Trust

Screens are IT infrastructure

A signage account can reach every lobby and canteen in the company, so it is treated like the rest of your estate: strong sign-in, least privilege, an audit trail, and data that stays in Europe.

Access control

Two-factor sign-in

TOTP enrolment and challenges per workspace, with an organisation-level requirement when you want it enforced.

Idle session limits

Configurable idle logout so a browser left open on a shared workstation does not stay signed in.

Granular permissions

Per-member capability overrides on top of roles, plus invitations that expire and can be revoked.

SSO on request

SAML single sign-on can be configured for your identity provider on Business plans.

Accountability

Full audit log

Publishes, schedule changes, device commands, member changes and support sessions are all recorded with actor and time.

Visible support access

When our staff or your reseller opens your workspace for support, it is logged and a banner shows it on screen.

Least privilege by default

Distributor and reseller staff get read-only visibility unless a workspace grants more; platform-light admins cannot delete accounts.

Data hygiene

Screenshots, health history, link clicks and incidents all have retention windows and scheduled pruning.

Hosting and data protection

SignTempo runs on EU-operated infrastructure and stores workspace data, media and playback telemetry in the EU. A GDPR data processing agreement is included on every paid plan.

Media lives in private storage and is delivered to players with short-lived signed URLs. Public endpoints used by players are limited to what a screen needs: adopting a pairing code, fetching its own content, and reporting its own health.

If you need a security review, a DPA countersigned, or answers to a vendor questionnaire, ask us and we will send documentation rather than a brochure.

Send us the questionnaire

We would rather answer your security review before you buy than after.