Security & Trust
Lease documents can contain sensitive commercial information and personal data. Signio is built to handle uploaded documents with transparent processing, structured access, and clear data handling principles.
At this stage, Signio focuses on practical trust fundamentals:
- controlled access to upload documents;
- clear product and privacy disclosures;
- transparent use of service providers;
- responsible handling of uploaded files and extracted lease data;
- building a stronger foundation for security and compliance over time.
Signio may process:
- account and workspace information;
- uploaded lease documents and related files;
- extracted lease fields, dates, payment structure, and commercial data;
- technical and usage data needed to operate the service.
Uploaded documents may contain personal data as well as confidential business information. GDPR applies to the processing of personal data, and organizations must protect processed personal data appropriately.
We aim to limit access to uploaded documents and extracted data to:
- authorized users within the relevant workspace;
- restricted internal personnel where needed for support, security, or maintenance;
- service providers acting on our behalf where required to provide the service.
Uploaded lease files are processed to extract and structure relevant lease information. This may include AI-assisted or automated processing designed to support workflow, review, and organization.
Outputs should be reviewed by the user before they are relied upon for legal, accounting, or commercial decisions.
Our MVP security approach includes measures such as:
- encryption in transit;
- hosted infrastructure with access controls;
- restricted production access;
- operational separation between product use and internal administration where practical;
- ongoing improvement of logging, monitoring, and retention controls.
We aim to keep uploaded files and related data only for as long as necessary to provide the service, maintain security, comply with legal obligations, and support legitimate operational needs.
Where deletion features are available, users can remove files or workspaces. Some data may remain in backups or logs for a limited period.
We rely on third-party providers for infrastructure, authentication, analytics, communications, support, and document/AI processing. We work to choose providers appropriate for the nature of the service and data involved.
A current subprocessor list can be requested at: info@getsignio.com
Signio is an early-stage product. We do not currently claim formal certifications such as ISO 27001 or SOC 2 unless explicitly stated.
Instead, our focus is on:
- transparent handling of uploaded lease data;
- privacy-conscious design;
- clear legal documents;
- strong practical controls for the stage we are in.
For more information about how we process personal data and your rights, see our Privacy Policy.
For security or privacy questions, contact:
info@getsignio.com
