Skip to content

Security

Signal security

Signal stores Instagram credentials, public post data and private messages sent to connected accounts. These are the controls protecting them.

  1. Passwordless sign-in

    Sign-in links expire after 30 minutes and work once. Session cookies are HTTP-only and scoped to Signal.

  2. Hashed API tokens

    Signal shows each token once, stores its SHA-256 hash and lets you set an expiry or revoke access.

  3. Permissioned writes

    Tokens start with read access. Write access is granted per token, while REST remains read-only.

  4. Platform rules enforced

    Signal checks Instagram’s reply window, comment permissions and rights-request eligibility on the server.

  5. Verified inbound webhooks

    Signal verifies Meta webhook signatures before processing each payload.

  6. Signed outbound webhooks

    Outbound deliveries use timestamped HMAC-SHA256 signatures. Registered endpoints must use HTTPS.

  7. Defined retention

    Signal applies configured retention rules and records completed cleanup work.

  8. Workspace export

    Export your workspace and download mentions or creators as CSV before closing the account.

  9. Operational visibility

    Workspace operations show recent jobs and relevant failures with sensitive error details removed.

Disclosure

Report a security issue

Email [email protected] with steps to reproduce the issue. We will acknowledge the report and share next steps.

Do not access other customers’ accounts or run scans that disrupt the service. Please allow a reasonable remediation window before public disclosure. Signal does not offer a paid bounty.

If the issue appears to involve Instagram or Meta, include that context so we can assess Signal’s exposure.

Worth knowing

  • Signal is not SOC 2 or ISO 27001 certified.
  • Contact us if you need a data processing agreement or security questionnaire.
  • Contact us before signup if you have data-residency requirements.

More on what is collected and why is on the privacy page.