Security
Last updated: March 2026
Our Commitment
Security is foundational to ScreenLoom. We take the protection of your content, account data, and screen infrastructure seriously. This page describes the measures we take and how to report a vulnerability if you find one.
Data Encryption
- In transit: All communication between your browser, screens, and our servers is encrypted using TLS 1.2 or higher.
- At rest: Stored data including uploaded media and account information is encrypted at rest using AES-256.
- Passwords: Passwords are hashed using bcrypt and are never stored in plain text.
Infrastructure
- Our infrastructure is hosted on enterprise-grade cloud providers with SOC 2 Type II certification.
- We use a content delivery network (CDN) to serve media files securely and efficiently to your screens worldwide.
- Network access to production systems is restricted through firewalls and private networking. No unnecessary ports are exposed publicly.
- Automated vulnerability scanning and dependency audits run continuously on our codebase.
Access Controls
- Internal access to production systems follows the principle of least privilege — employees only have access to what their role requires.
- Multi-factor authentication (MFA) is enforced for all team members with access to production infrastructure.
- Access logs are retained and reviewed regularly.
- Screen authentication tokens are scoped per device and can be revoked at any time from your dashboard.
Account Security
We recommend the following practices to keep your account secure:
- Use a strong, unique password for your ScreenLoom account.
- Enable two-factor authentication (2FA) if available on your plan.
- Revoke screen pairings for devices that are no longer in use.
- Review your team member list regularly and remove users who no longer need access.
Incident Response
In the event of a security incident affecting your data, we will:
- Notify affected customers promptly via email.
- Provide a clear description of what happened, what data was affected, and what steps we are taking.
- Comply with applicable data breach notification laws, including GDPR where relevant.
Responsible Disclosure
If you discover a security vulnerability in ScreenLoom, please report it to us before disclosing it publicly. We appreciate responsible disclosure and will work with you to understand and resolve the issue quickly.
To report a vulnerability, email us at security@screenloom.com. Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue
- Any supporting evidence (screenshots, request/response logs)
We commit to acknowledging your report within 2 business days and keeping you informed as we investigate and resolve the issue. We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it.
Sub-processors & Third Parties
We work with a small number of third-party service providers to deliver our platform. All sub-processors are vetted for security standards and bound by data processing agreements. A current list of sub-processors is available upon request at security@screenloom.com.
Contact
For security-related questions or concerns, reach us at: