Company / Security

Security Policy

SigDrive is designed for disconnected and customer-controlled environments where security requirements shape the architecture.

View our security.txt file

Our Security Commitment

Scope

This security policy applies to SigDrive products, services, and infrastructure, including the SigDrive Enterprise RF Data Lake platform, APIs, documentation portals, and corporate systems. It describes our security practices, vulnerability disclosure program, and customer commitments.

Data Protection

  • Encryption at Rest: Stored platform data can be protected with encryption and customer-managed key patterns where required by contract.
  • Encryption in Transit: Network communications are designed to use modern TLS and hardened cipher configurations.
  • Data Integrity: SHA-256 checksums validate file integrity from ingestion through access and help identify tampering or corruption.
  • Data Sovereignty: On-premises deployment supports customer ownership and control of data under the applicable agreement.

Access Control

  • Role-Based Access Control (RBAC): Granular permissions for viewing, uploading, annotating, and administering data.
  • Enterprise SSO: Integration with SAML 2.0, LDAP, and Active Directory for centralized identity management.
  • Multi-Factor Authentication: Support for hardware tokens, CAC/PIV cards, and TOTP authenticators.
  • Audit Logging: Security-relevant administrative and data-access events are recorded with timestamps and attribution. Deployment-specific retention and external log-protection options are reviewed with each customer.

Infrastructure Security

  • Air-Gap Architecture: No internet dependencies, phone-home licensing, or cloud requirements. Designed for disconnected networks.
  • Containerized Deployment: Kubernetes-based architecture with hardened container images scanned for vulnerabilities.
  • Network Segmentation: Micro-segmentation between services with least-privilege network policies.

Security Architecture Overview

Air-Gap Architecture

SigDrive is designed for disconnected networks, with no internet dependency, phone-home licensing, or required cloud service.

RBAC & Authentication

Role-based access controls define who can view, upload, annotate, or administer data, with support for enterprise identity providers.

Audit History

Administrative and data-access events are recorded with timestamps and attribution to support customer-led security reviews.

On-Premises Deployment

Deploy within customer infrastructure so data stays under customer policies and data-rights agreements.

Data Integrity

SHA-256 checksums validate file integrity from ingestion through access and help flag tampering or corruption.

Vulnerability Management

Security review practices and a responsible disclosure path for security researchers.

Security Standards & Customer Evidence

SigDrive is designed to support customer-led security assessments and defense deployment reviews.

NIST 800-53 Mapping
Controls mapping available for customer assessment
Disconnected Networks
Deployment pattern for customer-controlled environments
MOSA-Aligned
Architecture designed around modular open systems principles
FedRAMP Baseline Awareness
Federal security baseline considered in roadmap planning
CMMC Awareness
Cybersecurity Maturity Model requirements tracked for customer needs
Audit Evidence
Documentation to support customer-led reviews

Vulnerability Disclosure Program

How to Report

Send vulnerability reports to security@sigdrive.com. Please include:

  • • Description of the vulnerability
  • • Steps to reproduce the issue
  • • Potential impact assessment
  • • Any proof-of-concept code (if applicable)
  • • Your contact information for follow-up

Our Response Timeline

  • 24 hoursInitial acknowledgment of your report
  • 72 hoursPreliminary assessment and severity classification
  • 7 daysDetailed response with remediation plan
  • 90 daysTarget resolution for most vulnerabilities

Safe Harbor

SigDrive considers security research conducted in accordance with this policy to be authorized, lawful, and helpful to the security of our platform. We will not pursue legal action against researchers who act in good faith, report vulnerabilities responsibly, avoid accessing or modifying customer data, and do not disrupt our services. We ask that you give us reasonable time to address vulnerabilities before public disclosure.

Out of Scope

The following are not eligible for our vulnerability disclosure program:

  • • Denial of Service (DoS) attacks
  • • Social engineering attacks
  • • Physical security issues
  • • Issues in third-party services
  • • Spam or phishing attempts
  • • Clickjacking on static pages

Questions About Security?

Our team is available to discuss security requirements, provide additional documentation, or schedule a security review.