Security and governance

Move with intelligence.
Keep control of the action.

Signal OS is designed so evidence, access and approval survive the pressure to move quickly. We publish only controls that are implemented—never badges we have not earned.

01

Tenant isolation

Workspace-scoped PostgreSQL records use enforced row-level security and least-privilege runtime access.

02

Secure identity

Passwords use Argon2; sessions, resets, invitations and activation secrets are opaque and stored only as hashes.

03

Human approval

Outbound communication and high-risk mutations remain approval-gated and attributable to a person.

04

Evidence lineage

Sources, confidence, contradictions, workflow artifacts and meaningful actions remain inspectable.

05

Server-side secrets

Provider keys, OAuth credentials, webhook secrets and model configuration are never exposed to public UI code.

06

Untrusted inputs

External payloads and model output are validated and normalised before structured storage or rendering.

Data and account lifecycle

A considered end to the service.

Closing a subscription, removing access and deleting data are separate steps. Contact us to arrange an export or discuss a deletion request.

  1. 01 / ExportPlan your handover

    Request an export before your paid access ends. We verify that the requester is authorised for the workspace.

  2. 02 / AccessControl continued access

    Subscription status and workspace permissions govern access. Ask support about available recovery options.

  3. 03 / RetentionReview what must be retained

    Deletion requests are reviewed for legal, billing and security obligations. Automatic irreversible deletion is not enabled.

Responsible disclosure

Report a security concern directly.

Send a concise description to security@signaloshq.com. Do not include live credentials or personal data.

security@signaloshq.com