Security & Trust
ManySignal is built for security teams — which means our own security posture is held to the same standard we demand from your tools.
SOC 2 Type II
Audited annually
ISO 27001
Certified
HIPAA
BAA available
GDPR Ready
DPA available
How we secure ManySignal
Controls governing the ManySignal platform itself — how we protect the system that handles your data.
Encryption at rest
All tenant data encrypted with AES-256. Encryption keys managed per-tenant via AWS KMS or customer-managed key (CMK) configurations.
Encryption in transit
TLS 1.2 minimum enforced across all API endpoints, internal service mesh, and data pipelines. TLS 1.3 preferred.
Per-tenant isolation
Each tenant operates in a logically isolated data plane. Cross-tenant data access is architecturally impossible — verified annually by a third-party penetration test.
Key management (KMS)
AWS KMS with HSM-backed key material. Key rotation enforced every 365 days. CMK option available for Enterprise and self-hosted deployments.
Secrets rotation
All service credentials, API tokens, and signing secrets are rotated automatically on a 90-day cycle using HashiCorp Vault with zero-downtime rotation.
Audit logging
Every platform event — login, query, rule change, response action — is immutably logged with actor identity, timestamp, and before/after delta. Tamper-evident.
How we secure your data
Controls you configure — giving your team sovereignty over where data lives and who can access it.
Customer-managed encryption keys
Enterprise tenants can supply their own KMS key. ManySignal never touches your key material — revoke access and your data is cryptographically inaccessible.
VPC peering
Connect ManySignal to your data sources over a private VPC peering connection. No data traverses the public internet.
AWS PrivateLink
Ingest telemetry directly from your AWS environment via PrivateLink endpoints. Supported for all major log sources and S3 buckets.
Dedicated tenancy option
Enterprise customers can request dedicated infrastructure (single-tenant compute and storage) in the region of their choice.
Data residency by region
Choose where your tenant data is stored and processed: US East, EU West, AP Southeast, or UK. Data never leaves your chosen region.
Zero-trust internal network
All internal service-to-service calls require mTLS and short-lived SPIFFE credentials. No implicit trust based on network location.
Security certifications
| Framework | Status | Report | Renewal |
|---|---|---|---|
| SOC 2 Type II | Active | Available under NDA | March 2026 |
| ISO 27001 | Active | Certificate available | September 2025 |
| HIPAA BAA | Available | Sign via customer portal | Evergreen |
| PCI DSS | SAQ-D compliant | On request | Annual |
| FedRAMP | In Process | Package in review | Expected Q3 2026 |
| GDPR / DPA | Active | DPA available in portal | Evergreen |
Incident response
Our runbook — with time-bound SLOs — for any security incident affecting customer data.
Detect & triage
SLO < 1 hourAutomated anomaly detection on platform telemetry triggers an internal P1 ticket. On-call engineer acknowledges within 60 minutes around the clock.
Contain
SLO < 2 hoursBlast radius assessed, affected systems isolated or patched, customer data access reviewed for breach scope.
Customer notification
SLO < 4 hoursAffected customers notified by email with incident ID, scope, and initial impact assessment within 4 hours of declaration.
Root cause analysis
SLO < 72 hoursFull RCA delivered to affected customers within 72 hours. GDPR-mandated notifications filed within 72 hours of confirmed breach.
Post-incident review
SLO < 14 daysPublic post-mortem published (sanitised). Corrective controls deployed and evidenced. Customer sign-off on remediation.
Responsible disclosure
If you discover a vulnerability in ManySignal, we want to hear from you. We operate a safe-harbor responsible disclosure program — we commit to no legal action against researchers who disclose in good faith, and we acknowledge and triage all reports within 5 business days.
Detailed scope, out-of-scope exclusions, and CVD policy are published at our vulnerability disclosure policy page.
Read the disclosure policyPGP public key
Encrypt sensitive reports to our security team key. Fingerprint verified on Keybase.
Fingerprint: 3D4A 8B1C 09FF 2E87 4C6D A392 F104 7B5E A3F9 1C2E
Email: [email protected]
Contact the security team
For compliance documents, penetration test summaries, or enterprise security reviews.
Security starts with the platform you trust
Book a session with a solution engineer to walk through our security architecture, compliance docs, and enterprise deployment options.