Security
Signal security
Signal stores Instagram credentials, public post data and private messages sent to connected accounts. These are the controls protecting them.
Passwordless sign-in
Sign-in links expire after 30 minutes and work once. Session cookies are HTTP-only and scoped to Signal.
Hashed API tokens
Signal shows each token once, stores its SHA-256 hash and lets you set an expiry or revoke access.
Permissioned writes
Tokens start with read access. Write access is granted per token, while REST remains read-only.
Platform rules enforced
Signal checks Instagram’s reply window, comment permissions and rights-request eligibility on the server.
Verified inbound webhooks
Signal verifies Meta webhook signatures before processing each payload.
Signed outbound webhooks
Outbound deliveries use timestamped HMAC-SHA256 signatures. Registered endpoints must use HTTPS.
Defined retention
Signal applies configured retention rules and records completed cleanup work.
Workspace export
Export your workspace and download mentions or creators as CSV before closing the account.
Operational visibility
Workspace operations show recent jobs and relevant failures with sensitive error details removed.
Disclosure
Report a security issue
Email [email protected] with steps to reproduce the issue. We will acknowledge the report and share next steps.
Do not access other customers’ accounts or run scans that disrupt the service. Please allow a reasonable remediation window before public disclosure. Signal does not offer a paid bounty.
If the issue appears to involve Instagram or Meta, include that context so we can assess Signal’s exposure.
Worth knowing
- Signal is not SOC 2 or ISO 27001 certified.
- Contact us if you need a data processing agreement or security questionnaire.
- Contact us before signup if you have data-residency requirements.
More on what is collected and why is on the privacy page.