Encryption in Transit & At Rest
ActiveAll data encrypted in transit using TLS 1.3. Data at rest encrypted using AES-256. No data is ever stored or transmitted in plain text.
Security & Compliance
SiteSignal treats your project data with the same rigor you bring to a $50M build. Here is exactly what we do to protect it — and what's on our roadmap.
All data encrypted in transit using TLS 1.3. Data at rest encrypted using AES-256. No data is ever stored or transmitted in plain text.
Your organization's data is strictly isolated from all other customers using row-level security policies enforced at the database level — not just in application code. Even a bug in our application cannot return another organization's data.
Four permission levels: Admin, Project Manager, Executive, and Viewer. Permissions enforced server-side on every request. Organization admins control all user access and can revoke it instantly.
Every data change logged with timestamp, user ID, and before/after values. Full audit trail available to organization admins. Logs are immutable and retained for the life of the account.
We're honest about where we are and where we're going. No security theater. SiteSignal is an early-stage company: we are not SOC 2 certified and have not completed a third-party penetration test. Below is the actual calendar we are working against.
Our DPA is published in full — roles, processing details, security measures, subprocessors, 72-hour breach notification goal, audit rights, and deletion terms. Email legal@getsitesignal.io for a countersigned copy.
TOTP multi-factor authentication is available to every organization, and admins can require it for all members. Members without a verified factor are routed to enrollment on sign-in.
Built on WorkOS for broad identity provider compatibility (Okta, Entra ID, Google Workspace). The integration ships with the product; each Enterprise tenant is connected during onboarding. Contact sales to schedule provisioning.
We are not SOC 2 certified today and will not imply otherwise. Control design work is underway against the Security trust services criteria, with an independent CPA examination targeted for the first half of 2027.
Compliance monitoring active via Vanta. Observation period underway. Independent CPA audit targeted for completion H1 2027. This is a proactive compliance initiative — not in response to any regulatory requirement.
An external penetration test by a licensed firm is planned ahead of the SOC 2 Type I examination in 2027, then annually. We have not yet completed one, so there is no report to share today. Coordinated customer-led testing is welcome in the meantime — write to security@getsitesignal.io.
US-based infrastructure (AWS US-East). No data stored outside the United States. Backups encrypted and retained for 30 days.
Aggregated project metrics — budget figures, schedule percentages, RFI and change order counts. We do not send employee names, contacts, credentials, or documents to Anthropic's API. Free-text project fields may appear in context, so treat them accordingly. Our provider does not train on business API inputs or outputs.
SiteSignal personnel with a documented need. All access logged. No data sold, shared, or used to train AI models. You own your data completely and can export all of it as CSV at any time.
If you're a security team conducting a vendor review, or a procurement team with specific compliance requirements, contact us directly.
security@getsitesignal.io
For security reviews and vulnerability disclosures
legal@getsitesignal.io
For DPA requests and legal compliance documentation
Policy documents: Privacy · DPA · Terms · Documentation