Security · Updated July 20, 2026
What happens to the file you upload
The front door of this product asks you to hand a list of your customers to a company you have never met. This page answers the questions that deserves: what the audit receives, what it does with it, where it runs, who can see it, how to delete it, and what protections do not exist yet.
What the audit receives
One CSV that you choose and export yourself — typically leads, customers, quotes, or estimates from a CRM or a spreadsheet. In practice that file contains names, email addresses, phone numbers, estimate or job amounts, dates, and status fields.
Nothing is pulled automatically. There are no CRM integrations built, so the audit cannot reach into your system and take more than you gave it. It sees exactly the columns present in the file you upload, and you can strip columns before uploading if you would rather not send them.
What happens to it
The file is parsed and normalized: recognizable name, contact, amount, date, and status fields are mapped, duplicate contacts are merged, and unusable rows are counted and set aside. Estimate rows are classified as unsold, won, lost, or unknown. Those results are totaled and ranked into the report you receive.
The uploaded records and the cleaned data derived from them are retained so your report link keeps working. They are not sold, not shared with other customers, not enriched against outside data brokers, and not used as a marketing list by us. The audit exists to describe your backlog back to you.
Where it is processed
The application is hosted on Vercel and the normalized records and generated reports live in a managed PostgreSQL database. Traffic to the site is served over HTTPS, so the file is encrypted in transit on its way to us.
The subprocessor list is short because the product is small: cloud hosting, the managed database, and the AI provider used to classify ambiguous rows. There is no email-delivery vendor and no product-analytics vendor in the stack today, because neither sending nor analytics has been built. If that changes, this list changes with it.
Who can access it
The team operating the service, limited to what operating and debugging it requires. Because there are no accounts yet, there is also no customer-facing permission model to describe: access control today is internal, and the report link is the only external access path.
Anyone holding a report link can open that report. Report URLs contain an unguessable identifier and carry directives excluding them from search-engine indexing, so they are not discoverable by crawling or guessing. They are still shareable by design, which is useful and worth understanding before you forward one.
AI processing, stated precisely
Deterministic rules run first and handle most rows. Only rows whose status cannot be resolved by those rules are sent to an AI provider for classification, and rows that remain ambiguous stay unknown rather than being guessed into your totals.
We do not train models on your uploaded records, and we do not use one customer's data to benefit another. The provider processes that data under commercial terms restricting its use to returning our result. What we cannot honestly promise is a guarantee covering every practice of a third-party vendor forever — so we describe our own configuration and contractual position rather than issuing a blanket assurance we would not fully control.
How to get your data deleted
Email hello@signalback.ai with the report link, or the email address you used, and say you want it deleted. We remove the uploaded file, the normalized records derived from it, and the report — which means the link stops resolving. Your customers' records are covered by the same request; you do not have to file a separate one for them.
There is no self-serve delete button, because there is no account system to hang one on. Building customer-controlled retention and deletion is part of the account work, not a feature we are claiming today.
What does not exist yet
- No SOC 2, ISO 27001, or equivalent certification — none completed, none in audit
- No formal DPA countersigning process, and no published subprocessor change-notification commitment
- No accounts, authentication, roles, or audit logging you can inspect
- No sending infrastructure, so no messages have been sent to any contact on any uploaded list
- No CRM integrations, so nothing is written back into your system of record
The intent is to add formal data-processing terms and a customer-facing access and retention model alongside accounts and campaign sending. We are not attaching dates to that, because a security roadmap with invented deadlines is worth less than an accurate list of what is missing.
Reporting a problem
If you find a vulnerability, a data-handling mistake, or anything on this page that does not match what the product actually does, email hello@signalback.ai. We would rather correct this page than defend it.
Security FAQ
Do I have to create an account to upload a file?+
No. There are no accounts and no authentication in SignalBack today. You upload a CSV and receive a private report link. That also means the link itself is the only key to the report, so treat it like a password.
Can anyone find my report by searching?+
No. Report URLs contain an unguessable identifier, are not listed anywhere on the site, and are excluded from search-engine indexing. They are shareable by link, which is deliberate — you can send a report to a partner or bookkeeper — but anyone holding the link can open it.
Is my customer data used to train AI models?+
Not by us. We do not train models on uploaded records, and we do not use one customer's data to improve another customer's results. Rows that deterministic rules cannot classify are sent to an AI provider under commercial terms that restrict use of the data to returning our result. We can only speak for our own configuration and contracts, not for every downstream practice of a third party, so we state it that way rather than making a blanket guarantee.
Do you have SOC 2, ISO 27001, or a signed DPA?+
No. There is no completed SOC 2, ISO 27001, or equivalent certification, and no formal DPA countersigning process yet. Claiming otherwise would be the easiest and worst lie an early product could tell. If your procurement process requires any of these, we are not ready for you yet, and we would rather say so now than during a security review.
How do I get my data deleted?+
Email hello@signalback.ai with the report link or the email address you used, and ask for deletion. We delete the uploaded file and the records derived from it, including your customers' records, and the report link stops working. No account, no retention offer, no exit interview.
Read the sample report before you upload anything.
The sample uses fixed demo data and needs no file and no email address, so you can see exactly what the audit produces before deciding whether to send us your list.