Skip to content
Signal OS
How it worksFor PropTechIntegrationsInsightsPricingSecurityContact
Sign in

Legal / Security controls

Technical and organisational measures

The baseline controls used to protect Signal OS customer data. The final schedule is incorporated into an executed DPA.

Draft — not approved for production use.The production control inventory, hosting regions, recovery evidence and counsel wording require final verification.
Operational draft · Version 2026-08-25.v6 · Last updated 25 August 2026

Governance and responsibility

Security and privacy responsibilities are assigned to authorised operators. Material changes, incidents, access reviews and high-risk actions are recorded. Personnel and contractors with access to customer data are subject to confidentiality obligations and least-privilege expectations.

Identity and access control

Authenticated application access uses named user identities, protected sessions and role-based permissions. Workspace operations are tenant-scoped in PostgreSQL. Platform administration is separately permissioned, and individual outbound communication and irreversible deletion require recorded human approval.

Tenant isolation and data handling

Tenant-owned records use workspace identifiers and database policies that fail closed when no trusted tenant or system context is present. External content, webhook payloads, model output and connector results are treated as untrusted, validated and reduced before structured persistence or rendering. Model requests contain bounded task context rather than provider credentials; provider data collection is denied at the request-routing layer unless a separately approved production configuration states otherwise.

Secrets and encryption

Provider, OAuth, webhook and model credentials remain server-side and are not returned to browsers. Sensitive one-time values are encrypted or retained only as one-way verifiers. Production transport uses TLS. The final schedule will identify verified storage-encryption and key-management controls for each production provider.

Change, vulnerability and supplier management

Application changes are reviewed and tested in proportion to risk. Dependency, configuration and security findings are tracked to resolution. Providers are assessed for their role, data access, processing location and contractual safeguards before production use.

Logging, monitoring and incident response

Meaningful automation, approval, billing, access and service-case actions persist to PostgreSQL and are visible through operational or activity history. Webhooks are signature-verified and deduplicated. Suspected incidents are triaged, contained, investigated and documented, with customer notification handled under the DPA and applicable law.

Availability, recovery and deletion

Operational work uses durable queues, idempotency keys and retry controls. Backup, restore and recovery procedures are tested before the retention promise is enabled. Workspace deletion is separately gated by an exact allowlisted manifest, legal-hold check, live entitlement recheck, tenant-safe transaction and permanent audit evidence.

Customer responsibilities

Customers control their users, connected systems, lawful data sources and outbound approvals. Customers should grant only necessary access, protect credentials, review generated outputs and avoid uploading credentials or unnecessary sensitive data.

Signal OS

The commercial real estate signal-to-action workspace for PropTech sales teams.

Signal OS is owned and operated by SCIALO CONSULTING LTD.

ProductFor PropTech sales teamsBuilding energy and controlsProperty operationsWorkplace and occupancyIntegrationsPricing
ResourcesCRE buying signals guideCRE signal insightsSignal OS and your CRMSecurityProof of SignalContact
CompanyCompany and ownershipPrivacy noticePrivacy rightsTermsCookiesDPASecurity measuresSubprocessors
Anonymous site analytics: onHow measurement works

© 2026 SCIALO CONSULTING LTD. Registered in England and Wales under company number 16357294. Registered office: 1st Floor Spitalfields House, Stirling Way, Borehamwood, Herts, England, WD6 2FX. VAT registration number: 493809938.