Enterprise
Everything we can prove, and everything we can’t
You are going to send us a security questionnaire. This page is the answer key — what SignlOS provides today, what an Enterprise contract adds, and which rows we will have to answer “no” to.
Today, on every paid plan
What the platform already does
Not a plan, not a roadmap item. These are properties of how SignlOS is built.
Passwordless by construction
Sign-in is a one-time code by email or SMS, or a passkey using Touch ID, Face ID, or a hardware security key. There is no password store to breach and no reset flow to phish — which answers a surprising number of questionnaire rows outright.
Scoped, revocable machine credentials
API keys carry 14 scopes, are confined to the versioned API, and inherit their creator's workspace role — re-checked on every request, so removing a person disables their keys in the same moment.
Isolation enforced in the query
Every row carries a tenant id and every query is scoped by it, including the ones the REST API and MCP server serve. A credential resolves to exactly one workspace and cannot address another.
Flat pricing, whole company
$29 per month covers unlimited teammates. You never have to decide which support agents are allowed to read customer feedback.
AI access you control
The MCP server puts your feedback in front of an assistant under the same scoped key as everything else. Read-only by default; write scopes are a deliberate grant, not a toggle someone finds later.
Your domain, your brand
Portal and status pages serve from your own domain over HTTPS, with certificates issued automatically.
What a contract adds
The commercial layer
Enterprise is not a different product. It is the same platform with the paperwork and the commitments a procurement process needs.
- Contracted support response times
- Invoicing and purchase orders, rather than a card
- A completed security questionnaire and a named technical contact
- MSA and DPA review with your legal team
- Custom limits where the standard plan does not fit
- Advance notice of breaking API changes
How the conversation goes
- 1You send the questionnaire. We answer it, including the rows where the answer is no.
- 2We agree limits, response times, and terms.
- 3Legal reviews the MSA and DPA.
- 4You are on the same platform as everyone else, with a contract behind it.
Not yet
Where we will answer “no”
Better here than in week three of an evaluation. If any of these is a hard requirement, SignlOS is not the right fit today and we would rather say so.
No SAML or SCIM single sign-on
Sign-in is one-time codes and passkeys. Passkeys are phishing-resistant and hardware-backed, which satisfies some SSO requirements and not others. If IdP-managed provisioning is mandatory for you, SignlOS is not there yet.
Three roles, not custom ones
Owner, admin, and member. There is no custom-role builder and no per-board permission matrix.
No audit-log export
There is no exportable audit trail to forward to a SIEM today.
One hosting region
Data is stored in AWS US East (N. Virginia). There is no EU region, so EU-only data residency cannot be met.
Not SOC 2 certified
SignlOS is working toward SOC 2 Type II. It is not certified today.
No contractual uptime SLA on self-serve
The public status page at /p/signlos/status reports live component health; SignlOS does not publish a contractual uptime SLA on self-serve plans. An availability commitment can be negotiated as part of an Enterprise contract.
Questions
Frequently asked
Send us the questionnaire
We will fill it in honestly and tell you where we fall short, before you have spent a month evaluating.
Contact sales