Security & Trust

Built to be trusted with your brand's data

Signal360 runs on enterprise Google Cloud infrastructure in the EU, with encryption, role-based access, and transparent data handling. Here's exactly how we protect your data.

Infrastructure

Runs entirely on Google Cloud Platform in London (europe-west2). The database sits on a private VPC with no authorised public networks; all connections require SSL and are authenticated through the IAM-gated Cloud SQL Auth Proxy.

Encryption

Encrypted in transit with TLS and at rest with AES-256 via Google Cloud. Database connections require SSL.

Access & authentication

Authentication via Google Cloud Identity Platform. Role-based access (owner, admin, analyst, viewer, and client roles) with client-scoped access controls.

Data residency

Application and customer data are stored in the United Kingdom (Google Cloud europe-west2, London). For EEA customers this is a transfer to the UK under the European Commission's UK adequacy decision. Analytics warehouse data may be processed in other regions - see our sub-processor list.

Resilience

High-availability (regional) database with automated backups retained 14 days and point-in-time recovery.

Tenant isolation

Every brand and client workspace is scoped at the query layer, with client-scoped access controls so each organization's data stays within its own workspace.

Certifications & compliance

We believe in being precise about this. Signal360 does not yet hold its own independent security certification. We run entirely on Google Cloud Platform, which maintains SOC 2 Type II, ISO 27001, and ISO 27017/27018 certifications. A formal SOC 2 attestation for Signal360 is on our roadmap.

  • Underlying cloud infrastructure: SOC 2 Type II & ISO 27001 certified (Google Cloud)
  • Data processing aligned with UK & EU GDPR
  • UK data residency (Google Cloud europe-west2, London)
  • DPA available on request

Privacy & data protection

  • Signal360 is operated by Informabiz Group and processes data in line with UK and EU GDPR.
  • A Data Processing Agreement (DPA) is available on request for customers who need one.
  • We practice data minimization - we collect what's needed to measure AI visibility, not more.
  • Analysis prompts sent to AI model providers contain brand, competitor, and query data - not your customers' personal data.

Sub-processors

The third-party services we rely on to deliver Signal360, and the countries they operate in. We keep this list current; the authoritative version forms part of our DPA, and we will notify customers before adding a new sub-processor.

ProviderPurposeRegionUsed to train their models
Google Cloud PlatformCloud hosting, database, authentication, and analytics exportUnited KingdomN/A
ResendTransactional and notification emailEU / USN/A
OpenAIAI model provider - measuring brand representation in ChatGPTUSExcluded under API terms
AnthropicAI model provider - measuring brand representation in ClaudeUSExcluded under API terms
Google (Gemini)AI model provider - measuring brand representation in GeminiUS / EUExcluded under API terms
PerplexityAI model provider - measuring brand representation in PerplexityUSExcluded under API terms
DeepSeekAI model provider - measuring brand representationChinaNot guaranteed
Together AIAI model inference for the Llama engine - measuring brand representationUSExcluded under API terms
MistralAI model provider - measuring brand representationEUExcluded under API terms
xAI (Grok)AI model provider - measuring brand representationUSNot guaranteed
CloudflareBot protection on our public forms (Turnstile)GlobalN/A
Cookiebot (Usercentrics)Cookie consent managementEUN/A
Google Analytics & Tag ManagerWebsite analytics and tag management on signal360.aiEU / USN/A

“Excluded” means the provider's API or enterprise terms commit to not using your data to train their models, and we monitor those terms for changes. Where exclusion is not contractually guaranteed - currently DeepSeek and xAI (Grok) - we flag it. You can disable any engine in your workspace, so if a provider's terms don't meet your compliance bar, your data is never sent to it.

Security questions or disclosures?

Running enterprise security review, need a DPA, or reporting a vulnerability? Reach our team and we'll get back to you quickly.