Skip to content
A corridor of wall-mounted screens beside a glazed server room, with network switching hardware racked in the open cabinet below.

SECURITY & DATA HANDLING

Your content, on infrastructure you choose.

Self-hosted or cloud, SAML single sign-on, access scoped per user and per screen, and full operation on networks with no internet at all. Every line on this page is a shipped capability, not a roadmap item.

Self-hosted
Run the CMS on your own servers
SAML
Single sign-on, Business plan and up
3
Ports: TCP 80, 443, 9505
Air-gapped
Offline networks supported

START HERE

The short version, before you send the questionnaire.

Most security questions about digital signage come down to one thing: where does the content live and who can change it. LiveSign answers that by letting you decide. Run the CMS on our cloud, or run the whole thing on your own infrastructure, where nothing leaves your environment and the answer to every data-residency question is already yours.

Access is handled the way IT expects. SAML single sign-on from the Business plan up means signage login follows your existing joiner and leaver process, and built-in user administration limits each person to the screens and features they actually need.

And if the network cannot reach the internet at all, that is a supported deployment rather than an exception: the On-Premise Licensing Module runs Live fully offline on perpetual licence pricing. Send us your security questionnaire and you will get it back answered line by line, by the people who run the platform.

VERIFIED CAPABILITY

Deployment
Cloud-hosted by LiveSign, or fully self-hosted on your own infrastructure.
Self-hosting support
Dedicated support for self-hosted deployments on the Enterprise plan.
Single sign-on
SAML, on the Business plan and above.
Access control
Per user and per group, limiting both CMS features and which displays they reach.
Player ports
Outbound HTTP or HTTPS on TCP/80, TCP/443 and TCP/9505.
Air-gapped networks
Supported via the On-Premise Licensing Module on perpetual licence pricing.
Support hours
8:00 to 18:00 GMT/BST.

THE CONTROLS

What you can actually lock down.

Six real controls, each one a shipped capability rather than a roadmap item.

Self-hosted deployment

Run the entire Live CMS on your own servers rather than LiveSign's cloud. Content, media and management stay inside your infrastructure. Dedicated self-hosting support is included on the Enterprise plan.

SAML single sign-on

Available on the Business plan and above. CMS access uses your existing identity provider, so joiners and leavers are handled by the same process as every other system.

Scoped user access

Built-in user authentication controls exactly which CMS features each user or group can reach, so a store or department login cannot touch the rest of the network.

Display and user groups

Group screens and people the same way, by site, floor, building or department, so access and scheduling follow the same boundaries your organisation already uses.

Player communication

Live Players connect outbound to the CMS over HTTP or HTTPS on TCP/80, TCP/443 and TCP/9505. They are built to run as independently of the CMS as possible and keep playing if the link drops.

Offline networks

Networks that cannot reach the internet at all are supported through an On-Premise Licensing Module, available on Independent (perpetual licence) pricing.

FOR A PROCUREMENT REVIEW

The shortest answer to a data question is to keep the data.

Most signage security reviews are one question in different words: where does the content live, and who can reach it. Self-hosting answers it outright. The CMS, the media and the user administration run on infrastructure you already control, already monitor and already audit, inside the controls your organisation has in place for every other internal system.

For sites that cannot reach the internet at all, the On-Premise Licensing Module runs Live fully offline on perpetual licence pricing. For everything else there is SAML single sign-on from the Business plan up, so signage access follows your joiner and leaver process, and scoped user and display groups, so a site manager reaches their own screens and nothing beyond them.

Send the questionnaire before the demo rather than after. You will get it back answered line by line, including the lines where the answer is something we would need to work through with you.

Security and data handling: common questions

Can Live CMS be self-hosted for data control?

Yes. Self-hosting is supported, so the CMS and its content run entirely on infrastructure you control. Dedicated self-hosting support is included on the Enterprise plan.

How does LiveSign handle our compliance requirements?

Almost every requirement comes down to where content lives and who can reach it, so the deployment model does most of the work. Self-hosted, the CMS and all its content run inside your own environment, under the controls, monitoring and audits you already run. For sites with no internet access at all, the On-Premise Licensing Module runs Live fully offline. Send us the questionnaire or the specific requirement before you evaluate further and you will get a direct answer on each line, including anything that would need working through with us.

How do Live Players communicate with the CMS?

Players connect over HTTP or HTTPS using TCP/80, TCP/443 and TCP/9505, and are designed to run as independently from the CMS as possible. If the connection drops, the player keeps playing its current schedule and picks up changes on its next successful check-in.

Does LiveSign support offline networks?

Yes, through an On-Premise Licensing Module, available on Independent (perpetual licence) pricing. This is the option for networks with no internet access at all.

Is single sign-on supported?

Yes. SAML single sign-on is available on the Business plan and above.

Where is data stored on the cloud-hosted plan?

Ask us for the current answer for your region before you commit, and if data residency is a firm requirement, the self-hosted deployment removes the question entirely by keeping everything on your own infrastructure.

Can we restrict what local staff can change?

Yes. Built-in user authentication controls which CMS features each user or group can access, and display groups limit which screens they apply to. A local manager can be given their own screens and nothing else.

What are your support hours?

Support runs 8:00 to 18:00 GMT/BST. For deployments that need cover beyond that, talk to sales before committing.

STILL HAVE A QUESTION

Send us the security questionnaire.

We would rather answer it honestly up front than discover a blocker at contract stage.