M ManySignal

Company / Security

Security is how we earn the right to handle your telemetry

ManySignal processes security-critical data for enterprise customers. We are held to a higher standard than most SaaS vendors — and we think that is appropriate. This page explains what we do about it.

SOC 2 Type II

Security and Availability Trust Services Criteria

Certified

ISO 27001:2022

Information Security Management System — Platform Operations

Certified

HIPAA

PHI handling for healthcare customers (requires BAA)

Compliant

GDPR / UK GDPR

EU and UK personal data processing

Compliant

CSA STAR Level 1

Self-assessment of cloud security controls

Listed

How we protect your data

Security control summary

These are the controls that matter most to enterprise security teams. For a detailed Technical and Organisational Measures (TOM) document, contact your account team.

Data protection

  • AES-256 encryption at rest
  • TLS 1.2+ in transit
  • Per-tenant logical isolation at storage, cache, and queue layers
  • Zero-data-retention API agreements with all LLM providers

Access control

  • RBAC with principle of least privilege
  • MFA enforced for all production infrastructure access
  • SSO/SAML/SCIM support for customer tenants
  • Quarterly access reviews for all internal privileged accounts

Vulnerability management

  • Annual third-party penetration testing by qualified assessors
  • Continuous SAST and DAST in CI/CD pipelines
  • Automated dependency vulnerability scanning (Dependabot + Snyk)
  • Coordinated vulnerability disclosure programme (see VDP)

Incident response

  • 24×7 security on-call rotation
  • Incident response playbooks reviewed annually
  • Breach notification within 72 hours under GDPR
  • Post-incident reviews published internally within 5 business days

Business continuity

  • Multi-region active-active deployment on AWS
  • RTO < 4 hours, RPO < 1 hour for P1 incidents
  • Disaster recovery tests conducted quarterly
  • 99.95% uptime commitment for Enterprise customers (see SLA)

Request our SOC 2 Type II report

Qualified enterprise prospects and customers can access the full audit report via the ManySignal Trust Portal. Contact your account team or [email protected].