SSO and MFA enforcement
Require single sign-on and multi-factor authentication per workspace, with session timeouts.
Trust
Data stays in the EU, every workspace is isolated at the database level, and the paperwork your IT department will ask for is generated from the platform itself.

Require single sign-on and multi-factor authentication per workspace, with session timeouts.
Restrict console access to known networks and approved email domains.
Super admin, distributor, reseller, customer admin and user — plus audited support impersonation.
Every action logged, retention configurable per workspace, exportable as CSV.
Standard menu presets per role, layered platform → distributor → reseller → workspace → user. Menus shape what people see; permissions stay enforced on the server.
Every sign-in recorded with time and context, and a per-user activity timeline for reviews and incidents.
Interactive kiosks are limited to allowed domains, reset the session when idle, and can require a PIN to leave the experience.
Database, media and backups hosted in the EU, with the region recorded in your policy.
Every table is scoped to a workspace with row-level security — not just an application filter.
Devices authenticate with scoped tokens and can be revoked or re-paired individually.
Generate a JSON pack with policy, roles, asset counts, compliance documents and recent admin activity.
SignTempo processes very little personal data: account details for the people who log in, and operational telemetry from players. Audience measurement is aggregate by design — impressions are modelled or counted, never identified.
You can name a data protection contact and a data export contact per workspace, set the breach-notification window you have agreed with your customers, and keep your DPA, subprocessor list and penetration test summary in the same register the evidence pack reads from.

Most of the answers are already generated by the platform; we will fill in the rest.