Security & Trust

Introduction

Lease documents can contain sensitive commercial information and personal data. Signio is built to handle uploaded documents with transparent processing, structured access, and clear data handling principles.

1. Our approach

At this stage, Signio focuses on practical trust fundamentals:

  • controlled access to upload documents;
  • clear product and privacy disclosures;
  • transparent use of service providers;
  • responsible handling of uploaded files and extracted lease data;
  • building a stronger foundation for security and compliance over time.
2. What Signio processes

Signio may process:

  • account and workspace information;
  • uploaded lease documents and related files;
  • extracted lease fields, dates, payment structure, and commercial data;
  • technical and usage data needed to operate the service.

Uploaded documents may contain personal data as well as confidential business information. GDPR applies to the processing of personal data, and organizations must protect processed personal data appropriately.

3. Access and permissions

We aim to limit access to uploaded documents and extracted data to:

  • authorized users within the relevant workspace;
  • restricted internal personnel where needed for support, security, or maintenance;
  • service providers acting on our behalf where required to provide the service.
4. Document handling

Uploaded lease files are processed to extract and structure relevant lease information. This may include AI-assisted or automated processing designed to support workflow, review, and organization.

Outputs should be reviewed by the user before they are relied upon for legal, accounting, or commercial decisions.

5. Security fundamentals

Our MVP security approach includes measures such as:

  • encryption in transit;
  • hosted infrastructure with access controls;
  • restricted production access;
  • operational separation between product use and internal administration where practical;
  • ongoing improvement of logging, monitoring, and retention controls.
6. Data retention and deletion

We aim to keep uploaded files and related data only for as long as necessary to provide the service, maintain security, comply with legal obligations, and support legitimate operational needs.

Where deletion features are available, users can remove files or workspaces. Some data may remain in backups or logs for a limited period.

7. Service providers

We rely on third-party providers for infrastructure, authentication, analytics, communications, support, and document/AI processing. We work to choose providers appropriate for the nature of the service and data involved.

A current subprocessor list can be requested at: info@getsignio.com

8. Compliance posture

Signio is an early-stage product. We do not currently claim formal certifications such as ISO 27001 or SOC 2 unless explicitly stated.

Instead, our focus is on:

  • transparent handling of uploaded lease data;
  • privacy-conscious design;
  • clear legal documents;
  • strong practical controls for the stage we are in.
9. Privacy

For more information about how we process personal data and your rights, see our Privacy Policy.

10. Contact

For security or privacy questions, contact:

info@getsignio.com

Start with the lease you already have

Upload a lease, extract what matters, and start building more control from draft to signed.