All Legal Documents

Security

Effective date: October 1, 2026

Get AI Explanation

Need help understanding this document? Get an AI-powered explanation from your favorite AI models.

This page describes how Signa protects your account, your API keys, and the searches you run. It lists the controls we have in place today and the ones we are still working towards.

What we protect

Most of the trademark data Signa serves is public. It comes from official trademark registries and public corporate-data sources. What is not public is how you use it: the names you search, the marks you watch, your account details, and your API keys. Your searches can reveal plans that have not been announced, such as a product name or a mark a client intends to file. We treat that as confidential.

  • Your searches, watches, and request logs are scoped to your organization. No other customer can see them.
  • We do not sell, share, or publish customer queries.

Infrastructure

Signa's API runs on Amazon Web Services (AWS) in the US East region. Our website is served through Vercel.

Data residency: Account information, API request logs, and query data are stored in US East.

Network: Databases, search clusters, and caches run in private subnets and are not reachable from the internet. Public traffic enters through AWS CloudFront and a web application firewall (WAF).

Encryption

In transit: All connections to the Signa API and website use TLS 1.2 or higher. HTTP requests are redirected to HTTPS.

At rest: Our database, search cluster, cache, and object storage are encrypted at rest with AES-256, using AWS-managed keys.

API keys: API keys are stored only as hashes. We cannot see or recover your key after it is created. If you lose a key, revoke it and create a new one.

Access control

Customer accounts: API access requires an API key. You can sign in with email and password, or with Google, which applies your Google account's multi-factor authentication.

Internal access: Access to production is limited to the people who need it to run the service. The AWS root account is protected by multi-factor authentication. Deployments run through our CI/CD pipeline using short-lived credentials rather than stored keys.

Third parties: No third party has direct access to our production databases. Sub-processors receive only the data they need for their function. The full list is in our Privacy Policy and DPA.

Application security

Development: Every change goes through a pull request, automated tests, and code review before it is deployed.

Dependencies: Third-party dependencies are scanned for known vulnerabilities on every change and every six hours against production code. Security updates are proposed automatically.

API protections: Every endpoint requires authentication and applies rate limiting and input validation.

Patching: We fix vulnerabilities based on severity. Our targets:

SeverityTarget remediation time
Critical24 hours
High7 days
Medium30 days
LowNext release cycle

Monitoring and incident response

Logging: API requests are logged and kept for 90 days. Administrative actions on our AWS account are recorded in an audit log.

Alerting: Automated alerts cover errors and service health.

Incident response: We have a defined process for investigating and resolving security incidents and for telling affected customers.

Breach notification: If a personal data breach affects you, we will notify you without undue delay and within 72 hours of becoming aware of it. Where the GDPR requires it, we will also notify the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus. See our Privacy Policy for details.

Backups and availability

Backups: Our database is backed up continuously with point-in-time recovery, and backups are kept for 7 days. Backups are encrypted.

Recovery targets:

MetricTarget
Recovery Point Objective (RPO)1 hour
Recovery Time Objective (RTO)4 hours

Uptime: Current and historical uptime is on our status page at status.signa.so.

Compliance

Framework / RegulationStatus
GDPR (EU General Data Protection Regulation)Compliant
Cyprus Data Protection Law (Law 125(I)/2018)Compliant
EU AI ActMonitoring; compliance program in progress
SOC 2 Type IIPlanned
ISO 27001Planned
Independent penetration testPlanned

Our infrastructure providers, including AWS, hold their own SOC 2 and ISO 27001 certifications.

Security reviews

If your organization has a vendor security questionnaire, send it to security@signa.so and we will complete it. We can also provide our Data Processing Agreement and sub-processor list.

Responsible disclosure

If you find a security vulnerability in Signa, please report it to us.

How to report: Email security@signa.so with a description of the issue, steps to reproduce, and any supporting evidence.

What we commit to:

  • Acknowledge your report within 2 business days
  • Give an initial assessment within 5 business days
  • Keep you informed while we fix it
  • Not pursue legal action against researchers who act in good faith and follow this policy

What we ask:

  • Give us reasonable time to fix the issue before public disclosure
  • Do not access, modify, or delete other customers' data
  • Do not run denial-of-service tests against production
  • Do not use social engineering against Signa staff

Contact

Signa Technologies Ltd Registration No. HE 495212 Fellachoglou 35, Mouttallos 8016 Paphos, Cyprus

Security: security@signa.so Privacy: privacy@signa.so Legal and DPA requests: legal@signa.so

This page was last updated on October 1, 2026.