Security & Compliance | CloseSignal.ai

Security & Compliance

Security at CloseSignal

CloseSignal listens to live sales calls. We know exactly what that means. Your recordings, your transcripts, and your prospects' information pass through our system, and we treat that as the responsibility it is.

This page explains how we protect that data, in plain terms, and what we are still building. We would rather tell you where we are than imply we are somewhere we are not.

Data Protection

How Your Data Is Protected

Encryption in transit

Every connection to CloseSignal uses TLS. Audio, transcripts, and account data are encrypted as they move between your browser, our servers, and the AI models that process them.

Encryption at rest

Data stored in our database is encrypted at rest. If you connect your own AI provider key, that key is separately encrypted with AES-256 before storage, using a key held only in our production environment. Your provider key is never sent back to your browser after you save it. It is decrypted server-side, at the moment of the call, and nowhere else.

Separation between organizations

Every database query in CloseSignal is scoped to your organization. Your calls, your prospects, your framework configuration, and your team's activity are isolated from every other customer's. There is no shared pool of call data.

Access control

Access is verified on every request, server-side, using signed tokens. Permissions are role-based across three levels: closer, admin, and account owner. A closer cannot reach team-wide data. An admin cannot reach another organization's data.

Model access enforced on our servers

Which AI model runs on your calls is decided server-side, not by your browser. A modified client cannot request a different model or a higher tier than your plan allows.

The AI Layer

How We Handle the AI Layer

Your calls are not used to train AI models

We use commercial AI providers under agreements that exclude API data from model training. Your calls do not become training data, for them or for us.

Bring your own key

On plans that support it, you can connect your own AI provider key. Your call data then flows under your own provider account, on your own terms, rather than ours. The key is encrypted before storage and never exposed to your browser.

Rate limiting on every sensitive path

Authentication, transcription, and AI coaching endpoints are rate limited to prevent abuse and runaway usage.

Upload validation

Documents uploaded for framework configuration are checked by both file type and extension against an allowlist, with size limits enforced on every endpoint.

Application Security

How the Application Is Hardened

Restricted cross-origin access

Our API accepts requests only from our own verified domains, so even a copied or leaked access token can't be used from anywhere else.

Content Security Policy

Every page CloseSignal serves carries a Content Security Policy that restricts where the application may send data, blocks embedding by third-party sites, prevents form redirection, and disables browser plugins. That matters especially for a product that requests microphone access.

Refuses to run if misconfigured

Our production servers refuse to start if any critical security configuration is missing. There is no silent fallback to a weaker mode. If it is not configured correctly, it does not run.

Failure visibility

If a database write fails during a live call, the call continues, because interrupting your call is the worst possible outcome. Every such event is logged and alerts our team so it can be resolved the same day rather than discovered later.

Compliance

Compliance

In Progress, Not Yet Certified

SOC 2. CloseSignal is not SOC 2 certified today. We have built our controls in alignment with the Trust Services Criteria and intend to pursue Type II certification. We will say so here when it is complete, and not before. If your procurement process needs evidence in the meantime, contact us and we will walk you through our controls directly.

Data access and deletion

You can request an export or deletion of your organization's data at any time. Contact us and we will handle it.

HIPAA

CloseSignal is not a HIPAA-compliant platform and is not intended for use with protected health information.

Scope

HIPAA and Protected Health Information

CloseSignal is built for sales conversations between a seller and a prospect. It is not designed, configured, or offered as a platform for handling protected health information as defined under HIPAA.

What's out of scope

Customers may not use CloseSignal for calls in which protected health information is discussed, disclosed, or recorded. This includes calls between a healthcare provider and a patient, calls involving patient records or treatment information, and any use in which CloseSignal would act as a business associate under HIPAA. We do not offer Business Associate Agreements at this time.

What's generally fine

If you work in healthcare and your sales conversations are with clinics, providers, or administrators rather than patients, and no patient information is discussed, CloseSignal is generally appropriate for that use. If you are unsure whether your use falls inside this boundary, contact us before you start and we will tell you plainly.

Responsible Disclosure

Reporting a Vulnerability

If you have found a security issue in CloseSignal, we want to hear about it directly. Email [email protected] with enough detail to reproduce the issue.

We will acknowledge your report within two business days and keep you updated until it is resolved. We ask that you give us reasonable time to fix an issue before disclosing it publicly. We will not pursue legal action against researchers who report in good faith and do not access, modify, or destroy customer data in the process.

Roadmap

What We Are Still Building

We would rather list this than let you assume it is already done.

Administrative audit logging

An immutable record of every administrative action, including user changes, role changes, and plan changes.

Authentication event logging

A record of logins, failed logins, and token failures.

Configurable data retention

A retention window for call transcripts, set by you, enforced automatically.

SOC 2 Type II

In progress. We will update this page when it is complete.

Questions

Security questions go to the address below. If you are evaluating CloseSignal for a team and need to talk to someone about how we handle your data, we will get on a call.

Last updated: August 2026