Documentation

    Security and compliance

    SIGNLD is built for finance and operations data, so the security model is deliberately narrow: read what you authorise, encrypt everything, run inference privately, and never train on your data.

    The canonical facts

    AreaPosition
    Source accessRead-only connectors. SIGNLD does not write, update, or delete records in your systems
    Encryption at restAES-256
    Encryption in transitTLS
    CertificationSOC 2 Type II
    HostingUS-based AWS infrastructure
    InferencePrivate LLM powered by a single-tenant AWS Bedrock instance
    TrainingNever trained on your data

    What Enterprise adds

    • HIPAA BAA for workloads that touch protected health information.
    • GDPR DPA and custom data residency across US, EU, UK, and APAC.
    • Dedicated single-tenant VPC deployment.

    Access control inside the workspace

    • Workspace membership governs who can see Topics and Briefs.
    • Admin rights are separate from read and ask rights, so connection credentials are held by a small group.
    • SSO is available on Business and above.
    • Lineage means every answer can be traced, which is what makes access review meaningful.

    Read the full posture on the security page, or the security policy and data processing addendum.

    Security FAQ

    Can SIGNLD change or delete data in our systems?

    No. Every source connection is read-only by design. SIGNLD requests read scopes only and never writes back to a source system.

    Do you train models on our data?

    No. SIGNLD is never trained on your data. Inference runs on a single-tenant AWS Bedrock instance dedicated to SIGNLD.

    Where is our data hosted?

    On US-based AWS infrastructure by default, encrypted with AES-256 at rest and TLS in transit. Enterprise plans can specify data residency in the US, EU, UK, or APAC.

    Which certifications do you hold?

    SOC 2 Type II. Enterprise agreements add a HIPAA BAA and a GDPR DPA where required.

    Who can see a given answer?

    Access follows workspace membership and permissions. Admins manage connections and definitions, and other members read and ask within the Topics they can access.

    Further reading

    Was this helpful?

    Contact support