right fit: when a policy forbids any cloud service near the screens, including the one that tells a screen what to play. Brix itself does not run on your servers.

Try Brix free for 7 days

$6 per screen per month billed annually ($8 month to month). No card needed.

Start free trial