Skip to main content

Security & trust

Your account evidence and reports stay under your control.

A clear account of the safeguards ClientSignal uses today—from encrypted credentials and tenant isolation to human approval, export, and deletion controls.

AES-256-GCM Encryption
Supported OAuth tokens and sensitive integration credentials are encrypted at rest with AES-256-GCM. Encryption keys are stored separately from application data.
Row-Level Security (RLS)
Tenant-scoped queries, foreign keys, and database row-level policies restrict authenticated access to the current agency. Privileged service paths are separately authorized and tested.
Protected Integration Credentials
Supported integrations use provider-authorized connections or scoped credentials; ClientSignal does not request connected-platform passwords. Klaviyo uses a user-supplied private API key. Stored credentials are encrypted at rest and can be revoked at the provider.
Third-Party Infrastructure Controls
ClientSignal runs on Vercel and Supabase. Their current compliance documentation describes their independent controls and certifications; ClientSignal does not currently claim its own SOC 2 certification.
Transparent AI Data Handling
ClientSignal sends the inputs needed for report generation and, for explicitly granted Managed or Founding Pilot workspaces, Attention-brief assistance to its configured AI provider. ClientSignal does not use customer data to train its own models. Provider processing and retention are governed by the applicable commercial API terms; ask us for the current data-flow details.
HTTPS Everywhere
ClientSignal serves application traffic over HTTPS, including its public app, API endpoints, and provider webhooks.
Minimal Data Collection
We collect and process the workspace, connection, reporting, recipient, billing, and operational data needed to provide the applicable service. Explicitly granted Managed and Founding Pilot workspaces also process scoped Attention evidence and brief records. We do not sell customer data. Subprocessors receive only the data needed to operate their part of the service.
Human Approval Control
Review First mode lets you approve each AI-generated report before delivery and is available on every plan as an opt-in setting per client. In explicitly granted ClientSignal Managed and Client Ops Founding Pilot workspaces, a weekly Attention brief is shared only after ClientSignal review and approval.
Data Portability & Deletion
You can export workspace data and request deletion from Settings. Deletion closes access, reconciles supported integrations and billing, and removes stored files and application records. Temporary failures retry.

Control summary

Infrastructure, access, and data rights

These statements describe the product and infrastructure controls in use; they are not a claim that ClientSignal itself holds a separate SOC 2 certification.

Cloud Providers
Independent provider controls
Data Export
Download your data anytime
Account Deletion
Durable erasure and recovery
Your Data Stays Yours
Client data never used for ads or resale