Company / Security
Security is how we earn the right to handle your telemetry
ManySignal processes security-critical data for enterprise customers. We are held to a higher standard than most SaaS vendors — and we think that is appropriate. This page explains what we do about it.
SOC 2 Type II
Security and Availability Trust Services Criteria
ISO 27001:2022
Information Security Management System — Platform Operations
HIPAA
PHI handling for healthcare customers (requires BAA)
GDPR / UK GDPR
EU and UK personal data processing
CSA STAR Level 1
Self-assessment of cloud security controls
How we protect your data
Security control summary
These are the controls that matter most to enterprise security teams. For a detailed Technical and Organisational Measures (TOM) document, contact your account team.
Data protection
- AES-256 encryption at rest
- TLS 1.2+ in transit
- Per-tenant logical isolation at storage, cache, and queue layers
- Zero-data-retention API agreements with all LLM providers
Access control
- RBAC with principle of least privilege
- MFA enforced for all production infrastructure access
- SSO/SAML/SCIM support for customer tenants
- Quarterly access reviews for all internal privileged accounts
Vulnerability management
- Annual third-party penetration testing by qualified assessors
- Continuous SAST and DAST in CI/CD pipelines
- Automated dependency vulnerability scanning (Dependabot + Snyk)
- Coordinated vulnerability disclosure programme (see VDP)
Incident response
- 24×7 security on-call rotation
- Incident response playbooks reviewed annually
- Breach notification within 72 hours under GDPR
- Post-incident reviews published internally within 5 business days
Business continuity
- Multi-region active-active deployment on AWS
- RTO < 4 hours, RPO < 1 hour for P1 incidents
- Disaster recovery tests conducted quarterly
- 99.95% uptime commitment for Enterprise customers (see SLA)
Request our SOC 2 Type II report
Qualified enterprise prospects and customers can access the full audit report via the ManySignal Trust Portal. Contact your account team or [email protected].