Trust / security
Security & data protection
Security is an implementation discipline: understand the data, minimise exposure, control access and keep dependencies reviewable.
No certification claim. This page describes working principles, not a certification, audit report or guarantee.
Operational principles
- Collect and expose only what the workflow needs.
- Use role-based access, strong authentication and least privilege where the platform supports it.
- Separate production credentials from documentation and testing.
- Review integrations, webhooks, exports and retention before go-live.
- Keep a human owner for high-impact communications and automated decisions.
Platform hygiene
Implementations should use current vendor controls, verified domains, secure secrets handling, controlled user access and documented change ownership. Third-party platform security remains a shared responsibility.
Incidents and questions
Report a suspected security issue promptly to contact@coresignalagency.com with enough detail to investigate. Do not include passwords or unnecessary personal data.
Review boundaries
Before launch, confirm vendor contracts, subprocessors, transfer safeguards, backup and deletion expectations, incident responsibilities and any sector-specific controls.