Security & Compliance

Enterprise-grade security,law firm standards.

Our architecture documentation, Data Processing Agreement, and Information Security Policy are available on request.

US-Only Data Residency

All client data is processed and stored exclusively on AWS infrastructure in US-East-1 and US-West-2. No data ever transits non-US servers. Contractually guaranteed in your DPA.

AWS US-Only

Row-Level Tenant Isolation

PostgreSQL Row-Level Security ensures complete isolation. No firm's data is ever accessible by another firm's users, enforced at the database level, not just the application layer.

Zero Cross-Contamination

Immutable Audit Logging

Every data access event is written to an immutable PostgreSQL trigger table. Full audit trail available on request, who accessed what, when, and from where.

Tamper-Proof Logs

SOC 2 Type II Infrastructure

Infrastructure SOC 2 Type II compliance inherited through Supabase, AWS, and Netlify. ClientSignal's own application-level SOC 2 Type II audit is in progress.

SOC 2 Compliant

AI: Zero Data Retention

ClientSignal™ uses AI analysis on a per-request basis. No client data is retained by the AI model or accessible outside your tenant. Contractually guaranteed.

Zero AI Retention

Enterprise Authentication

PKCE OAuth, JWT claims, and four-tier role-based access control. MFA enforcement and SSO/SAML integration are on the H2 2026 roadmap. Breach notification SLAs negotiable by firm.

Enterprise Auth
Security Documentation Available on Request
Information Security Policy
v1.2 · April 2026
Data Processing Agreement
GDPR & CCPA compliant
Security Architecture Overview
Technical reference doc
SOC 2 Infrastructure Reports
Supabase · AWS · Netlify
Limited Founding Client Spots Available

Ready to know what your
clients actually think?

Founding clients receive locked pricing through 2027, priority onboarding, and direct access to the ClientSignal™ product team.