Skip to content

Site search

Type to search Pages

Trust centre

For the person who has to sign off on relying on us.

This page states where your data lives, who else processes it, what our AI colleagues do without a human in the loop, and — just as plainly — what we do not yet have.

Where data lives

Where your records sit, and who hosts them.

The website is a public surface today; these are the facts a reviewer would check first.

Single-tenant database

Records are stored in a Neon Postgres database provisioned for this venture alone — not a shared multi-tenant store that mixes our records with anyone else's.

Hosted on Netlify

The website and its delivery run on Netlify. Nothing about the hosting arrangement is hidden: the processor is named below and published in full.

Encrypted in transit

Traffic between a browser and the service is encrypted, so records moving over the wire are not exposed to a party sitting between the two.

One codebase, one rule set

The mobile and desktop applications are built from the same code and the same rules as the website, and talk to the same authenticated endpoints — there is no second, looser path in.

The five providers that process personal data.

Netlify

Hosts the website and delivers it to the browser.

Neon

Runs the managed Postgres database in which this site stores its records.

Resend

Delivers transactional email — the messages the site sends in direct response to something you do.

Plausible Analytics

Measures usage without cookies and identifies nobody, so we can count visits without building a profile of a visitor.

What is automated, and what a human decides.

A security reviewer looks for specifics, so this page describes what runs today rather than what is planned. Signura is currently a public website. There is no authenticated product surface yet, which means there is no sign-in, no user accounts, and no in-product data for a signed-in user to reach or alter. When there is one, this page will describe its access boundaries here; until then, claiming access controls that do not yet run would tell you nothing true.

What our AI colleagues do without a human

The recurring work on this site is narrow: sending a transactional email in response to your action, measuring usage without cookies, and checking a public form for abuse. No AI colleague makes a material commitment on its own account. The people accountable for Signura review and approve any change to how personal data is handled, and any request a person makes about their own data is answered by a human, not resolved automatically.

Accessibility

The interface is built to WCAG 2.1 AA: semantic structure, full keyboard operability, visible focus, dialogs that trap and then restore focus, and honoured reduced-motion settings. We have not commissioned an independent accessibility audit; the Accessibility Statement at /legal/accessibility records what we have tested ourselves, so you can see the basis for the claim rather than take it on faith.

What we do not have

What we cannot claim, stated plainly.

An honest absence is more useful to a reviewer than a vague assurance. Here is what a buyer often expects that we do not yet hold, and what exists instead.

No certifications yet

Signura holds no SOC 2, ISO 27001 or equivalent certification, and has commissioned no independent security audit or penetration test. We will not display a badge we have not earned. What is true is described above: what is encrypted, who processes data, and what a human approves.

No uptime commitment

We publish no availability figure and offer no service-level agreement. Inventing one would fabricate the very number a buyer relies on. Any such commitment would live in a signed contract, not on this page.

No bug bounty

There is no paid disclosure programme and no reward for reporting a flaw. What exists instead is a published route for reporting a vulnerability, described below.

No security desk to name

As a pre-launch venture we have no dedicated security team, CISO or headcount to name. A person accountable for Signura reads and answers what you send.

Reporting a vulnerability.

If you find a security issue, there is a published route for reporting it. The Vulnerability Disclosure Policy, published at /legal/security-disclosure, sets out what is in scope, what good-faith research means here, and what a reporter can expect to hear back. We would rather you tell us than not, and the policy is written so a researcher knows where the boundaries are before they begin.

Security review

What a security review actually asks.

Where is our data stored?

In a Neon Postgres database provisioned for this venture alone, delivered through Netlify, with traffic to the browser encrypted in transit. Neon and Netlify appear on our published Sub-processor List, and no other store holds our records.

Who can see our data?

There is no authenticated product surface yet, so no external user signs in to view anything. The only parties that receive personal data are the five named sub-processors, each limited to the function it performs. Internally, the humans accountable for Signura handle any data request.

What happens if you discover a breach?

We have not had to handle one. Our commitments on how personal data is handled and how affected people are informed are set out in the Privacy Policy, so they are written down rather than improvised. We do not overstate a process we have not exercised.

Can we get a data-processing agreement?

Yes. Business customers can obtain data-processing terms before any customer data is processed. Ask us before you send anything, and we will provide the terms to review.

What do your agents do without a human?

On this website, the automated work is confined to three things: sending transactional email in response to your action, cookieless usage measurement, and anti-abuse checks on public forms. None of that touches a customer's records or reaches a decision that binds anyone. Anything consequential is left to the people accountable for Signura, and a person answers any request you make about your own data.

What can we ask for about our own data?

You can ask what personal data is held about you, ask for it to be corrected, and ask for it to be deleted. Write to hello@signura.ai, and the Privacy Policy sets out how each request is handled.

Ask a question, or read the detail.

Send a security question and a person will answer. The Privacy Policy sets out, in full, how we handle personal data.