1. How we protect you
In short: Every church’s data is walled off in the database itself, everything is encrypted, and every sign-in goes through a dedicated identity provider.
- Every church is walled off. Which church may see which data is decided by the database itself, on every request, not by the app’s screens. Automated tests check that one church can never read or change another’s, for every role.
- Encrypted everywhere. All traffic uses HTTPS with strict transport security; data is encrypted at rest.
- Sign-in. People sign in through Auth0, a dedicated identity provider. Your session lives in a secure, HTTP-only cookie that other sites and scripts can’t read.
- Hardened pages. Every page carries a strict content security policy that blocks scripts we didn’t write, and a set of security headers that stop it being framed or misread.
- Roles. Each person’s role (owner, admin, editor, operator or viewer) is enforced by the database, so an operator can change what’s playing and nothing else.
2. Your TVs
- A TV joins your church only when an owner or admin approves the code it shows, using the same standard as signing in to other devices (OAuth 2.0 device authorization).
- Each TV has its own credentials, stored in the Apple TV’s secure keychain, and they change regularly. Removing a TV on the Displays page stops them working at once.
- If a TV’s credentials are ever copied to another device, we detect it, pause the TV, and tell your church, so it can pair the TV again.
- The TV app can’t upload, edit or delete anything, and has no way to type in text.
3. Your files
- Files are stored privately and reached only through short-lived signed links; there is no public address for any church’s file.
- Uploads go to a separate holding area. Before a file can reach a screen, we check what it really is from its contents, not its name, and accept only pictures and videos in formats we allow.
- Files a church deletes go to its trash, and are permanently deleted 30 days later.
4. Our people and process
- Access to production systems is limited to those who need it, with multi-factor authentication.
- Every change that touches sign-in, data access, storage, uploads or the TV connection gets a security review before it ships, and the whole Service is reviewed every month.
- We keep encrypted daily backups of the database.
- Secrets are never stored in our code, and automated checks stop them reaching it.
5. Reporting a problem
In short: Found a security problem? Email us. We’ll reply within 3 business days, and we won’t take action against good-faith research.
Email support@displayte.com with what you found and how to reproduce it. We’ll acknowledge it within 3 business days, keep you updated, and credit you if you’d like once it’s fixed. Our contact details are also at /.well-known/security.txt.
If you act in good faith, we won’t pursue legal action against you for research that: stays within your own accounts, or test accounts you create; doesn’t access, change or delete other churches’ data; doesn’t disrupt the Service or anyone’s screens; and gives us reasonable time to fix a problem before you tell anyone else. Please don’t use automated scanners that send large volumes of requests, social engineering, or physical attacks.