SignalOps by Epic Experience Advisors, LLC

Security & Trust

A conservative V1 description of security-related controls that are visible in the current SignalOps application, with unsupported claims intentionally left out.

V1 draft for qualified legal counsel review. This page is not attorney-reviewed, final, or legal advice.

1. Scope and entity

SignalOps is operated by Epic Experience Advisors, LLC (EEA). SignalOps is EEA’s operational-intelligence product and operating brand, not a separate corporation or LLC.

This page describes application controls visible in the current implementation. It is not a certification, audit report, security addendum, incident-history statement, or promise that every customer deployment has identical configuration.

2. Account and session controls

SignalOps uses Better Auth email/password accounts and signed-in session controls for account access. Protected application routes use authenticated session checks, and account-facing security paths support session review or revocation behavior where available in the current implementation.

The current implementation does not provide provider-backed MFA enrollment as a generally available account control. The security settings path identifies that limitation; customers should not treat MFA as enabled by default and should use their existing organizational security practices around account access.

3. Workspace and tenant boundaries

Protected SignalOps routes apply authenticated workspace and organization checks before returning customer records or performing mutations. Records are scoped through server-side authorization boundaries rather than relying only on hidden navigation or browser state.

Customers are responsible for assigning authorized users appropriately and for reviewing workspace membership, submitted data, and operational permissions within their organization.

4. Application security paths

  • Security-sensitive account and administrative actions have application security or audit-event paths where those workflows are implemented.
  • The application applies a content-security policy and other security headers through its framework security layer.
  • The application applies a permissions policy that leaves unused browser capabilities disabled unless the application explicitly opts into them.
  • Sign-in, session, workspace, and administrative routes remain separate from the public legal and marketing pages.

5. Upload validation and quarantine

CSV and XLSX scan uploads pass through type, size, and content validation before they are used for scan processing. Upload metadata is recorded with a quarantine state, and processing is blocked while an upload is not cleared for analysis. Formula cells and unsupported upload types are rejected by the current validation paths.

Customers should still sanitize and minimize files before upload and should not submit information they are not authorized to share.

6. What this page does not claim

This page intentionally does not make claims about independent certifications, specific encryption standards, guaranteed backups or recovery, infrastructure or hosting arrangements, subprocessors, a fixed uptime commitment, passkeys, recovery codes, or generally available provider-backed MFA. Those topics require separate verification and counsel or procurement review before any commitment is made.

7. Reporting a security concern

Customers and partners should report a suspected security issue through their existing EEA engagement, account, or support contact so it can be routed with the relevant workspace and relationship context. If that path is not available, use signalops-ai-7@polsia.app and include only the minimum non-sensitive detail needed to establish contact. Do not include passwords, session tokens, private keys, or customer operational records in an initial message.

This is a reporting route, not a promise of a particular response time, remediation outcome, or disclosure process. EEA will assess a report in context and may request additional information through a safer channel.

8. V1 draft status

This is a working V1 document for qualified legal counsel, security, and procurement review. It is not attorney-reviewed, final, or legal advice, and it should not be treated as a substitute for a customer-specific security questionnaire or agreement.