How Sigbot protects the data that moves through connected inboxes — from authentication and encryption to how we respond when something goes wrong.
Sigbot is built on established cloud infrastructure rather than self-managed servers, so the Services inherit the physical and network security controls of our providers:
Google Cloud Platform
Firebase (Google)
Paddle (merchant of record)
We log access to production systems and monitor for anomalous activity. Log retention periods are reviewed periodically in line with our data minimisation obligations.
We welcome reports of potential security issues through our Vulnerability Disclosure Policy. Independent security testing is planned for launch; the cadence will be confirmed and published here once finalised.
We maintain an internal process for identifying, containing, and notifying customers of security incidents affecting their data, consistent with the notification commitments in our Data Processing Addendum (including 72-hour notification for confirmed personal data breaches under UK/EU GDPR).
A current list of subprocessors that may process Customer Data is maintained in our Data Processing Addendum.
Sigbot is a growing company and is transparent about where formal certifications currently stand:
Customer Data is retained for as long as your account is active, or as described in our Data Processing Addendum. You can request deletion of your account and associated data by contacting legal@sigbot.co.
Security questions or concerns: security@sigbot.co. To report a vulnerability, see our Vulnerability Disclosure Policy.