Protect your account and your screens.
How Better Signage protects account access and media delivery, and how to report a security concern privately.
Updated September 22, 2026
Account and device access
Dashboard access uses password authentication and secure, HttpOnly session cookies. Passwords are stored as one-way hashes. Customer account requests are scoped to the signed-in account. Guest tickets use a private emailed link with access lasting up to seven days; anyone holding that link can access its ticket, so keep it private. The staff support queue requires platform-administrator access.
Apple TVs pair using a temporary, single-use code, then authenticate with device credentials. The service stores device-credential hashes; the app keeps its credential in the tvOS Keychain. Remove a screen from your account when it should no longer receive new playlists.
Use a unique password, protect access to your email inbox, and sign out on shared computers. Account settings provides password changes and session controls.
Media delivery
Cloud communication uses HTTPS. Media delivery is authorized by the service, and downloaded media is checked against its expected byte count and SHA-256 hash before the player treats it as ready.
Optional local peer delivery uses encrypted connections and authorized peers on the same account. Keep pairing codes, signed media links, and device credentials private.
These controls do not constitute an uptime guarantee, a claim of independent certification, or a promise that no security incident can occur.
Report a security issue privately
Email [email protected] with the subject Security report. Include the affected page or component, a clear description, and the minimum steps needed to reproduce it using an account you control.
Do not include other customers’ personal information, passwords, tokens, or private media. Avoid accessing other accounts or interrupting live service. If a screenshot is necessary, redact sensitive details before sending it.
Wes Walz handles reports directly. We do not publish a response-time commitment or a paid bug-bounty program.
Privacy and data requests
For personal-data access, correction, or deletion, use a privacy ticket. Read the privacy policy for data categories and the storage policy for cookies and local data.