Security Policy
SigDrive is designed for disconnected and customer-controlled environments where security requirements shape the architecture.
View our security.txt file
Our Security Commitment
Scope
This security policy applies to SigDrive products, services, and infrastructure, including the SigDrive Enterprise RF Data Lake platform, APIs, documentation portals, and corporate systems. It describes our security practices, vulnerability disclosure program, and customer commitments.
Data Protection
- Encryption at Rest: Stored platform data can be protected with encryption and customer-managed key patterns where required by contract.
- Encryption in Transit: Network communications are designed to use modern TLS and hardened cipher configurations.
- Data Integrity: SHA-256 checksums validate file integrity from ingestion through access and help identify tampering or corruption.
- Data Sovereignty: On-premises deployment supports customer ownership and control of data under the applicable agreement.
Access Control
- Role-Based Access Control (RBAC): Granular permissions for viewing, uploading, annotating, and administering data.
- Enterprise SSO: Integration with SAML 2.0, LDAP, and Active Directory for centralized identity management.
- Multi-Factor Authentication: Support for hardware tokens, CAC/PIV cards, and TOTP authenticators.
- Audit Logging: Security-relevant administrative and data-access events are recorded with timestamps and attribution. Deployment-specific retention and external log-protection options are reviewed with each customer.
Infrastructure Security
- Air-Gap Architecture: No internet dependencies, phone-home licensing, or cloud requirements. Designed for disconnected networks.
- Containerized Deployment: Kubernetes-based architecture with hardened container images scanned for vulnerabilities.
- Network Segmentation: Micro-segmentation between services with least-privilege network policies.
Security Architecture Overview
Air-Gap Architecture
SigDrive is designed for disconnected networks, with no internet dependency, phone-home licensing, or required cloud service.
RBAC & Authentication
Role-based access controls define who can view, upload, annotate, or administer data, with support for enterprise identity providers.
Audit History
Administrative and data-access events are recorded with timestamps and attribution to support customer-led security reviews.
On-Premises Deployment
Deploy within customer infrastructure so data stays under customer policies and data-rights agreements.
Data Integrity
SHA-256 checksums validate file integrity from ingestion through access and help flag tampering or corruption.
Vulnerability Management
Security review practices and a responsible disclosure path for security researchers.
Security Standards & Customer Evidence
SigDrive is designed to support customer-led security assessments and defense deployment reviews.
Vulnerability Disclosure Program
How to Report
Send vulnerability reports to security@sigdrive.com. Please include:
- • Description of the vulnerability
- • Steps to reproduce the issue
- • Potential impact assessment
- • Any proof-of-concept code (if applicable)
- • Your contact information for follow-up
Our Response Timeline
- 24 hoursInitial acknowledgment of your report
- 72 hoursPreliminary assessment and severity classification
- 7 daysDetailed response with remediation plan
- 90 daysTarget resolution for most vulnerabilities
Safe Harbor
SigDrive considers security research conducted in accordance with this policy to be authorized, lawful, and helpful to the security of our platform. We will not pursue legal action against researchers who act in good faith, report vulnerabilities responsibly, avoid accessing or modifying customer data, and do not disrupt our services. We ask that you give us reasonable time to address vulnerabilities before public disclosure.
Out of Scope
The following are not eligible for our vulnerability disclosure program:
- • Denial of Service (DoS) attacks
- • Social engineering attacks
- • Physical security issues
- • Issues in third-party services
- • Spam or phishing attempts
- • Clickjacking on static pages
Questions About Security?
Our team is available to discuss security requirements, provide additional documentation, or schedule a security review.