Security

Signal's security posture is a product decision, not a checklist. The principles below are how the system is shaped — not what we promise.

What Signal will never ask for

  • · Platform passwords.
  • · Cookies or browser session tokens.
  • · 2FA codes or recovery codes.
  • · Proxy or fingerprint configuration.
  • · Credentials of any kind that aren't scoped through OAuth.

OAuth-first account model

Every account connects through the platform's official authorization flow. Scopes are requested explicitly, OAuth tokens are encrypted at rest and revocable from inside the app, and each connection is visible per account. Signal never asks for or stores a platform password.

What Signal will never do

  • · Use anti-detect browsers.
  • · Route through proxies to disguise origin.
  • · Randomize browser fingerprints.
  • · Manage farms of synthetic accounts.
  • · Publish, comment, or reply without your explicit approval.
  • · Auto-index or manipulate content for search rankings.
  • · Fabricate analytics. When data isn't connected, we say so.

Human approval is structural

Every item Signal surfaces is a recommendation. The founder approves, softens, delays, or sets aside each item — there is no path through the system that bypasses the weekly review. Approved items publish on the schedule you set; nothing reaches a platform outside that approval.

Persistence & encryption

Signal stores your workspace data in Postgres behind per-workspace row-level security. Sensitive credentials — OAuth access and refresh tokens — are encrypted at rest (AES-256-GCM) and never logged, with rotation and revocation wired into the account management flow.