Security & Trust
The screen displays. It does not observe.
The player app declares no camera permission, no microphone permission, and no location permission of any kind. It cannot access a camera or microphone even if the hardware had one โ the operating system would refuse the request. No audience measurement, no facial detection, no people counting, no presence tracking.
We have no password to lose.
We never ask you to create one, so there is none to steal, reuse, or breach. You sign in with Google, with Apple, or with a one-time link we email you.
- No cameras or microphones
- Encrypted in transit
- Signed updates
- Tamper-evident play records
- Consent-first analytics
01
Privacy by architecture
The privacy guarantees are structural โ capabilities are absent, not merely switched off.
- No camera, no microphone, no location permission on the Smart Box. The capability is absent at the operating-system permission level, not disabled in configuration.
- Device telemetry, zero viewer telemetry. The box reports its own health and identity โ address, board, app version, uptime, network type and signal, temperature, and which content played when.
- Nothing is tracked on our website until you agree. Analytics and advertising storage default to denied before any tag loads, with per-category choice you can withdraw later. Verifiable from any browser's network tab.
- We don't track you. There's no advertising SDK in the app, no advertising identifier, and no data sold to brokers โ which is why SLX On Air never shows you the "allow tracking?" prompt.
- The apps never ask for your microphone, your contacts, or background location. On iOS, location is a single approximate reading โ when-in-use only, about 100 m accuracy, and updating stops after the first fix. We work out your neighbourhood, and the neighbourhood is what's kept.
- On Android, location is requested in context โ never at launch โ and the app works without it. Bluetooth scanning is declared
neverForLocation, so the promise not to derive location from it is machine-readable and enforced by the OS. - Analytics and crash reporting are Firebase only. Crash reports carry technical tags and our own user id โ no post text, no photos, no message content. You can switch crash reporting off in the app, and it takes effect immediately.
02
Proof & verification
Proof of Play is available on Pro boards, enabled per board. Where it's on, the record is designed so that you don't have to take our word for it.
- Tamper-evident play records. Each play is recorded in an unbroken chain where every entry mathematically depends on the one before it, so nothing can be inserted, deleted, reordered or edited after the fact without the chain visibly breaking โ including by us.
- Signed on the device. Each batch is signed with an elliptic-curve key generated inside the box's own secure key store, which cannot be exported. An attacker with our database can't rewrite records; another machine can't impersonate a box.
- Every day's play records are timestamped by two independent time-stamping authorities, and the timestamps themselves are published โ anyone can download them and verify them, without trusting SLX On Air. The two authorities are freetsa.org and DigiCert, neither of which has any relationship to us. The timestamps are verified rather than merely obtained, and the raw RFC-3161 tokens are downloadable.
- Anyone can verify a report, with no SLX account, at our public verification portal.
- We can tell whether the TV was actually on. Where the panel reports its state, we can tell whether the TV was actually receiving a signal over HDMI โ screen-time we can vouch for is shown as verified; time we can't is disclosed separately.
What Proof of Play does not prove
- It proves the player rendered the content, and โ where the panel reports โ that the TV was receiving a signal. It does not prove a human saw it. An unsensed screen in an empty room produces identical records.
- Some TVs keep their HDMI receiver powered in standby and never report a change, so those screens can't be sensed. They are graded panel unknown rather than counted as verified.
- It is not audience measurement โ no impressions, no dwell time, no demographics, by design.
- It guarantees integrity from the moment the box recorded the event onward.
- A re-provisioned box legitimately restarts its chain. That's expected and visible, not a break.
03
The Smart Box on your network
What your network team needs to know before an install.
- Outbound-only. No inbound ports are open in normal operation. The box opens no listening sockets; every connection is initiated by the box. No VPN, no port forwarding, no inbound firewall rule required.
- It never scans, enumerates or reaches anything else on your network. No mDNS/Bonjour, no SSDP/UPnP, no subnet sweeping, no SMB or printer discovery. It talks to our cloud and to nothing else on your LAN โ which removes the "IoT device as a pivot point" concern entirely.
- It runs on a fully isolated guest VLAN with no route to internal systems. No static IP or DHCP reservation needed. Wired Ethernet is the recommended enterprise installation.
- Your Wi-Fi password never reaches our servers. It goes from your phone to the box over a direct short-range Bluetooth link and straight into the device's Wi-Fi settings. It is never transmitted to us, never written to our app's storage, and never logged. What the box does report about the network: name, signal, speed, and its own local addresses โ never the password.
- The screen keeps playing when the internet doesn't. Cached content continues indefinitely through an outage โ no blank screen, no error message, no freeze. Interrupted downloads resume.
- It's an appliance, not a computer. No home button, no menu, no app drawer, no notification shade, and no way to close the app from the screen. If anything interrupts it, the box puts your content back by itself within seconds. USB debugging is disabled on production devices.
- Remote support is five fixed actions, on an allowlist the box enforces: restart the app, reboot the box, refresh content, clear cached content, and capture a screenshot for diagnostics. There is no remote shell and no arbitrary command execution. Screenshots capture the public display only.
- Take-down is immediate. Remove something in the console and it's off the screen within minutes.
04
Secure updates
Nothing installs unless the device can prove it's ours. This section describes SLX On Air application software.
- Application updates are signed and signature-verified by the device before installation. Updates to the screen software are signed with our key, and the device's operating system refuses to install any update not signed with that same key. The signing key is not on the device and never travels with an update.
- This is what stops a malicious update server. Even if an attacker completely controlled our update servers or our download links, they could not install substituted software: what they built isn't signed with our key, and the device rejects it.
- A hostile network can delay your updates. It cannot change them. If someone redirects our update traffic or runs an interception proxy, the connection fails validation and is dropped โ the device retries later. The worst case is a device that doesn't get patched, not a device that gets attacked.
- No failure path weakens security. When the update path fails โ no network, unreachable server, invalid certificate โ the device retries with backoff. There is no fallback to an unencrypted or unverified path.
- We track how every update lands across the fleet, and can halt a rollout at any point. Updates go to a subset of devices first and widen. If we halt a rollout, devices that haven't taken it never will.
- A failed update never leaves a dead screen, and never needs a site visit. The box keeps a copy of the working version before installing. If an install fails, it restores the previous version automatically and permanently blocks the bad one from being retried. If power is lost mid-update, the box comes back running the version it had.
- It repairs itself afterwards, too. If the app stops running, the device notices within a minute and restarts it, escalating to a reinstall from a local backup if that doesn't work. The recovery service is started by the operating system rather than by the software it supervises, so a completely broken app cannot take the recovery mechanism down with it.
- Security fixes reach the fleet typically within 24 hours, without anyone visiting the site. A box that's switched off or offline gets it when it next comes online.
- Update reports contain device identity, software versions and update outcomes โ never your content.
- A customer's box can only run the software channel we've assigned it. Moving one is a deliberate, authorised action from our console โ not something that can happen from the device.
05
Your data
Where it lives, how it travels, how long we keep it, and how you get rid of it.
- Encrypted in transit, everywhere โ TLS on every connection between the apps, the devices, the website and our servers. TLS 1.3 on the website and console; HTTP redirects to HTTPS.
- Even if someone installs a certificate on your phone, our apps won't trust it. Both apps trust only the operating system's own root certificates, so interception tooling that works against a browser does not work against them. On iOS, encrypted transport is enforced by the OS with no exempted domains at all.
- Encrypted at rest by our managed cloud platforms.
- Application credentials are held in server configuration, never in source code.
- Request rate limiting on public API endpoints, returning 429 above threshold, and inbound webhooks are signature-verified with HMAC-SHA256.
- Data residency. Our primary database is hosted in Mumbai, India. Media storage, outbound email and payment processing are also handled within India. Some global services we rely on โ sign-in, content screening, maps and analytics โ are operated by Google and may process data outside India.
- Served over TLS 1.3 with HSTS, a strict framing policy, and browser-enforced hardening headers. HSTS is enabled and preload is submitted.
- A published vulnerability-disclosure contact at
/.well-known/security.txt, in RFC 9116 format, with a monitored mailbox behind it. - A published retention schedule, enforced in code. Crash logs 90 days; device health data tiered from 30 days of full detail to a year of daily summaries; Proof-of-Play raw events 90 days with two-year summaries; administrative audit records two years; invoices per statutory requirement.
- Deletion is a real workflow, not a support ticket.
- Business documents are delivered through expiring, access-checked links โ invoices and Proof-of-Play reports.
- We never touch your card details. Payments go directly to our PCI-DSS-compliant payment gateway; we store an order reference and an amount.
- A published list of every sub-processor, what each receives, and why. The timestamping authority receives only a cryptographic hash โ no personal data.
- Administrative actions are audit-logged โ who, what, when, to what, and whether it succeeded โ retained for two years.
Stated plainly
- Content posted to a board is public by design, because a board is a public screen. It is not private, protected or access-controlled.
- Our support staff can view customer content through an internal console, under named controls.
- We can capture a screenshot of a screen for diagnostics on request. Screenshots capture the public display only.
06
Identity & access
Brief, because there is not much to it โ and that is the point.
- Passwordless sign-in โ Google, Apple, or a one-time emailed link. No password is created, stored or transmitted, and we hold no password database.
- Short-lived tokens that renew silently, so a captured credential has a limited life and you're never interrupted by a login wall.
- Signing out ends your session everywhere it exists โ on the device and on our servers. The app is wiped back to a fresh-install state, and the credential that identified it is invalidated immediately rather than left to expire.
- Session credentials are held in your phone's secure hardware store and are never copied into cloud backups.
- Least privilege you can point at. Organisation roles โ owner, admin, billing โ govern the console: devices, boards, content, purchases. Board posting permissions are a separate, content-moderation model.
- Client-side checks are presentation; the server is the authority. Every action is independently authorised server-side, so the browser has no power to grant anything.
- Cross-site request forgery is structurally impossible, not merely defended against: authorisation travels in an explicit header, never an ambient cookie, so a cross-site request carries no credentials at all.
- If your organisation enforces two-step verification on Google or Apple, that applies to your console too โ you're signing in through your own identity provider.
07
For everyone
If you use SLX On Air and none of the above is your job, this is the part that matters.
- You never have a password with us.
- Nothing to remember, nothing to reuse, nothing for anyone to steal from us.
- Your connection is always encrypted.
- Unlike a web browser, the app refuses to trust a certificate someone adds to your phone, so a hostile cafรฉ or airport Wi-Fi can't read what you post.
- We never ask for your microphone, your contacts, or your location in the background.
- Location is asked for only when you're looking for boards near you, and the app works fine if you say no.
- We never get access to your photo library.
- When you attach a photo you choose it in your phone's own picker, and the app receives only the items you picked.
- Signing out really signs you out.
- Tokens, cached posts, cached images, drafts and preferences are all destroyed, and the session ends on our servers too.
- You can turn off crash reporting.
- From a switch in the menu, and it works immediately.
- Nothing is tracked on this website until you say yes.
- And you can change your mind later.
- Can someone hijack my screen?
- Content can only reach a screen through the board it belongs to, and only from people the owner has admitted to that board. The box doesn't listen on the network, doesn't accept content from USB, Bluetooth or your local network, and only ever fetches its one assigned board. If something unwanted appears, the owner removes it and it's gone in seconds.
- Will an update break my screen?
- It updates itself, usually overnight, in seconds. If an update ever fails, the screen goes back to the version it was running, by itself โ it won't go dark, and nobody needs to come out.
08
For enterprise & healthcare
Written for the people who have to sign this off.
- We are public-display signage, not a healthcare data system. No clinical integration, no HL7/FHIR, no patient identifiers anywhere in our data model.
- All content is customer-authored and intended for public display, so patient data must never be posted to a board โ the same rule that already applies to the lobby noticeboard we replace.
- Wired Ethernet is the recommended enterprise installation. Plug the box in and setup is skipped entirely โ no wizard, no interaction.
- Your screens get security patches automatically, with no IT ticket and no site visit โ typically within 24 hours, for SLX On Air application software.
- Our support staff cannot sign in as you. There is no impersonation feature.
- Our support staff can act on your account โ and every action they take is recorded. Every state-changing action in our internal console is audit-logged with two-year retention.
- Remote maintenance access is off by default, must be authorised from our console, is time-limited, and expires automatically.
- Privacy built around India's DPDP Act, with a documented data inventory, purpose record and retention schedule.
Request our security pack
A fuller written answer for a security review โ controls, sub-processors, retention, and the things we deliberately donโt do, with the reasoning. Sent to your inbox.
Request the security packNeed more detail than the pack covers? Say so in the same email and weโll take you through our full documentation under NDA.

