Security

How SignlOS protects your data

Everything below is a property of how the system is built, not an intention. The second half of the page is the part most vendors leave out.

Encryption

TLS 1.3 in transit and AES-256 at rest, including database backups. HTTPS is enforced — plain HTTP is redirected, not served.

No passwords to steal

Authentication is a one-time code by email or SMS, or a passkey using Touch ID, Face ID, or a hardware security key. There is no password hash table in the database, no reset flow to phish, and nothing a customer can reuse from a site that has already been breached.

Workspace isolation in the query

Every row carries a tenant id and every query filters on it — the API, the public endpoints, and the MCP server included. Isolation is a WHERE clause on the data path, not a check a caller could route around.

Scoped machine credentials

API keys are stored only as SHA-256 hashes, carry 14 narrow scopes, and are rejected outside the versioned API. A key can never grant more than its creator currently holds, and it is re-checked on every request.

Managed infrastructure

S3 + CloudFront for the web front end. ECS Fargate for the API. Aurora PostgreSQL for application data. The application layer runs in private subnets; nothing but the load balancer and the CDN is reachable from the internet.

Anti-framing and transport headers

A Content-Security-Policy frame-ancestors allowlist, HSTS with a one-year max-age and includeSubDomains, X-Content-Type-Options, and a strict referrer policy are set at the edge on every response.

Public status page

Incidents affecting SignlOS are posted to our own status page, on the same software customers use. You do not have to ask us whether something is down.

Data portability

Boards, posts, votes, roadmap, and changelog export as JSON through the REST API at any time, with a read-only key. There is no export queue and no exit fee.

Just as important

What we do not claim

A security page that lists only strengths is a security page you cannot trust. If any of these is a hard requirement for you, we would rather you knew now.

  • SignlOS is working toward SOC 2 Type II. It is not certified today.
  • There is no ISO 27001 certification, and no HIPAA BAA.
  • There is no SAML or SCIM single sign-on. Passkeys are phishing-resistant but not identity-provider managed.
  • There is no customer-facing audit log or SIEM export.
  • There is one hosting region — aws us east (n. virginia). — so EU-only data residency cannot be met.
  • The public status page at /p/signlos/status reports live component health; SignlOS does not publish a contractual uptime SLA on self-serve plans.

More detail for procurement is on the Enterprise page.

Questions

Frequently asked

Disclosure

Reporting a vulnerability

Email security@signlos.com with enough detail to reproduce the issue. We will acknowledge it and keep you updated through the fix. We will not pursue anyone who reports a genuine issue in good faith and without accessing other customers’ data.