Security Program
What we actually do, stated plainly, with no badge we have not earned.
Infrastructure
Our platform runs on Microsoft Azure. We inherit the physical, environmental and hardware security controls of that platform, and we are responsible for everything we build on top of it. We do not operate our own data centres.
Data protection
- Data encrypted in transit using TLS 1.2 or higher
- Data encrypted at rest using AES-256
- Database access governed by role-based access control
- Application secrets held in a managed key vault rather than in configuration files or code
Access control
- Multi-factor authentication required for administrative access
- Least-privilege assignment of platform roles
- Service-to-service authentication using managed identity rather than shared credentials
Monitoring and response
Platform and application telemetry is collected centrally and retained. Incident response procedures are aligned to NIST guidance and described on our incident response page.
The data we hold
The substantive data in SignalGround is public federal licensing information. We are not holding a repository of customer secrets. Customer-specific data is limited to account information and the record of queries run, which matters for what an attacker would gain and for what a compliance review needs to examine.
Assessments and certification
Reporting a problem
See the vulnerability disclosure policy.