Encrypted in transit and at rest
The platform is served only over HTTPS. The database is encrypted at rest. Stored credentials — OAuth tokens, API keys, SMTP passwords, SSO secrets — are encrypted again at field level with AES-256-GCM before they are written, under a key held outside the database.
- TLS in transit
- Database encrypted at rest
- AES-256-GCM field encryption for credentials
- Encryption key held outside the database
Role-based access with an audit trail
Each workspace's records are scoped to that workspace in the data-access rules, not just the interface. Within a workspace, permissions follow the member's role. Record changes, exports and LP document views are written to an audit log with the acting user, time and, where available, IP address — and audit entries cannot be edited or deleted through the API.
- Role-based permissions
- Workspace isolation
- Append-only audit log (via the API)
- SAML SSO on every plan
Managed, replicated infrastructure
The platform runs on managed cloud infrastructure, served only over HTTPS. The database runs as a replicated cluster, so losing one machine loses no data. Ask us for the current backup schedule and recovery targets — we will put them in writing rather than on a banner.
- Managed hosting
- Replicated database
- Encrypted at rest
- HTTPS only
- DDoS protection
SOC 2 Type II audit in progress
A SOC 2 Type II audit is in progress; we do not hold a report today, and this page will say so when we do. Our data processing is aligned with GDPR and CCPA, and a Data Processing Agreement — GDPR Article 28, with Standard Contractual Clauses for international transfers — is available. EU data residency available on Enterprise plans.
- SOC 2 Type II audit in progress
- GDPR- and CCPA-aligned data processing
- DPA available
- EU data residency (Enterprise)
Rate limits, lockouts and failed-action tracking
Sign-in, sign-up and public endpoints are rate limited. An account is locked for ten minutes after five consecutive failed sign-ins. Failed actions are recorded in the workspace audit log, where admins can review them.
locked · 10 min
- Rate limiting + throttling
- Lockout after 5 failed sign-ins
- Failed actions in the audit log
- Admin-visible audit trail
Breach notification under the DPA
Security reports go to security@deelsignal.com. Customers who sign our DPA are notified of a personal data breach affecting their data without undue delay, with what is known about its scope and the steps taken.
- security@deelsignal.com
- Breach notification without undue delay (DPA)
- Audit log available for investigation
Our Data Processing Agreement template and the full list of vendors that process customer data, with what each receives and where it is located.
We take security reports seriously and respond within 48 hours. Please disclose responsibly — we do not pursue legal action against good-faith researchers following our disclosure guidelines.
security@deelsignal.comReport a vulnerability