SIGBOT
Legal & Trust

Security Overview

Last updated: 19 July 2026

How Sigbot protects the data that moves through connected inboxes — from authentication and encryption to how we respond when something goes wrong.

1. Infrastructure

Sigbot is built on established cloud infrastructure rather than self-managed servers, so the Services inherit the physical and network security controls of our providers:

Hosting

Google Cloud Platform

Application backend

Firebase (Google)

Payments

Paddle (merchant of record)

2. Encryption

3. Authentication and Access

4. Monitoring and Logging

We log access to production systems and monitor for anomalous activity. Log retention periods are reviewed periodically in line with our data minimisation obligations.

5. Vulnerability Management

We welcome reports of potential security issues through our Vulnerability Disclosure Policy. Independent security testing is planned for launch; the cadence will be confirmed and published here once finalised.

6. Incident Response

We maintain an internal process for identifying, containing, and notifying customers of security incidents affecting their data, consistent with the notification commitments in our Data Processing Addendum (including 72-hour notification for confirmed personal data breaches under UK/EU GDPR).

7. Subprocessors

A current list of subprocessors that may process Customer Data is maintained in our Data Processing Addendum.

8. Compliance Status

Sigbot is a growing company and is transparent about where formal certifications currently stand:

9. Data Retention and Deletion

Customer Data is retained for as long as your account is active, or as described in our Data Processing Addendum. You can request deletion of your account and associated data by contacting legal@sigbot.co.

10. Contact

Security questions or concerns: security@sigbot.co. To report a vulnerability, see our Vulnerability Disclosure Policy.