Your data, your tenant, your Machines.
Signal handles data the way a sane company should: per-tenant isolation, sandboxed execution, no shared training. Below is the short version. We're happy to share the longer one — and a real DPA — once you're talking to us.
-
Your data stays in your tenant
Every customer gets an isolated tenant. Data, embeddings, model weights, conversations — all live in storage scoped to your organization. No tenant can see another tenant's data, ever. Encrypted at rest with per-tenant keys.
-
Sandboxed execution
Code execution and browser automation run in disposable sandboxes that are torn down when the session ends. The sandbox can't reach your network, can't persist files unless you explicitly save them, and can't talk to other tenants.
-
We don't train shared models on your data
Your data is used to train Machines for you. It is never pooled with other customers' data, and we never use it to fine-tune the underlying foundation models. If a Machine you build references your data, only your tenant can use that Machine.
-
Wipe on demand
One click and everything goes — every dataset, every Machine, every conversation, every embedding. We propagate the deletion to every backing store within 24 hours and confirm in writing.
-
Compliance roadmap
We're early alpha and not yet certified, but we're building toward SOC 2 Type II in parallel with the product. ISO 27001, GDPR/CCPA-compliant data handling, and HIPAA Business Associate Agreement support are on the roadmap. We'll publish dates and audit reports as they land.
Need something specific?
Most security questions we get are about data residency, retention, audit logs, and on-prem deployment options. We cover all of these and are happy to walk through them in detail. Reach out and we'll send the full architecture doc.
Get in touch