Schema gate
Unknown fields and unsafe values fail validation before durable ingestion.
Security by contract
SignalOps is designed around bounded operational facts. Security controls sit at schema validation, identity, tenant authorization, storage, and credential lifecycle boundaries.
Unknown fields and unsafe values fail validation before durable ingestion.
Managed ingest secrets appear once; only SHA-256 digests and safe prefixes persist.
Operator membership is revalidated against durable storage near every protected read and mutation.
Browser roles have no direct grants to SignalOps tables or administrative RPCs.
SignalOps currently does not claim SOC 2 certification, ISO 27001 certification, HIPAA eligibility, or a contractual 99.9% SLA. Those require independent scope, controls, evidence, legal terms, and completed audits. The product does enforce HTTPS in production, HSTS, CSP, same-origin mutation checks, signed HttpOnly operator sessions, rate limits, bounded payloads, audit events, retention jobs, and revocable tenant credentials.
To report a security issue, use the contact channel and mark the request as security-related. Do not include production secrets or customer content.