Security at SignalDesk
A plain-language summary of how we keep your brand inputs and AI-generated drafts private. For the legal version, see the Privacy Policy.
Authentication
- Email + password or Google sign-in.
- Sessions are revalidated on every server request.
- Passwords found in known public breaches are rejected.
- Email verification is required. No anonymous accounts.
Your data stays yours
- Brands, opportunities, and billing records are scoped to your account. Other users can't see them.
- Admin actions are checked on the server, not just in the UI.
- Billing state can only be changed by verified Stripe events.
Transport and hosting
- HTTPS everywhere. All traffic is TLS-encrypted in transit.
- Data at rest is encrypted by our managed cloud provider.
- Served behind a global edge network with DDoS protection.
AI and external processing
- Your brand inputs are sent to AI providers only to generate opportunities and drafts for your brand.
- We do not authorize providers to train their models on your data.
- Card data never touches our servers. Payments are handled by Stripe.
Account control
- Delete your account at any time from Plan & billing → Danger zone. This removes your data and cancels any active subscription.
- Edit your brand inputs whenever you need to.
What we don't claim
We're not currently SOC 2 or ISO 27001 certified, and we don't yet offer multi-factor authentication or SSO. If those are blockers, get in touch.
Report a vulnerability
Found a security issue? Email security@rtovmarketing.com. Please don't publicly disclose until we've had a chance to investigate.