Security & Trust

How SYGNAL protects emergency response data: enterprise cloud infrastructure, encryption everywhere, and privacy by default. Last updated: July 2026.

Company

SYGNAL is a product of 2708046 Ontario Inc., operating as SYGNAL, a Canadian company based in Ontario. We are the supplier of record on every purchase. Authorized dealers may present and support SYGNAL, but the contract, the invoice, and the support obligation are ours.

Infrastructure

SYGNAL runs entirely on Google Cloud. We deploy on managed services, so platform patching, capacity planning, and physical data centre security are handled by Google under a continuously audited security program.

Encryption

Every connection to SYGNAL is encrypted in transit with TLS 1.2 or higher. Data at rest is encrypted with AES-256 using Google managed keys. No part of the stack moves session data unencrypted.

Authentication and Access

Account access uses OAuth based authentication with the option of email and password, Apple, or Google sign in. There is no unauthenticated path into the platform: every read and write is tied to a verified identity, and your organization records, including member list, licence state, and account settings, are readable only by members of your organization. Operational data carries no personal information beyond a display name. Administrative access to SYGNAL systems is restricted to named accounts with two step verification enforced, and every administrative action requires a verified identity. Enterprise licences are validated server side at every application launch, and a suspended or revoked licence terminates active sessions within 24 hours.

Privacy and Data Minimization

We collect the minimum information needed to run the service: a display name and, if you create an account, an email address. Session telemetry is bound to the session. Once a session ends, ongoing transmission stops and the session is sealed. We do not sell personal information and we do not use customer data to train models. We follow the principles of GDPR and CCPA or CPRA. See the Privacy Policy for the full list of data categories and your rights.

Service Providers

SYGNAL is delivered on major enterprise providers, Google Cloud for infrastructure, and a PCI DSS Level 1 certified processor for payments. Card numbers never touch SYGNAL systems. A named sub-processor list, including the data each one handles, is available to customers and prospective customers on request, and we notify customers of a material change before it takes effect.

Certifications

Google Cloud, our infrastructure provider, holds the following independent third party certifications, renewed annually, which cover the platform SYGNAL is built on. Current audit reports are available from Google on request: ISO/IEC 27001 (Information Security Management), ISO/IEC 27017 (Cloud Services Security), ISO/IEC 27018 (Personally Identifiable Information in Public Clouds), and SOC 1, SOC 2 Type II and SOC 3 reports. Payment card data is handled entirely by a PCI DSS Level 1 certified processor and never touches SYGNAL systems.

Data Residency and Retention

SYGNAL data is stored on multi-region cloud infrastructure in North America. Account data is kept for the life of your subscription. Session and after action data is retained according to your plan, and you may request deletion of any session at any time. On account closure we delete personal data within 90 days. If your policy has specific residency requirements, contact us before purchase and we will confirm exactly what we can meet.

Availability and Recovery

The platform inherits the availability and backup posture of Google Cloud managed services, including automated multi-region database replication. SYGNAL is designed to keep working when connectivity does not: sessions continue to record on device without a network connection and reconcile when connectivity returns, so an incident is never dependent on a live uplink.

Incident Response

If we become aware of a breach affecting your data we will notify the affected organization administrator without undue delay and within 72 hours of confirming the breach, with what we know, what we are doing, and what we need from you. We will follow up with a written summary once the incident is closed.

Responsible Disclosure

If you believe you have found a security vulnerability in SYGNAL, email support@sygnalapp.com. We commit to acknowledging good faith reports within three business days, working with you on a fix, and crediting researchers who request it. Please do not publish details until a patch is available.

For Emergency Service IT Teams

SYGNAL is built around the realities of fire, EMS, and hazmat operations. We do not require ingestion of CAD or records management data, we do not publish who is on shift, and we do not need a connection into your network. The application talks outbound over HTTPS only, so it does not require inbound firewall rules or a VPN. If your procurement process requires a vendor security questionnaire, a data processing agreement, a sub-processor list, or evidence of insurance, send the request to support@sygnalapp.com and we will return it within five business days.

Contact

For security, privacy, or data rights questions: support@sygnalapp.com or 1 (888) 306-7880.

Contact Sales