Updated 2 October 2026.
What kiosk software is
Kiosk software is the stack that turns a computer and a touchscreen into a single-purpose machine that runs unattended. It is not one product. A working kiosk needs six layers, and buyers who only look at the screens the customer sees usually find the problems later, in updates, monitoring and integration.
| Layer | What it does | What to ask |
|---|---|---|
| 1. Operating system and kiosk mode | Boots the device into one app and keeps users out of everything else | Which OS? How is it locked down? How are OS updates controlled? |
| 2. Kiosk application | The screens, workflow and logic the user sees | Who owns the code? Can we change screens and flows ourselves? |
| 3. Device management (MDM/EMM) | Enrols, configures and updates the fleet remotely | Can we update one kiosk, a pilot group and then all of them? |
| 4. Remote monitoring | Reports health, faults, stock and connectivity, raises alerts | What does it alert on, and who receives the alert? |
| 5. Payments and peripherals | Drives the card terminal, scanner, printer, locks and dispense mechanism | Is the payment terminal certified? Where does card data go? |
| 6. Back office and integrations | Content, pricing, users and reporting; APIs to POS, ERP, PMS or ServiceNow | Is there a documented API? Can we export all our data? |
The rest of this page explains each layer, then gives a checklist for comparing kiosk software and says what KioskForce supplies.
Layer 1: operating system and kiosk mode
“Kiosk mode” means the operating system locks the device to one app, or a short allowlist of apps, so a member of the public cannot reach the home screen, notifications, settings or a browser. The major operating systems all have this built in. Use the platform’s own mechanism rather than hiding the navigation bar with an app trick.
Android: lock task mode and dedicated devices
Android calls single-purpose devices dedicated devices (formerly corporate-owned, single-use or COSU). Android’s documentation describes them as “fully managed devices that serve a specific purpose”, with kiosks, digital signage and hospitality check-in among the customer-facing examples.
The core feature is lock task mode, supported on fully managed devices since Android 5.0 (API level 21). In lock task mode, users “typically can’t see notifications, access non-allowlisted apps, or return to the home screen”. Only apps on an allowlist set by the device policy controller can run, and from Android 9 the administrator can selectively re-enable features such as the status bar, notifications or the power-button menu. Dedicated devices can also use ephemeral users for shared sessions and control when system updates install.
To use these APIs, the kiosk app is managed through a custom device policy controller, the Android Management API, or an EMM platform that supports dedicated devices.
Windows: Assigned Access and Shell Launcher
Assigned Access configures a Windows device either as a kiosk that runs a single UWP app or Microsoft Edge full screen above the lock screen, and automatically restarts the app if it is closed, or as a restricted user experience with an allowlist of apps and a tailored Start menu. It is supported on Windows Pro, Enterprise, Education and IoT Enterprise editions.
Shell Launcher replaces the Windows Explorer shell with a custom desktop or UWP application. Microsoft names kiosks, ATMs and digital signage as typical uses. It is available on Enterprise, Education and IoT Enterprise editions. Shell Launcher does not by itself stop a user launching other applications, so it is combined with policies such as AppLocker.
iPad and Linux
On iPad, Guided Access temporarily restricts the device to one app, and Single App Mode locks a supervised, managed device to one app. Tablets on stands are common for countertop ordering and check-in. Linux kiosks usually boot a minimal system straight into a full-screen browser or app; lockdown is then a matter of configuration rather than a single built-in feature.
Which to choose: Android suits purpose-built kiosks on low-power embedded boards. Windows suits kiosks that must run existing Windows software or peripheral drivers. Tablets suit light, indoor, countertop use.
Layer 2: the kiosk application
This is what the user sees and what most people mean by “kiosk software”. There are two common architectures:
- Native app. Built for the OS. It gives direct, reliable access to peripherals, works offline and starts quickly. Changing it means shipping an app update.
- Web app in a locked browser. Screens are served from a web platform, so content and design changes are instant across the fleet. Peripheral access goes through a local bridge, and the kiosk depends on its connection unless the app caches pages.
Whichever you choose, the application should handle the details that separate a kiosk from a website:
- Session timeout and reset: clear the basket and personal data after a period without input, so the next person sees a fresh screen.
- Large targets and short flows: a first-time user should finish a transaction in about a minute.
- Accessibility: controls within reach, an audio or tactile alternative, adjustable contrast and a choice of language. In the US, sections 308 and 309 of the 2010 ADA Standards set reach ranges of 15 to 48 inches and a maximum operating force of 5 pounds-force for operable parts.
- Failure handling: what the screen says when a printer jams, a door fails to open or the payment is declined, and how the transaction is recorded either way.
- Offline behaviour: what still works without a connection, and how records sync when it returns.
Layer 3: device management (MDM / EMM)
Once there is more than a handful of kiosks, nobody can update them by hand. Device management software, called MDM or EMM in the mobile world, enrols each device, applies its kiosk-mode policy, installs and updates the app, sets Wi-Fi and security settings, and can lock or wipe a device remotely. NIST SP 800-124 Rev. 2 (May 2023) is a useful neutral reference for managing mobile devices securely in an organisation.
System updates are the risky part. Android device owners can set a system update policy to install updates automatically, within a daily maintenance window, or postpone them for 30 days. From Android 9, freeze periods of up to 90 days block system updates over critical trading periods, with at least 60 days between freezes. Use them: an OS update on launch day is a common way to take down a fleet.
Stage every release. Push app and firmware updates to one test kiosk, then a pilot group, then the fleet, and keep the previous version available for rollback.
Layer 4: remote monitoring
Monitoring tells you a kiosk is down before a customer does. Good kiosk monitoring reports:
- Connectivity: last seen, network type and signal (Ethernet, Wi-Fi or 4G).
- Peripheral health: printer paper and jams, card terminal status, scanner, door locks and sensors, dispense faults.
- Stock and consumables: for vending and locker kiosks, level by item or cell, with low-stock alerts.
- Transactions: a log of every sale, issue, return and failed attempt, so faults can be traced.
- Alerts: to a named person or team by email or in a service-management tool, not just a red dot on a dashboard nobody watches.
Layer 5: payments and peripherals
The kiosk app drives every peripheral: card terminal, scanner, printer, badge reader, locks, sensors and dispense motors. Vending-type kiosks commonly connect card readers and cash devices over MDB, the standard vending-machine bus, which lets operators choose between payment providers.
Keep card data out of the kiosk. The safest design uses a certified payment terminal that reads the card and talks to the processor directly; the kiosk app only sends an amount and receives approved or declined. Card acceptance is governed by the PCI Security Standards Council:
- PCI DSS sets security requirements for any environment that stores, processes or transmits payment account data.
- PCI PTS POI covers the devices that protect PINs and card data at the point of interaction, including unattended terminals.
- P2PE (point-to-point encryption) encrypts card data from the point of capture to the point of decryption, which keeps it out of the kiosk’s systems.
Ask any supplier which terminal is used, what certifications that terminal holds, and whether the kiosk software ever sees a card number. See payments and payment kiosks.
Layer 6: back office, content and integrations
Content and pricing
Operators need to change menus, products, prices, promotions and screen content without a site visit, and schedule changes in advance: a breakfast menu, a weekend promotion, a holiday closure message. If the kiosk has an advertising screen, the content system should report plays and impressions per campaign.
Integrations and APIs
The kiosk is rarely the system of record. Depending on the type, transactions need to reach a POS, an ERP or inventory system, a hotel property-management system, a patient system, an identity or HR directory, or an IT service-management platform such as ServiceNow. Integration methods range from a REST API and webhooks to scheduled CSV files or a direct database connector. Integration work often costs more than the screens, so scope it early and ask for API documentation before you buy.
Data ownership
Confirm in writing that you can export all transaction, user and device data at any time in a usable format, and what happens to it if the software subscription ends.
Kiosk security checklist
- Lock the OS with the platform’s kiosk mode; no visible desktop, browser address bar or settings.
- Disable or physically secure USB ports, and keep keyboards and service ports behind a locked panel.
- Run the app with least privilege; no shared admin passwords on devices.
- Keep the OS and app patched through managed, staged updates; freeze during peak periods instead of skipping patches.
- Put kiosks on a separate network segment or cellular connection, away from the corporate network and POS systems that don’t need them.
- Use a certified payment terminal so card data never reaches the kiosk app.
- Clear personal data at session end; don’t store more than the transaction needs.
- Log every transaction and door or dispense event, and alert on tampering and repeated failures.
How to compare kiosk software
“Best kiosk software” depends on the kiosk. Score any option against these questions:
- Which OS and lockdown method does it use, and can we manage it with our existing MDM?
- Can we change screens, products, prices and content ourselves, and schedule changes?
- How are app and OS updates staged, and can we roll back?
- What does monitoring report, and how do alerts reach us?
- Which payment terminals and peripherals are supported, and does the software ever handle card data?
- Is there a documented API? Which systems does it already integrate with?
- What happens without a network connection?
- Who owns the data, and can we export all of it?
- What does it cost per kiosk per month, and what is included?
- Who supports it, how, and in which time zone?
What KioskForce supplies
KioskForce designs the hardware and the software of its kiosks, vending machines and smart lockers in-house. The software layers map like this:
| Layer | KioskForce |
|---|---|
| OS and controller | Android-based industrial control boards, booting straight into the machine application |
| Application | Our own machine software for vending, locker and issuing workflows: product selection, code entry, RFID badge, PIN or QR login (biometric optional, quoted per project), per-user quotas, returns |
| Cloud dashboard | Built by Vending on Track, our Australian software partner, and included with the machine rather than sold as a separate tier: inventory, users and quotas, low-stock alerts, door and dispense events, remote settings and pricing, reports, multi-site management |
| Updates and monitoring | Firmware updates pushed over the air; offline alerts in the dashboard. Machines buffer data if the connection drops and sync when it returns, but access-controlled issuing with quotas needs a live connection |
| Payments | MDB cashless terminals such as Nayax and Cantaloupe, coin and note acceptors, QR, WeChat Pay and Alipay mini-apps, optional Vending on Track VendCoin, or free issue against an account. Item-level sales data comes from the machine’s own telemetry, not the payment terminal (payments) |
| Content | Remote advertising-screen management with campaign statistics (visual ads) and remote pricing (remote settings) |
| Integrations | REST API, CSV import and export, and a database connector, scoped as a project; ServiceNow integration |
| Custom software | New interfaces, mobile apps, WeChat or Alipay mini-programs, telemetry back ends, ERP connectors and dashboards, developed by our Nanjing engineering team and scoped and quoted separately from the hardware |
| Support | By email, or through the local distributor where one supplied the machine |
Where we are the wrong choice: if you need a software-only licence for kiosks you already own, a Windows kiosk built around existing desktop software, or a digital-signage or wayfinding content platform, a specialist software provider will serve you better. Our software is designed for the machines we build.
Frequently asked questions
What is kiosk software?
Kiosk software is everything that makes a computer and touchscreen work as an unattended, single-purpose machine: the operating system locked into kiosk mode, the application customers use, device management that installs and updates it, remote monitoring of the hardware, drivers and integrations for peripherals such as payment terminals, scanners, printers and locks, and APIs that send each transaction to back-office systems.
What is kiosk mode?
Kiosk mode is an operating-system setting that locks a device to one app or a short allowlist of apps, so users cannot reach the home screen, settings or other software. On Android it is lock task mode on a fully managed dedicated device, available since Android 5.0. On Windows it is Assigned Access, which runs one app full screen and restarts it if it closes, or Shell Launcher, which replaces the Windows shell with a custom app. On iPad it is Guided Access, or Single App Mode on supervised devices.
What is kiosk management software?
Kiosk management software lets an operator run a fleet of kiosks remotely. It enrols and configures devices, pushes app and operating-system updates, shows which kiosks are online and which peripherals have faults, raises alerts, changes content and prices, and reports on transactions. On Android this is usually done through an enterprise mobility management (EMM) or MDM platform or the Android Management API, sometimes combined with a vendor’s own cloud dashboard.
Should a kiosk run Android or Windows?
Android suits single-purpose kiosks: it runs on low-power embedded boards, has lock task mode and dedicated-device management built in, and boots straight into the app. Windows suits kiosks that must run existing Windows desktop software or drivers for specialised peripherals, or that are managed with an existing Windows estate. Both can be locked down properly; choose by the software and peripherals the kiosk must run.
How do kiosks handle card payments securely?
The safest design keeps card data out of the kiosk software altogether. A certified payment terminal reads the card and talks to the payment processor, and the kiosk app only receives an approved or declined result and an amount. Card acceptance is governed by the PCI Security Standards Council: PCI DSS covers the environment that stores, processes or transmits account data, and PCI PTS POI covers the PIN-entry device. Point-to-point encryption (P2PE) further reduces what the kiosk can see.
How should kiosk software updates be rolled out?
In stages. Release to one test kiosk, then a small pilot group, then the rest of the fleet, with a way to roll back. Schedule updates outside trading hours. On managed Android devices, system update policies can install updates automatically, within a daily maintenance window, or postpone them for 30 days, and from Android 9 freeze periods of up to 90 days can block system updates during peak trading.
What software do KioskForce kiosks run?
KioskForce kiosks run on Android-based industrial control boards with KioskForce’s own machine application. They connect to a cloud dashboard built by Vending on Track, our Australian software partner, for inventory, users, quotas, alerts, remote settings and reports. Integration is available through a REST API, CSV import and export and ServiceNow. Firmware updates are pushed over the air. Custom software such as new user interfaces, mobile apps or ERP connectors is developed by our Nanjing engineering team and scoped separately.
Related reading
- What is a kiosk? and types of kiosks.
- Smart vending machines: what “connected” should mean in practice.
- ServiceNow integration and payments.
- Kiosk cost: hardware, software and running costs.
- Customer Service FAQ: MOQ, lead times, warranty and support.
Get started
Tell us what the kiosk must do, which payment methods and peripherals it needs, and which systems the data has to reach. We will say what our standard software covers and what would need custom development, with the software scoped and quoted separately.
Project brief · 60 seconds
What are we building together?
Three quick steps. Your brief goes straight to the engineers who design, build and support KioskForce systems.