Skip to main content

Trust center

Security you can review before you buy

Review public controls, policy paths, subprocessors, and system status without assuming a certification or private report is currently available.

Signal workspace

Validated, routed, acknowledged.

Partner rules checked
Human decisions drafted
Receipts attached

How your data is handled

Encrypted everywhere

TLS in transit, AES-256 at rest, KMS-managed keys, AWS US regions.

Retention choices

Document retention follows the selected plan and any purchased Vault option; no universal WORM term is implied.

Least-privilege access

Role-based access, MFA options, and reviewable logs support control evaluation on applicable surfaces.

SOC 2 readiness

work; no public report claimed

Healthcare

control readiness + BAA review path

ISO 27001

readiness path; no certification claimed

Status

current operational state on /status

Common diligence questions

Can our auditor get access?

Review role-scoped access and export requirements during diligence; availability depends on the applicable workspace and plan controls.

Where does data live?

Confirm current hosting, residency, and subprocessor details on the public security and policy paths during procurement.

Do you sign BAAs?

A BAA review path is available for qualifying healthcare workflows; no plan-level entitlement is promised on this page.

Pen tests?

Ask for the current diligence-artifact inventory. This page does not promise a report or redacted summary without dated evidence.

Need implementation-specific detail?

Start with public policies and status, then request the current evidence inventory for your review scope.

© 2026 SignalEDI Inc. All rights reserved.