Trust Center
Everything your reviewers will ask for, published up front.
SiteSignal is an early-stage company selling to firms with mature vendor review processes. Rather than making you request documents one at a time, they are all here — including the parts that are still roadmap.
Last reviewed August 1, 2026
Documents.
Security
Active controls, what is genuinely in place today, and a dated compliance roadmap with no inflated claims.
Review security controlsPrivacy Policy
What we collect, how it is used, retention periods by data type, international transfers, and how to exercise rights.
Read the privacy policyTerms of Service
Commercial terms: accounts and roles, data ownership, AI disclaimers, invoice-based fees, liability, and termination.
Read the termsData Processing Addendum
Controller and processor roles, processing details, security measures, 72-hour breach notice goal, audit rights, and deletion.
Read the DPAAI disclosure
Exactly what is sent to Anthropic, what is never intentionally sent, that we do not train models on your data, and where human review is required.
See the AI disclosureSubprocessors
The full list of vendors that touch customer data, what each one does, and how we notify you before that list changes.
View subprocessorsCSV import specifications
Column schemas for budget and schedule imports, accepted date and currency formats, and how validation errors are reported.
View import schemasProduct documentation
Role and permission model, how the deterministic risk score is calculated, and what each subscription tier unlocks.
Open documentationPosture at a glance.
| Area | Status | Detail |
|---|---|---|
| Tenant isolation | Row-level security in Postgres | Enforced at the database layer, not only in application code, and covered by automated isolation tests in CI. |
| Encryption | TLS 1.3 / AES-256 | In transit and at rest, including backups. |
| Authentication | MFA available, SSO for Enterprise | Organization admins can require TOTP multi-factor for every member. SAML/OIDC single sign-on is available to Enterprise where configured. |
| SOC 2 Type II | IN PROGRESS | Not certified. Compliance monitoring active via Vanta. Observation period underway. Independent CPA audit targeted for completion H1 2027. Report available upon completion — join the waitlist below. |
| Data residency | United States | All customer data stored on US infrastructure. |
| Data export | Self-serve CSV, any time | Admins export every organization record without contacting us. |
SOC 2 Type II
Audit in progress.
SOC 2 Type II audit in progress. We will notify waitlist subscribers when the report is available. There is no report to request under NDA today.
Who touches your data.
Supabase
Managed Postgres database, authentication, and storage
United States
Vercel
Application hosting, edge network, and request logging
United States
Resend
Transactional email delivery (alerts, reports, invitations)
United States
Anthropic
AI risk narratives, recovery plan drafts, and status reports
United States
Full detail, including data categories and change-notice commitments, is in the DPA.
Running a vendor questionnaire?
Send us your SIG Lite, CAIQ, or internal template and we will return it completed. We will also sign your DPA or ours, and answer follow-ups directly rather than routing you through a portal.
Typical turnaround: one business day.