Built to be handed to your security team.
How the Behaviour Code handles and protects data, written for the people who have to sign off on it. If you need anything beyond this, email security@signallabs.ca.
LAST UPDATED SEPTEMBER 2026 · SIGNAL LABS INC.
Anonymous by design
The research record of every sitting is stored without personal identifiers: its answers and result carry no name or email. Contact details are collected only if someone chooses to give them, to receive their read, join the Program or join research; then the email is kept with that person’s own read, so we can send it and they can come back to it, and never with the research record. Data minimisation is the default, not an afterthought.
Encryption
All traffic is served over HTTPS/TLS. Data at rest lives in managed PostgreSQL (Supabase), encrypted at rest by the provider. We never see or store card details: payments are taken by Stripe, and we keep only the record that a payment was made.
Access control
The database runs with row-level security enabled and no public policies, so the public/anonymous key can read nothing directly. All reads and writes go through our server-side API using a service-role key that is never exposed to the browser. The practitioner console sits behind authentication. Access follows least-privilege.
Where data lives (subprocessors)
We run on a small set of established providers, each maintaining their own security programs and certifications:
- Vercel: application hosting.
- Supabase: managed PostgreSQL database and storage.
- Anthropic: the language model behind the reads we compose, the Agent and the conversation (not used to train their models).
- Stripe: payments.
- Meta (Instagram): only if you connect your Instagram business account to the Agent, to read your posts and their numbers (it never posts for you); revocable at any time.
- Resend: transactional email (your read).
- ConvertKit (Kit): opt-in email communications.
Primary data residency: the United States. We can share each provider’s current compliance documentation on request.
The “Lived” read: your public record
The Lived read is built from your public record only: what a search finds from the name, role and company you give us (your site, your profiles, what you have published), plus any text of your own that you choose to paste. It never connects to your email, documents or accounts, and it asks for no passwords or permissions.
Data lifecycle
Anonymized research data is retained in aggregate. Identifiable data is retained until the person unsubscribes or requests deletion, then removed within 30 days. Deletion and access requests are handled per our Privacy Policy.
What we never do
We do not sell, rent or trade data. We do not use it for third-party advertising. We do not feed identifiable client data into third-party model training.
Honest posture
We are an early-stage research company and are candid about it: the controls above are real and in place today, but we do not yet hold formal certifications such as SOC 2. We are happy to complete a security questionnaire, sign an NDA or DPA and discuss your specific requirements. For enterprise reviews, contact security@signallabs.ca.
Signal Labs · The Personal Brand, Measured · File closed
◆ The thinking, in your inbox
One idea a week on reading people, and being read. No noise.