Screenly achieves ISO/IEC 27001:2022 certification

SECURITY |
Screenly achieves ISO/IEC 27001:2022 certification

Screenly is now certified against ISO/IEC 27001:2022, the international standard for information security management systems. The certification was issued by Glocert International Certifications (UK) Limited, accredited under IAF and IAS, following an independent audit of our security practices.

This wasn’t a self-assessment. An accredited third party reviewed how we manage information security risk, how we develop and ship software, and how we run our operations, and checked all of it against the ISO 27001 requirements. The certificate covers our full platform: cloud infrastructure, device software, APIs, and support. The parts customers actually touch, from the dashboard down to the player itself.

Why this matters in digital signage

Digital signage has a quiet security problem: almost nobody thinks it has one.

A signage player is a networked computer that sits inside a business for years, behind a TV in a lobby, above a counter, in a hallway. It’s physically accessible, rarely inspected, and usually forgotten by IT the week after install. That combination creates risk in three ways:

A compromised screen is public. It shows whatever the attacker wants, to your customers, in your building, with your brand next to it. There’s no quiet failure mode.

A compromised player is a foothold. Default credentials, open ports, or old firmware don’t just put the screen at risk, they put a machine inside your network perimeter at risk, and that machine can be used to reach further in.

Nobody’s watching it. Laptops get patched because people use them every day. A signage player can run unmaintained for years, accumulating known vulnerabilities the whole time.

We built Screenly around this: no default credentials, no open inbound ports, encrypted communication between player and cloud, and automatic security updates so a fleet stays patched without anyone visiting a device. This certification is now independent confirmation of that, not just how we describe ourselves.

We built Screenly around this: no default credentials, no open inbound ports, encrypted communication between player and cloud, and automatic security updates so a fleet stays patched without anyone visiting a device. This certification is now independent confirmation of that, not just how we describe ourselves.

What this means for customers

ISO 27001 forces a level of discipline and documentation around information security that’s easy to skip when you’re moving fast. Having a licensed auditor check our work makes sure that we never miss a step. It also gives our clients and their procurement teams a level of independently verified trust to point to.

For customers, this doesn’t change anything day to day. What it adds is a verified security posture, backed by periodic surveillance audits over the next three years.

This certification joins our SOC 2 Type II report as independently verified evidence of how we handle security, not a claim we’re making about ourselves, but something outside auditors have checked and are on the hook to keep checking.

The certificate and related documentation are available at security page.

Certificate No. 26ISMS-1228, issued August 7, 2026, valid through August 6, 2029.

Sam Rodriguez
Sam Rodriguez View Profile
Sam supports Compliance and Enterprise Operations.

Recent Posts

Display your best content with Screenly digital signs.

Get started today quickly and easily with Screenly's secure, enterprise-grade digital signage.

Screenly digital signage display