Tenant isolation
Organization and site authorization is enforced for tenant-controlled backend resources.
Security and trust
ArraySignal applies practical application-security and data-integrity controls appropriate to the current product stage. This page describes implemented controls and does not claim third-party certification.
Organization and site authorization is enforced for tenant-controlled backend resources.
Server-side validation, bounded request bodies, duplicate suppression, rate controls, and Turnstile verification protect public submissions.
Server credentials remain outside browser bundles and production configuration fails safely when required secrets are incomplete.
Structured server events use correlation IDs while excluding passwords, tokens, API keys, and form message contents.
HTTPS deployment, HSTS, content-type protection, clickjacking defenses, a permissions policy, and Content Security Policy reduce browser attack surface.
Invalid telemetry is retained as an explicit quality condition instead of being silently converted into production or loss values.
Responsible disclosure
Use the published security contact and avoid including production credentials, personal data, or customer telemetry in an initial report.
Explore your portfolio
We’ll discuss telemetry coverage, portfolio priorities, and a practical evaluation scope—without presenting sample estimates as guaranteed outcomes.