Security posture

Security and Data Handling

SignalWise AI is built around a cautious upload-based audit workflow for pilot customers. Reports are advisory, evidence-led and designed for technical review before operational decisions are made.

Current workflow

No live network credentials required.

The current platform works from uploaded site evidence and structured context. Future integrations will be designed read-only first and least-privilege by default.

Upload-first workflow

The current audit workflow works from evidence users choose to upload. It does not require live network access or vendor credentials.

Scoped access

Customer audit access is scoped to the owning account. Administrator and support roles separate account amendments from routine support actions.

Account activity ledger

Registration, recovery, support notes and account amendments create restricted, append-only operator records without storing password or token values.

Recovery controls

Password recovery uses hashed, one-time, expiring tokens. Hosted links are sent to the account owner rather than exposed to support operators.

File handling

Uploads are restricted by type and size. TXT and CSV can be parsed; PDFs and images are treated as supporting context unless deeper extraction is added later.

Secrets management

Service keys, email credentials and payment secrets are handled through environment variables and are not exposed in frontend code.

What data users may upload

Account and contact details

Site information and business impact notes

Network evidence such as floorplans, exports, screenshots and TXT/CSV notes

Audit reports and generated recommendations

Operational metadata needed to deliver the service

What SignalWise AI does not require

Live access to routers, switches, firewalls or wireless controllers

Production admin credentials for vendor platforms

Permission to make network configuration changes

Unauthorised customer or third-party data

Roadmap controls

Enterprise controls planned as the pilot matures.

SignalWise AI is GDPR-aware in posture and will strengthen deletion, retention, tenant scoping and federation as customer requirements become clearer. No security certifications are claimed at this stage.

SSO/SAML
Tenant-scoped role templates
Customer-controlled deletion
Vendor API permission scoping
Encryption documentation
DPA readiness
Configurable retention policies