Skip to main content

Last reviewed 29 September 2026

Trust and security

ServiceSignal is designed to collect only what its current free tools need, keep private reports out of public discovery, restrict administration, and delete operational data on a defined schedule.

Current scope matters: ServiceSignal does not take payments, create customer accounts, accept evidence uploads, or deliver paid files. Those capabilities require separate security, privacy, and release gates before they can be enabled.

Deployed controls

Protection across the current service

Private report access

Assessment reports require an unguessable record identifier and a separately signed, expiring capability token. Report routes are excluded from search and optional analytics.

Restricted administration

Production administration is protected by Cloudflare Access, an explicit administrator allow-list, short sessions, and independent hardware-key MFA.

Purpose-limited storage

Live application records are held in Cloudflare D1. Private product files use non-public R2 storage and are not exposed through public bucket URLs.

Signed service requests

Server-to-Worker requests are authenticated and time-bound. Write operations use replay protection, and administrative changes produce attributable audit events.

Consent-aware measurement

Google Analytics and Vercel Web Analytics remain off until a visitor opts in. Query strings, fragments, reports, authentication, and administration are excluded.

Finite retention

Assessment data is normally deleted 12 months after completion. A scheduled daily control removes expired D1 records and logs only deletion counts.

Data journey

From submission to deletion

The public application validates a submission, sends it to the private service API, and stores the assessment and answer rows in D1. The returned report link contains a time-limited signature. Scheduled retention removes the database record and its dependent answers when the approved period ends.

  1. 01

    Validate

    Constrain required fields, formats, lengths, and allowed answers.

  2. 02

    Authenticate

    Sign server requests and reject stale, altered, or replayed writes.

  3. 03

    Restrict

    Require an expiring report capability and exclude private routes from analytics.

  4. 04

    Delete

    Apply the approved retention rule and record only operational deletion counts.

Service providers

A small, named operating set

Vercel

Public application hosting and consent-gated Web Analytics

Cloudflare

Network protection, administrator access, Worker API, D1, and private R2

Resend

Requested framework delivery and contact-form email

Microsoft

Operational and enquiry mailbox hosting

Google Analytics

Optional public-page analytics after affirmative consent

Governance

Controls need operating evidence

  • Administrator access is reviewed quarterly and removed when it is no longer needed.
  • Retention-job health and manual mailbox deletion actions are reviewed monthly.
  • Application changes pass type, lint, unit, build, live content, and browser checks appropriate to their risk.
  • Security-sensitive changes require review of failure states, logging, privacy impact, and rollback.
  • Paid delivery remains blocked until its threat model, entitlement controls, legal terms, and end-to-end tests are complete.

Report a security concern

Email [email protected] with the affected route or feature, when you observed the issue, likely impact, and safe reproduction details. Do not include passwords, access tokens, unnecessary personal data, or information taken from another person's report.

Responsible testing boundary

Do not disrupt the service, access data that is not yours, use social engineering, send malware, or continue once a finding is demonstrated. ServiceSignal does not currently operate a public bounty programme. Good-faith reports will be assessed and handled through the incident process.

Common questions

Current security boundaries

Can someone find my report by changing the URL?

A valid record identifier is not sufficient. The application also requires a signed capability token that is bound to the report type and identifier and expires after the configured access period.

Does ServiceSignal use assessment answers to train AI?

No. Current assessment scoring is deterministic and the live product does not send assessment answers to a generative AI provider.

Are toolkit files publicly downloadable?

No paid toolkit files are currently released. Private R2 storage is connected for future approved files, but checkout and paid delivery remain disabled.

Does ServiceSignal claim a security certification?

No. This page describes deployed controls and operating boundaries; it does not claim ISO 27001, Cyber Essentials, SOC 2, or another certification that has not been obtained.