Security

Security you can see in the product

This page is maintained by the DataSignal IQ team to answer the questions security reviewers ask first. It describes controls that exist in the application today, not an independent assessment.

Controls in the product

Access model

  • Every contact dataset has a single owner, plus an explicit list of people granted access.
  • Administrators create shared datasets and manage who can read or manage them.
  • A dataset uploaded by an individual is private to that individual until they share it.
  • Access is granted by email to an existing account, and can be revoked at any time.

Tenancy isolation

  • Contacts, uploads, segments, exports, activities and column registries all carry the dataset or connection they belong to.
  • Row level security policies run in the database, so isolation applies to every query path rather than the interface alone.
  • Server side authorisation rechecks the caller's access before any record is read or written, including by identifier.

Authentication

  • Email and password sign in, with a six digit code flow for password resets.
  • Google sign in for organisations that prefer it.
  • Sessions refresh proactively, and every protected request revalidates its bearer token independently.

Data handling

  • Uploaded files are stored as DataSignal IQ datasets in private buckets that are not publicly readable.
  • Connected AWS and Google sources are queried in place. DataSignal IQ does not copy them.
  • Connections are configured per organisation and can be removed at any time.
  • Exports are generated per request and are downloadable only by people with access to the source dataset or connection.
  • Uploads and exports keep a history showing what was imported or taken, when, and by whom.

Shared responsibility

Where our work ends and yours begins

DataSignal IQ provides the isolation, authentication and audit surfaces. Your organisation decides who is invited, which datasets and connections are shared, and what data is uploaded in the first place.

DataSignal IQ provides

Row level isolation, authentication, private file storage, and upload and export history.

Your administrators decide

Which datasets and connections exist, who is granted access to each, and when access is removed.

Your organisation owns

The lawful basis for the data you upload, its retention, and any contractual commitments to your own customers.

Questions

Common security questions

Is this an independent certification?

No. This page describes controls that exist in the product today. It is maintained by the DataSignal IQ team and is not an audit report or a certification of any kind.

Who can see a dataset I upload myself?

Only you, until you explicitly grant access to someone else. Administrators create the shared datasets; personal uploads stay private by default.

How is access revoked?

An owner or manager removes the person from the dataset's access list. The change applies immediately to reads, writes and exports.

Do you support compliance frameworks?

Tell us which framework matters to your organisation and we will share what we can support in writing. We do not publish compliance claims we cannot evidence.

Reporting a vulnerability or need a security review? hello@gravity115.com

Bring your security team into the conversation

We will walk through the access model, isolation boundaries and export trail in detail.