Last updated July 21, 2026
SigComply is a non-custodial compliance engine. Your raw evidence (API responses, documents, PDF bytes) and resource identifiers (ARNs, email addresses, usernames, account IDs) never leave your own environment. The SigComply CLI runs inside your CI/CD, aggregates results into counts locally, and only those counts reach us. We store aggregated compliance results — never raw evidence, never PII.
Raw evidence, files or PDF bytes, cryptographic signatures, and resource-level identifiers such as ARNs, usernames, email addresses, IP addresses, or account IDs. Our submission endpoint is structurally counts-only and rejects or redacts anything that looks like an identifier. Plain language: we store "3 users have MFA disabled", never "alice, bob, and carol have MFA disabled".
To operate the Compliance Dashboard and Auditor Portal, generate reports you request, alert you when data goes stale, and manage your subscription. We do not sell your data or use it for advertising.
We rely on a small set of infrastructure providers to run the service, including our hosting platform (Render), payment processor (Stripe), and email delivery (Postmark). Each processes only the limited data needed for its function.
We retain aggregated compliance data for as long as your account is active so you can track drift over time. You can request access to, correction of, or deletion of your account data at any time by contacting us. Deleting your organization removes its associated compliance data from our systems.
Questions about privacy? Email privacy@sigcomply.com.
This is a beta-stage policy for an early-access product and may be updated as SigComply matures. Material changes will be reflected by the "last updated" date above.