M ManySignal

Security & Trust

ManySignal is built for security teams — which means our own security posture is held to the same standard we demand from your tools.

SOC 2 Type II

Audited annually

ISO 27001

Certified

HIPAA

BAA available

GDPR Ready

DPA available

How we secure ManySignal

Controls governing the ManySignal platform itself — how we protect the system that handles your data.

Encryption at rest

All tenant data encrypted with AES-256. Encryption keys managed per-tenant via AWS KMS or customer-managed key (CMK) configurations.

Encryption in transit

TLS 1.2 minimum enforced across all API endpoints, internal service mesh, and data pipelines. TLS 1.3 preferred.

Per-tenant isolation

Each tenant operates in a logically isolated data plane. Cross-tenant data access is architecturally impossible — verified annually by a third-party penetration test.

Key management (KMS)

AWS KMS with HSM-backed key material. Key rotation enforced every 365 days. CMK option available for Enterprise and self-hosted deployments.

Secrets rotation

All service credentials, API tokens, and signing secrets are rotated automatically on a 90-day cycle using HashiCorp Vault with zero-downtime rotation.

Audit logging

Every platform event — login, query, rule change, response action — is immutably logged with actor identity, timestamp, and before/after delta. Tamper-evident.

How we secure your data

Controls you configure — giving your team sovereignty over where data lives and who can access it.

Customer-managed encryption keys

Enterprise tenants can supply their own KMS key. ManySignal never touches your key material — revoke access and your data is cryptographically inaccessible.

VPC peering

Connect ManySignal to your data sources over a private VPC peering connection. No data traverses the public internet.

AWS PrivateLink

Ingest telemetry directly from your AWS environment via PrivateLink endpoints. Supported for all major log sources and S3 buckets.

Dedicated tenancy option

Enterprise customers can request dedicated infrastructure (single-tenant compute and storage) in the region of their choice.

Data residency by region

Choose where your tenant data is stored and processed: US East, EU West, AP Southeast, or UK. Data never leaves your chosen region.

Zero-trust internal network

All internal service-to-service calls require mTLS and short-lived SPIFFE credentials. No implicit trust based on network location.

Security certifications

Framework Status Report Renewal
SOC 2 Type II Active Available under NDA March 2026
ISO 27001 Active Certificate available September 2025
HIPAA BAA Available Sign via customer portal Evergreen
PCI DSS SAQ-D compliant On request Annual
FedRAMP In Process Package in review Expected Q3 2026
GDPR / DPA Active DPA available in portal Evergreen

Incident response

Our runbook — with time-bound SLOs — for any security incident affecting customer data.

1

Detect & triage

SLO < 1 hour

Automated anomaly detection on platform telemetry triggers an internal P1 ticket. On-call engineer acknowledges within 60 minutes around the clock.

2

Contain

SLO < 2 hours

Blast radius assessed, affected systems isolated or patched, customer data access reviewed for breach scope.

3

Customer notification

SLO < 4 hours

Affected customers notified by email with incident ID, scope, and initial impact assessment within 4 hours of declaration.

4

Root cause analysis

SLO < 72 hours

Full RCA delivered to affected customers within 72 hours. GDPR-mandated notifications filed within 72 hours of confirmed breach.

5

Post-incident review

SLO < 14 days

Public post-mortem published (sanitised). Corrective controls deployed and evidenced. Customer sign-off on remediation.

Responsible disclosure

If you discover a vulnerability in ManySignal, we want to hear from you. We operate a safe-harbor responsible disclosure program — we commit to no legal action against researchers who disclose in good faith, and we acknowledge and triage all reports within 5 business days.

Detailed scope, out-of-scope exclusions, and CVD policy are published at our vulnerability disclosure policy page.

Read the disclosure policy

PGP public key

Encrypt sensitive reports to our security team key. Fingerprint verified on Keybase.

Key ID: 0xA3F91C2E
Fingerprint: 3D4A 8B1C 09FF 2E87 4C6D A392 F104 7B5E A3F9 1C2E

Email: [email protected]

Contact the security team

For compliance documents, penetration test summaries, or enterprise security reviews.

Security starts with the platform you trust

Book a session with a solution engineer to walk through our security architecture, compliance docs, and enterprise deployment options.