Security and trust

Controls that protect the workflow without hiding uncertainty.

ArraySignal applies practical application-security and data-integrity controls appropriate to the current product stage. This page describes implemented controls and does not claim third-party certification.

01

Tenant isolation

Organization and site authorization is enforced for tenant-controlled backend resources.

02

Protected public forms

Server-side validation, bounded request bodies, duplicate suppression, rate controls, and Turnstile verification protect public submissions.

03

Secret boundaries

Server credentials remain outside browser bundles and production configuration fails safely when required secrets are incomplete.

04

Operational logging

Structured server events use correlation IDs while excluding passwords, tokens, API keys, and form message contents.

05

Transport and browser policy

HTTPS deployment, HSTS, content-type protection, clickjacking defenses, a permissions policy, and Content Security Policy reduce browser attack surface.

06

Data-quality integrity

Invalid telemetry is retained as an explicit quality condition instead of being silently converted into production or loss values.

Responsible disclosure

Report a potential security issue privately.

Use the published security contact and avoid including production credentials, personal data, or customer telemetry in an initial report.

Explore your portfolio

Bring a real operating question to the conversation.

We’ll discuss telemetry coverage, portfolio priorities, and a practical evaluation scope—without presenting sample estimates as guaranteed outcomes.

Book a portfolio review