Security

Last updated: July 3, 2026

Signals is committed to protecting customer messaging data with enterprise-grade security practices. Our infrastructure, built on Google Cloud Platform, implements defense-in-depth principles to safeguard information at every layer.

1. Infrastructure Security

Our platform is built on industry-leading security infrastructure with multiple layers of protection:

1.1 Encryption

  • Data in Transit: TLS 1.3 encryption for all connections
  • Data at Rest: AES-256 encryption for all stored data
  • HTTPS Only: Automatic redirect from HTTP to HTTPS
  • Managed SSL Certificates: Automatically renewed and maintained

1.2 Private Cloud Infrastructure

  • Google Cloud Platform: Enterprise-grade infrastructure with SOC 2 Type II compliance
  • Virtual Private Cloud (VPC): Isolated network environment with strict access controls
  • No Public Access: Backend systems are not exposed to the public internet
  • Dedicated Infrastructure: Resources allocated specifically for our services

1.3 Access Control

  • Multi-Factor Authentication: Required for all administrative access
  • Role-Based Access Control (RBAC): Least privilege principle for all team members
  • Audit Logging: Comprehensive logging of all system access and changes
  • Regular Access Reviews: Quarterly reviews of access permissions

1.4 Network Security

  • DDoS Protection: Google Cloud Armor for distributed denial of service mitigation
  • Web Application Firewall: Protection against OWASP Top 10 vulnerabilities
  • Rate Limiting: API rate limiting to prevent abuse
  • IP Allowlisting: Available for enterprise customers

2. Customer Data and Messaging Security

Signals processes sensitive customer data through iMessage, RCS, SMS, 10DLC SMS, WhatsApp, and connected commerce and support systems. We implement strict controls to protect this information:

2.1 Messaging Security

  • Encryption: Message data is encrypted in transit and at rest
  • Provider Controls: Messaging providers are selected and configured for production-grade delivery, webhook validation, and access controls
  • Route Evidence: Message route metadata records the channel and provider evidence used for operational and compliance decisions
  • PII Protection: Customer phone numbers and personal data encrypted with AES-256

2.2 Media Upload and Storage Security

  • Secure Upload: TLS 1.3 encryption for media uploads
  • Content Validation: Automated scanning to prevent malicious file uploads
  • Encrypted Storage: Media encrypted at rest
  • Access Controls: Attachments accessible only to authorized systems and personnel
  • Automatic Deletion: Media deleted according to configurable or operational retention policies

2.3 Brand Data Isolation

  • Multi-Tenant Architecture: Complete data isolation between brands
  • Role-Based Access: Strict access controls ensure brands only see their own data
  • API Security: OAuth 2.0 and API key authentication with rate limiting
  • Data Residency: Options for geographic data storage requirements

2.4 Compliance Records

  • Consent Evidence: Marketing consent, suppression, and opt-out evidence are stored for auditability
  • Suppression Controls: STOP-style and ordinary-language opt-outs block future outreach
  • Marketing Gate Logs: Blocked marketing sends and skip reasons are logged for operational review
  • Channel Evidence: Provider service evidence supports channel-specific compliance decisions

3. Data Retention & Privacy

We implement data minimization principles and retain data only as long as necessary:

  • Messaging Conversations: Retained according to business customer settings, operational needs, and legal requirements
  • Media Attachments: Deleted based on configurable or operational retention policies
  • Analytics Data: Aggregated analytics retained to provide trend insights to brands
  • Contact and Consent Information: Retained as needed to provide the Service, honor opt-outs, and maintain compliance records
  • Security Logs: Retained as required for security monitoring and compliance

3.1 Data Deletion Requests

You can request deletion of your personal data at any time by contacting security@returnsignals.com. We will:

  • Acknowledge your request within 48 hours
  • Complete deletion within 30 days
  • Provide confirmation once deletion is complete
  • Retain only data required by law or legitimate business purposes (e.g., financial records)

3.2 Automated Backups

  • Daily automated backups with 14-day retention
  • All backups encrypted with AES-256
  • Backups stored in separate geographic regions for disaster recovery
  • Regular backup restoration testing

4. Compliance & Standards

We adhere to industry-standard security frameworks and compliance requirements:

4.1 SOC 2 Type II Compliance

Signals, as part of Material Model, is working toward SOC 2 Type II certification. This includes:

  • Security controls for protecting customer data
  • Availability and performance monitoring
  • Processing integrity verification
  • Confidentiality protection measures

4.2 Security Best Practices

  • Regular Security Audits: Quarterly internal security assessments
  • Vulnerability Scanning: Automated scanning for known vulnerabilities
  • Penetration Testing: Annual third-party penetration tests
  • Dependency Updates: Regular updates of all software dependencies

4.3 Incident Response

  • 24/7 Monitoring: Automated alerts for security incidents
  • Response Team: Dedicated security team with on-call rotation
  • Notification Procedures: Affected users notified within 72 hours of confirmed breach
  • Post-Incident Reviews: Comprehensive analysis and remediation after incidents

5. Security FAQ

5.1 What customer data do you collect?

Signals collects only the data needed to provide customer messaging and analytics services:

  • Customer Contact Information: Phone numbers, emails, and messaging handles used for supported channels
  • Conversation Content: Messages between customers, Signals, AI agents, and human operators
  • Media: Customer-uploaded images or files used for support, returns, exchanges, and product questions
  • Order Information: Product details, order IDs (provided by brand, not collected directly)
  • Compliance Metadata: Consent evidence, suppression state, message route evidence, and opt-out records
  • Engagement Metadata: Timestamps, resolution outcomes, sentiment data, and workflow outcomes

For detailed information, see our Privacy Policy and Messaging Compliance pages.

5.2 How do you secure customer messages?

Customer messages are protected through multiple security layers:

  • Encryption in Transit: TLS 1.3 for API connections to messaging providers
  • Encryption at Rest: AES-256 encryption for stored message content
  • Access Controls: Only authorized AI agents and brand administrators can access conversations
  • Audit Logs: All message access logged and monitored for unauthorized activity

5.3 How long do you retain media attachments?

Media attachments are handled with strict retention policies to protect customer privacy:

  • Configurable Retention: Brands set their own retention policies based on their needs
  • Automatic Deletion: Attachments deleted after the configured retention period where available
  • On-Demand Deletion: Customers can request deletion through the applicable brand or by contacting Signals
  • Encrypted Storage: Attachments encrypted at rest

5.4 How do you protect against common web attacks?

We implement multiple layers of protection:

  • XSS Protection: Content Security Policy (CSP) headers and input sanitization
  • CSRF Protection: Anti-CSRF tokens for form submissions
  • SQL Injection: Not applicable (static site with no database)
  • DDoS Mitigation: Google Cloud Armor and rate limiting
  • Clickjacking: X-Frame-Options and CSP frame-ancestors headers

5.5 What should I do if I find a security vulnerability?

We appreciate responsible disclosure of security vulnerabilities. Please report issues to security@returnsignals.com with:

  • Detailed description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact assessment
  • Your contact information for follow-up (we respect reporter anonymity if requested)

We commit to acknowledging your report within 48 hours and providing status updates throughout the resolution process.

5.6 How will I be notified of security incidents?

In the event of a security incident that affects your data, we will:

  • Notify affected users within 72 hours of confirming the breach
  • Send notifications via email to registered contact addresses
  • Post a security advisory on our website
  • Provide details about the incident, its impact, and remediation steps

6. Reporting Security Issues

We take security issues seriously and appreciate the security research community’s efforts in keeping our users safe.

6.1 Responsible Disclosure

When reporting vulnerabilities, please:

  • Email security@returnsignals.com with details
  • Allow us reasonable time to address the issue before public disclosure
  • Avoid accessing, modifying, or deleting data beyond what’s necessary to demonstrate the vulnerability
  • Do not perform actions that could harm our users or services

6.2 Our Commitment

  • Response Time: Acknowledgment within 48 hours
  • Status Updates: Regular updates on investigation and remediation
  • Recognition: Credit for responsible disclosure (with your permission)
  • Safe Harbor: No legal action for good-faith security research

7. Additional Resources

For more information about our data practices and policies:

8. Contact Information

For security-related questions, vulnerability reports, or security incident notifications, please contact:

Material Model, Inc. (d/b/a Signals)

2261 Market Street STE 85311, San Francisco, CA 94114

Security Email: security@returnsignals.com

Website: www.returnsignals.com

Response Time: Security inquiries are acknowledged within 48 hours

For general inquiries, you may also contact us at hello@returnsignals.com.