NINJA SIGNAL

Trust

What Signal does with your data, where it runs, and who to call if something goes wrong. If your procurement team needs a longer document, email [email protected].

Region

Signal runs on Hetzner in Finland (eu-north). Backups replicate to Hetzner Nuremberg (eu-central). No US processor for any customer-owned data. UK/EU data never leaves the EEA.

Data handling

Threat intelligence in the shared graph is derived from public feeds (NVD, CISA KEV, OTX, MalwareBazaar, CIRCL, MITRE ATT&CK, and others). Customer-submitted IOCs (e.g. Threat Check inputs) are processed to answer the query and then dropped from application memory. Rate-limit and abuse-detection logs are retained for 30 days.

Key custody

TLS via Caddy's automatic ACME issuance. JWT signing key rotated quarterly, held only in server-side environment variables. Neo4j credentials scoped per tenant on enterprise deployments. No customer secrets stored in git.

Retention

DEFCON subscriber records: consent timestamp + IP retained for as long as the subscription is active plus 12 months post-unsubscribe (compliance evidence). Application logs: 30 days rolling. Neo4j backups: 30 days daily, 12 weekly.

Incident contact

Reachable at [email protected] for any suspected data or security incident affecting your usage of Signal. Response target: 24 hours acknowledgement, 72 hours substantive update.

Continuity

Single-founder company. Enterprise contracts include a source-code escrow clause and a documented handover runbook. Product surface has a hot-standby container on a separate Hetzner region; graph is restorable from the most recent backup within 4 hours.

Sub-processors

Hetzner (hosting). Anthropic (LLM prose generation for DEFCON only — no customer IOCs sent). listmonk self-hosted (no third-party email SaaS). Cloudflare DNS. No analytics beacons.

Compliance

UK GDPR + EU GDPR: data-subject requests processed within 30 days. Double opt-in on all mailing lists, unsubscribe honoured in one click. No dark patterns. security.txt at /.well-known/security.txt.

Last reviewed 2026-08-10. Changes to this page are versioned in git — see the history.