How PartnerSignals protects your data.
PartnerSignals processes pipeline data, revenue signals, and deal intelligence for its customers. This page documents how we protect your data — our security controls, compliance posture, and available documentation — so your security team has answers before they ask.
Where we stand
We publish our current posture honestly — In Progress means actively underway, not aspirational. We do not claim certifications we don't hold.
SOC 2 Type II
AICPA Trust Services Criteria
Audit preparation underway; target Q1 2027. Controls inventory, evidence collection, and access-control documentation are all active tracks.
GDPR
EU General Data Protection Regulation
Data Processing Agreement available on request. We process EU personal data only as necessary for service delivery, with documented lawful basis.
CCPA
California Consumer Privacy Act
California residents can request access, deletion, or portability of their personal data. Covered fully by our privacy policy.
ISO 27001
Information Security Management
Scheduled to follow SOC 2 Type II. Many ISO 27001 controls map directly to our SOC 2 control set, reducing the incremental lift.
PCI DSS
Payment Card Industry Data Security
PartnerSignals does not store, process, or transmit cardholder data. All payments are handled by Stripe, a PCI DSS Level 1 certified provider.
HIPAA
Health Insurance Portability and Accountability Act
PartnerSignals does not process Protected Health Information. HIPAA does not apply to our platform or data types.
How we protect your data
Every layer is chosen with multi-tenant isolation and defense in depth in mind. No shared storage, no shared keys, no cross-tenant queries.
Hosting & Infrastructure
- Red Hat OpenShift on AWS (ROSA HCP) — us-east-1
- Three-layer shared responsibility: AWS owns physical infra, Red Hat SRE patches and monitors the Kubernetes control plane 24/7, PartnerSignals owns the application layer
- Zero Trust Workload Identity eliminates long-lived credentials between services; isolated Kubernetes namespaces per workload
- WAF (Cloudflare Managed Ruleset + OWASP Core), Super Bot Fight Mode, DDoS protection, HSTS, SSL/TLS Full (Strict) at the edge — hardened July 2026
Encryption
- All data in transit: TLS 1.2+ enforced (sslmode=verify-full)
- Encryption at rest: pgcrypto with per-tenant key isolation via CloudNativePG
- Secrets via Doppler — zero plaintext secrets in codebase or CI logs
- Production credentials in 1Password team vault, not personal
Tenant Isolation
- Row-Level Security (RLS) enforced at the PostgreSQL layer on every table
- No query executes without a valid tenant_id context
- No shared storage, no shared keys, no cross-tenant queries
Managed Control Plane
- ROSA HCP: control plane runs in a Red Hat-owned AWS account
- 24/7 patching, monitoring, and incident response by Red Hat SRE
- PartnerSignals owns the application layer; Red Hat owns the Kubernetes substrate
No Frontier-Model Training Exposure
The pipeline data, revenue signals, and deal intelligence you run through PartnerSignals are used to operate the product for you — and for nothing else. Your data is never used to train frontier AI models, ours or any provider's, and is never pooled into a shared training corpus. When we use AI to process your data, it runs under contractual terms that prohibit provider-side training on your inputs.
Is our data used to train AI models?
No — not by PartnerSignals and not by any model provider we use.
Is our data pooled with other customers'?
No. Processing is tenant-isolated.
Can we get this in writing?
Yes — it is a contractual term, available on request.
Security questions or need documentation?
Our team responds to security reviewers directly.