Skip to main content

Security & Compliance

Built for enterprise from day one.

SiteSignal treats your project data with the same rigor you bring to a $50M build. Here is exactly what we do to protect it — and what's on our roadmap.

What's active today.

Encryption in Transit & At Rest

Active

All data encrypted in transit using TLS 1.3. Data at rest encrypted using AES-256. No data is ever stored or transmitted in plain text.

Multi-Tenant Data Isolation

Active

Your organization's data is strictly isolated from all other customers using row-level security policies enforced at the database level — not just in application code. Even a bug in our application cannot return another organization's data.

Role-Based Access Control

Active

Four permission levels: Admin, Project Manager, Executive, and Viewer. Permissions enforced server-side on every request. Organization admins control all user access and can revoke it instantly.

Audit Logging

Active

Every data change logged with timestamp, user ID, and before/after values. Full audit trail available to organization admins. Logs are immutable and retained for the life of the account.

Compliance roadmap.

We're honest about where we are and where we're going. No security theater. SiteSignal is an early-stage company: we are not SOC 2 certified and have not completed a third-party penetration test. Below is the actual calendar we are working against.

  1. Data Processing Addendum (DPA)

    AVAILABLE NOW

    Our DPA is published in full — roles, processing details, security measures, subprocessors, 72-hour breach notification goal, audit rights, and deletion terms. Email legal@getsitesignal.io for a countersigned copy.

  2. Multi-Factor Authentication

    AVAILABLE NOW

    TOTP multi-factor authentication is available to every organization, and admins can require it for all members. Members without a verified factor are routed to enrollment on sign-in.

  3. Single Sign-On (SSO/SAML)

    ENTERPRISE — CONFIGURE WORKOS

    Built on WorkOS for broad identity provider compatibility (Okta, Entra ID, Google Workspace). The integration ships with the product; each Enterprise tenant is connected during onboarding. Contact sales to schedule provisioning.

  4. SOC 2 Type I

    TARGET H1 2027

    We are not SOC 2 certified today and will not imply otherwise. Control design work is underway against the Security trust services criteria, with an independent CPA examination targeted for the first half of 2027.

  5. SOC 2 Type II

    IN PROGRESS

    Compliance monitoring active via Vanta. Observation period underway. Independent CPA audit targeted for completion H1 2027. This is a proactive compliance initiative — not in response to any regulatory requirement.

  6. Third-Party Penetration Testing

    ANNUAL FROM 2027

    An external penetration test by a licensed firm is planned ahead of the SOC 2 Type I examination in 2027, then annually. We have not yet completed one, so there is no report to share today. Coordinated customer-led testing is welcome in the meantime — write to security@getsitesignal.io.

How we handle your data.

Where your data lives

US-based infrastructure (AWS US-East). No data stored outside the United States. Backups encrypted and retained for 30 days.

What we send to AI

Aggregated project metrics — budget figures, schedule percentages, RFI and change order counts. We do not send employee names, contacts, credentials, or documents to Anthropic's API. Free-text project fields may appear in context, so treat them accordingly. Our provider does not train on business API inputs or outputs.

Who can see your data

SiteSignal personnel with a documented need. All access logged. No data sold, shared, or used to train AI models. You own your data completely and can export all of it as CSV at any time.

Security review? We'll respond within one business day.

If you're a security team conducting a vendor review, or a procurement team with specific compliance requirements, contact us directly.

Policy documents: Privacy · DPA · Terms · Documentation