Security & trust
Your account evidence and reports stay under your control.
A clear account of the safeguards ClientSignal uses today—from encrypted credentials and tenant isolation to human approval, export, and deletion controls.
- AES-256-GCM Encryption
- Supported OAuth tokens and sensitive integration credentials are encrypted at rest with AES-256-GCM. Encryption keys are stored separately from application data.
- Row-Level Security (RLS)
- Tenant-scoped queries, foreign keys, and database row-level policies restrict authenticated access to the current agency. Privileged service paths are separately authorized and tested.
- Protected Integration Credentials
- Supported integrations use provider-authorized connections or scoped credentials; ClientSignal does not request connected-platform passwords. Klaviyo uses a user-supplied private API key. Stored credentials are encrypted at rest and can be revoked at the provider.
- Third-Party Infrastructure Controls
- ClientSignal runs on Vercel and Supabase. Their current compliance documentation describes their independent controls and certifications; ClientSignal does not currently claim its own SOC 2 certification.
- Transparent AI Data Handling
- ClientSignal sends the inputs needed for report generation and, for explicitly granted Managed or Founding Pilot workspaces, Attention-brief assistance to its configured AI provider. ClientSignal does not use customer data to train its own models. Provider processing and retention are governed by the applicable commercial API terms; ask us for the current data-flow details.
- HTTPS Everywhere
- ClientSignal serves application traffic over HTTPS, including its public app, API endpoints, and provider webhooks.
- Minimal Data Collection
- We collect and process the workspace, connection, reporting, recipient, billing, and operational data needed to provide the applicable service. Explicitly granted Managed and Founding Pilot workspaces also process scoped Attention evidence and brief records. We do not sell customer data. Subprocessors receive only the data needed to operate their part of the service.
- Human Approval Control
- Review First mode lets you approve each AI-generated report before delivery and is available on every plan as an opt-in setting per client. In explicitly granted ClientSignal Managed and Client Ops Founding Pilot workspaces, a weekly Attention brief is shared only after ClientSignal review and approval.
- Data Portability & Deletion
- You can export workspace data and request deletion from Settings. Deletion closes access, reconciles supported integrations and billing, and removes stored files and application records. Temporary failures retry.
Control summary
Infrastructure, access, and data rights
These statements describe the product and infrastructure controls in use; they are not a claim that ClientSignal itself holds a separate SOC 2 certification.
- Cloud Providers
- Independent provider controls
- Data Export
- Download your data anytime
- Account Deletion
- Durable erasure and recovery
- Your Data Stays Yours
- Client data never used for ads or resale