Trust
Security & compliance
TVpilot runs businesses' public screens, so reliability and data protection are core product features, not afterthoughts. This page describes how we protect your account, content and devices.
Last updated: July 2026
Infrastructure & hosting
- The TVpilot platform runs on enterprise-grade cloud infrastructure whose providers are SOC 2 Type 2 attested and ISO 27001 certified; customer data is stored in the European Union.
- The application is delivered through a global edge network: content is served from the location closest to each screen, with automatic TLS on every connection and DDoS mitigation applied at the network edge before traffic ever reaches the application.
- Application workloads run in isolated, ephemeral compute environments that are provisioned per request, there are no long-lived servers to patch, and no shared state between executions.
- Every release is deployed atomically: a new version goes live only when it is fully built and healthy, and can be rolled back instantly. Screens never see a half-deployed platform.
- Media files are stored in access-controlled storage buckets; payments are processed by Stripe, so card details never touch TVpilot servers.
Data protection
- All traffic is encrypted in transit (TLS 1.2+); data is encrypted at rest.
- Every account's data is isolated with database-level access policies (row-level security): one customer can never read another customer's content.
- Automatic daily database backups allow point-in-time recovery.
- We process personal data under the GDPR. We collect only what the service needs (account email, name, uploaded content, device status) and never sell data.
Device & player security
- Screens are claimed with single-use codes; each player authenticates with its own credentials that can be revoked from the dashboard at any time.
- Players only pull content over HTTPS; no inbound connections or port-forwarding to your network are required.
- The self-healing kiosk (watchdog reboots, crash recovery, auto-reconnect) keeps screens running without manual intervention.
Application security
- Authentication is handled by a dedicated auth provider with secure password hashing; rate limiting protects sign-in and API endpoints.
- Internal endpoints (cron, device APIs) require authenticated, secret-based access.
- Dependencies are kept current and changes are reviewed before deployment.
Availability
We target 99.9% uptime for the player-facing infrastructure. The platform scales automatically with demand, there is no capacity ceiling to hit during traffic peaks, and the edge network keeps serving cached content even when an origin region is degraded.
Screens are resilient by design: every player caches its playlist and media locally, so if the platform is briefly unreachable your screens simply keep playing and reconnect automatically. Combined with the self-healing kiosk (watchdog reboots, crash recovery, auto-reconnect), a temporary network or platform issue never means a black screen in your store. Custom SLAs are available on the Business plan.
Responsible disclosure
Found a vulnerability? Please report it to support@tvpilot.app. We respond quickly, will not take legal action against good-faith research, and credit reporters when a fix ships.
Questions
For security questionnaires, data-processing agreements or Business-plan requirements (SSO/SAML, audit logs), contact support@tvpilot.app. See also our privacy policy and terms of service.