Privacy Policy

Last updated July 21, 2026

The short version

SigComply is a non-custodial compliance engine. Your raw evidence (API responses, documents, PDF bytes) and resource identifiers (ARNs, email addresses, usernames, account IDs) never leave your own environment. The SigComply CLI runs inside your CI/CD, aggregates results into counts locally, and only those counts reach us. We store aggregated compliance results — never raw evidence, never PII.

What we collect

  • Account information — your email address, organization name, and password (stored hashed) so you can sign in.
  • Aggregated compliance data submitted by the CLI: policy identifiers, pass/fail/skip results, severity, category, and resource counts (for example, "3 of 10 resources failed"). We regenerate result messages from counts and scrub any free-text server-side.
  • Run metadata: framework, CLI version, branch, commit SHA, and CI provider.
  • Billing information: subscription state and a Stripe customer reference. Card details are handled by Stripe — we never see or store them.

What we never collect

Raw evidence, files or PDF bytes, cryptographic signatures, and resource-level identifiers such as ARNs, usernames, email addresses, IP addresses, or account IDs. Our submission endpoint is structurally counts-only and rejects or redacts anything that looks like an identifier. Plain language: we store "3 users have MFA disabled", never "alice, bob, and carol have MFA disabled".

How we use it

To operate the Compliance Dashboard and Auditor Portal, generate reports you request, alert you when data goes stale, and manage your subscription. We do not sell your data or use it for advertising.

Sub-processors

We rely on a small set of infrastructure providers to run the service, including our hosting platform (Render), payment processor (Stripe), and email delivery (Postmark). Each processes only the limited data needed for its function.

Data retention & your rights

We retain aggregated compliance data for as long as your account is active so you can track drift over time. You can request access to, correction of, or deletion of your account data at any time by contacting us. Deleting your organization removes its associated compliance data from our systems.

Contact

Questions about privacy? Email privacy@sigcomply.com.

This is a beta-stage policy for an early-access product and may be updated as SigComply matures. Material changes will be reflected by the "last updated" date above.