Disclaimer
TomorrowOS is an open source unified API layer for digital signage operating systems. It is provided to help developers, integrators, CMS vendors, hardware partners and signage teams build, test and understand cross-platform signage functionality. TomorrowOS may be used as a reference layer, SDK, API structure, connector framework, testing model or starting point for other projects. Use of TomorrowOS is at your own risk.No warranty
TomorrowOS is provided “as is”, without warranty of any kind. The project maintainers do not guarantee that TomorrowOS will be:- Error-free
- Secure
- Complete
- Suitable for production use
- Compatible with every device, operating system or firmware version
- Available at all times
- Free from bugs, downtime, playback issues or compatibility gaps
No production guarantee
TomorrowOS does not provide any uptime guarantee, service level agreement, production support guarantee or operational guarantee. This applies to all use cases, including:- Small signage networks
- Large signage networks
- Enterprise deployments
- Retail deployments
- QSR deployments
- Government deployments
- Transport deployments
- Healthcare deployments
- Mission-critical environments
- Internal prototypes
- Commercial products built on top of TomorrowOS
No liability for downtime or loss
The maintainers, contributors and project owners are not responsible for any loss, damage, downtime, outage, failed playback, failed display, failed update, failed command, data issue, security issue, business interruption or commercial impact arising from the use of TomorrowOS. This includes, but is not limited to:- Screen downtime
- Black screens
- Failed content playback
- Failed image playback
- Failed video playback
- Failed widget playback
- Failed ZIP package handling
- Failed synchronisation
- Failed proof-of-play
- Failed proof-of-display
- Device control issues
- Incorrect capability mapping
- Firmware-specific issues
- OS-specific issues
- Integration failures
- Network failures
- Lost revenue
- Lost advertising value
- Lost customer opportunity
- Operational disruption
- Hardware damage
- Software failure
- Customer claims
- Third-party claims
Forks and third-party implementations
TomorrowOS is open source and may be forked, modified, extended or used as the foundation for other projects, subject to the project license. The maintainers are not responsible for:- Forked versions of TomorrowOS
- Modified versions of TomorrowOS
- Third-party SDKs
- Third-party connectors
- Third-party packages
- Third-party dashboards
- Third-party commercial products
- Third-party deployments
- Third-party support promises
- Third-party security practices
- Any project built on top of TomorrowOS
No guaranteed compatibility
Digital signage operating systems vary widely. Support may depend on:- Operating system
- Device model
- Firmware version
- Browser engine
- Media engine
- Hardware generation
- Native API access
- App permissions
- Network conditions
- Storage availability
- Runtime environment
- Whether a bridge or agent is available
Device control risk
TomorrowOS may include or describe APIs for device control, screen control, local APIs, remote commands, package handling, telemetry, screenshots, proof-of-play and other operational functions. These areas can create risk if implemented incorrectly. You are responsible for ensuring that any implementation includes appropriate:- Authentication
- Authorisation
- Permission checks
- Secure storage
- Safe defaults
- Logging controls
- Customer data protection
- Device testing
- Rollback process
- Operational monitoring
- Compliance review
Package and content risk
ZIP packages, widgets, HTML content, JavaScript, media files and external content should be treated as untrusted until validated. You are responsible for validating:- Package structure
- Manifest files
- File types
- File sizes
- Checksums
- Safe extraction paths
- External dependencies
- Runtime permissions
- Fallback content
- Rollback behaviour
- Security impact
Security responsibility
TomorrowOS may help define security patterns, but it does not remove your responsibility to secure your own deployment. You are responsible for:- Protecting credentials
- Protecting access tokens
- Securing local APIs
- Securing remote commands
- Validating packages
- Protecting customer data
- Managing logs and screenshots
- Reviewing dependencies
- Monitoring vulnerabilities
- Applying updates
- Complying with applicable laws and customer requirements
SECURITY.md.
Private contact: security@tomorrowos.org
Not professional advice
TomorrowOS documentation may discuss technical, operational, security, commercial or deployment considerations. This information is general in nature and does not constitute legal, security, compliance, engineering, financial or professional advice. You should seek appropriate professional advice before using TomorrowOS in environments where failure could create material risk.User responsibility
By using TomorrowOS, you accept responsibility for your own use of the project. This includes responsibility for:- Testing before deployment
- Validating device support
- Validating OS support
- Validating firmware support
- Reviewing security risks
- Reviewing operational risks
- Monitoring production behaviour
- Supporting your own customers
- Managing incidents
- Maintaining your own fork or implementation
- Complying with applicable contracts, laws and regulations