We protect your data so you can protect your operation

Signals processes operational support information that may be commercially sensitive. The platform is designed to minimise the personal data it receives and to use customer information only for providing the Signals service.

Data model

Signals primarily analyses operational metadata, aggregated activity, service performance, health indicators and risk signals.

Customers control which systems and information are connected. Depending on the source platform and configuration, connected records may contain limited customer or employee personal data. Signals aims to minimise the collection and storage of information that is not required for analysis.

Encryption

Data is encrypted in transit using TLS. Data stored within our managed hosting and database services is encrypted at rest using the security capabilities provided by those services.

Application credentials and integration secrets are stored using environment configuration or managed secret facilities rather than being embedded directly in source code.

Customer separation

Signals operates as a multi-tenant SaaS platform. Customer data is associated with a specific workspace and access is restricted through application-level tenant checks.

We design access controls around least-privilege principles and do not provide customers or unrelated third parties with direct database access.

Infrastructure

Signals is hosted on managed cloud infrastructure in Europe.

Our infrastructure uses managed hosting and database services, with backups and recovery capabilities determined by the services and plans in use.

Production infrastructure is separated from development activity. Additional test and demonstration environments may use synthetic, anonymised or appropriately authorised data.

Access control

Access to production systems is restricted to authorised personnel who require it to operate and support the service.

Core infrastructure accounts use individual credentials and multi-factor authentication where supported. Permissions are limited according to operational need.

Integrations and data flow

Signals connects to support platforms, CRM systems and related business tools using customer-authorised API credentials or OAuth connections.

Where possible, integrations use read-focused and scoped permissions. Signals does not make material changes to connected customer systems unless the relevant feature has been explicitly enabled and authorised.

Connected data is retrieved, normalised, analysed and associated with the relevant Signals workspace.

Application security

Signals is developed using version-controlled source code and managed deployment processes.

Dependencies are reviewed and updated as the product develops. Build-time checks, framework security controls and application-level authorisation are used where implemented within the current service.

Incident handling

Signals investigates security and availability incidents according to their severity and potential customer impact.

Material incidents are reviewed to understand their cause, contain the issue and reduce the risk of recurrence. Affected customers will be contacted when an incident materially affects their data or use of the service.

Compliance development

Signals is not currently independently certified under SOC 2 or ISO 27001.

As the platform grows, planned security work includes formalising internal controls, expanding security documentation and arranging independent testing before broader enterprise adoption. SOC 2 Type I and later Type II may form part of that future programme.

Data ownership and usage

Customers retain ownership of their data. Signals processes customer information only to operate the service and provide enabled features such as analysis, health scoring, alerts, reports and recommendations.

We do not sell customer data.

We do not use customer data for advertising.

We do not use customer data to train shared AI models unless this has been expressly agreed.

Retention is governed by the customer agreement, product configuration and reasonable operational requirements.

Security questions

For security reviews, data-processing questions or vendor assessments, contact:

[email protected]

We can provide relevant architecture, data-flow and control information based on the current product configuration.