M ManySignal

Platform Security

The platform that protects you has to be protected too

ManySignal holds your most sensitive telemetry, credentials for your production systems, and control over automated response actions. We take that responsibility seriously: encryption at rest and in transit, zero-trust access, continuous vulnerability management, and annual third-party penetration tests.

Security controls summary

Control area Implementation
Encryption at rest AES-256-GCM for all data at rest. Customer-managed keys (BYOK) supported via AWS KMS, Azure Key Vault, GCP CKMS.
Encryption in transit TLS 1.3 minimum on all external endpoints. mTLS for internal service-to-service communication. Certificate rotation automated via cert-manager.
Authentication SSO (SAML 2.0, OIDC) required for all human access. MFA enforced. Session tokens expire after 8 hours. Refresh tokens expire after 30 days.
Authorization RBAC with predefined and custom roles. Every API request evaluated against a permissions policy. No implicit admin access — break-glass access is time-limited and logged.
Secret management Connector credentials and API keys stored as opaque secrets in an internal vault. Secrets are never returned in plaintext via API after initial entry.
Vulnerability management Container images scanned on build and daily. Critical CVEs are patched within 48 hours. SAST runs on every commit. Annual third-party penetration test.
SOC 2 Type II Annual audit covering Security, Availability, and Confidentiality criteria. Report available under NDA.
Incident response Documented IRP with defined RTO/RPO targets. Customer notification within 72 hours for confirmed data incidents. Post-incident report within 14 days.
Supply chain security SBOM for all production container images. Pinned dependency versions. Artifact signing with cosign. SLSA Build Level 2.

Responsible disclosure and bug bounty

ManySignal operates a private bug bounty program through a third-party coordination platform. Security researchers who discover vulnerabilities in the platform can report them through the coordinated disclosure process. Verified critical and high-severity reports receive a response within 24 hours and a fix within the published SLA window.

Our security team publishes a quarterly security blog post covering the vulnerability classes discovered, time-to-fix metrics, and any platform hardening changes made in response to research findings. We do not suppress or minimize valid reports.

Security properties you can verify

SOC 2 Type II report

Available under NDA. Covers Security, Availability, and Confidentiality trust services criteria. Audit conducted by an accredited third-party firm annually.

Penetration test results summary

Annual third-party penetration test scope and findings summary available to enterprise customers on request. No open critical or high findings at time of last test.

SBOM for all production images

Software bill of materials for every production container image, covering direct and transitive dependencies. Available as CycloneDX or SPDX format via the API.

Network egress logging

All outbound network connections from the platform infrastructure are logged and available to self-hosted customers and cloud customers with the security add-on.

Audit trail integrity verification

The hash-chained audit trail allows independent verification of record integrity using the published chain root and an open-source verification tool.

Shared responsibility document

A detailed shared responsibility matrix covers which security controls are ManySignal's responsibility vs. the customer's, for both cloud-hosted and self-hosted deployments.

Platform Security — FAQ

What happens to my data if I cancel my subscription?

After subscription termination, tenant data is retained for 30 days in case of reinstatement. After 30 days, data is permanently deleted according to our data deletion procedure. A deletion certificate is provided on request.

Does support staff have access to my event data?

No. Support staff access to tenant data requires explicit customer authorization via a time-limited delegation token. Without a delegation token, support can only access metadata (event counts, connector health, error logs) not event content.

Is ManySignal FedRAMP authorized?

FedRAMP Moderate authorization is in progress for the AWS GovCloud deployment. The standard commercial deployment is not FedRAMP authorized. For federal requirements, contact the public sector team for the current authorization status and timeline.

How are connector credentials protected?

Connector credentials (API keys, OAuth tokens, passwords) are stored as opaque secrets encrypted with a tenant-specific data key. The data key is encrypted with a key encryption key managed in your KMS (for BYOK) or ManySignal's KMS. Credentials are never stored in plaintext in any configuration file or database column.

What security certifications does ManySignal hold?

ManySignal is SOC 2 Type II certified (audited annually by an independent assessor), ISO 27001 certified, and HIPAA-eligible. The current SOC 2 report and ISO 27001 certificate are available under NDA on request. Penetration test summaries and the SBOM (software bill of materials) are also available for enterprise prospects.

How does ManySignal handle vulnerabilities in its own software supply chain?

The platform runs automated SCA (software composition analysis) on every build. Critical CVEs in dependencies trigger a patch release within 72 hours. ManySignal publishes a security advisory and releases an updated SBOM for each patch. Customers on the Helm chart distribution receive updates via the standard release channel.

What is ManySignal's penetration testing cadence?

External penetration tests are conducted annually by an independent assessor. Additional targeted tests are run after major architectural changes. Bug bounty submissions are accepted year-round via the responsible disclosure programme at /company/security.

How is multi-factor authentication enforced for platform access?

MFA is required for all user accounts — there is no MFA-exempt role. Supported factors include TOTP authenticator apps, WebAuthn hardware keys, and SAML/SSO federation (which delegates MFA enforcement to your IdP). API key access is separate from user login and uses secret-based authentication.

Does ManySignal use AI training data from customer tenants?

No. Customer telemetry, case data, and verdicts are never used for model training. AI models used in the triage agent are either commercially licensed foundation models or models trained exclusively on publicly available security data. This is a contractual commitment in the DPA.

Security documentation available on request

SOC 2 report, pen test summary, shared responsibility matrix, and SBOM — request the full security package.