Security & Compliance
CloseSignal listens to live sales calls. We know exactly what that means. Your recordings, your transcripts, and your prospects' information pass through our system, and we treat that as the responsibility it is.
This page explains how we protect that data, in plain terms, and what we are still building. We would rather tell you where we are than imply we are somewhere we are not.
Data Protection
Every connection to CloseSignal uses TLS. Audio, transcripts, and account data are encrypted as they move between your browser, our servers, and the AI models that process them.
Data stored in our database is encrypted at rest. If you connect your own AI provider key, that key is separately encrypted with AES-256 before storage, using a key held only in our production environment. Your provider key is never sent back to your browser after you save it. It is decrypted server-side, at the moment of the call, and nowhere else.
Every database query in CloseSignal is scoped to your organization. Your calls, your prospects, your framework configuration, and your team's activity are isolated from every other customer's. There is no shared pool of call data.
Access is verified on every request, server-side, using signed tokens. Permissions are role-based across three levels: closer, admin, and account owner. A closer cannot reach team-wide data. An admin cannot reach another organization's data.
Which AI model runs on your calls is decided server-side, not by your browser. A modified client cannot request a different model or a higher tier than your plan allows.
The AI Layer
We use commercial AI providers under agreements that exclude API data from model training. Your calls do not become training data, for them or for us.
On plans that support it, you can connect your own AI provider key. Your call data then flows under your own provider account, on your own terms, rather than ours. The key is encrypted before storage and never exposed to your browser.
Authentication, transcription, and AI coaching endpoints are rate limited to prevent abuse and runaway usage.
Documents uploaded for framework configuration are checked by both file type and extension against an allowlist, with size limits enforced on every endpoint.
Application Security
Our API accepts requests only from our own verified domains, so even a copied or leaked access token can't be used from anywhere else.
Every page CloseSignal serves carries a Content Security Policy that restricts where the application may send data, blocks embedding by third-party sites, prevents form redirection, and disables browser plugins. That matters especially for a product that requests microphone access.
Our production servers refuse to start if any critical security configuration is missing. There is no silent fallback to a weaker mode. If it is not configured correctly, it does not run.
If a database write fails during a live call, the call continues, because interrupting your call is the worst possible outcome. Every such event is logged and alerts our team so it can be resolved the same day rather than discovered later.
Compliance
SOC 2. CloseSignal is not SOC 2 certified today. We have built our controls in alignment with the Trust Services Criteria and intend to pursue Type II certification. We will say so here when it is complete, and not before. If your procurement process needs evidence in the meantime, contact us and we will walk you through our controls directly.
You can request an export or deletion of your organization's data at any time. Contact us and we will handle it.
CloseSignal is not a HIPAA-compliant platform and is not intended for use with protected health information.
Scope
CloseSignal is built for sales conversations between a seller and a prospect. It is not designed, configured, or offered as a platform for handling protected health information as defined under HIPAA.
Customers may not use CloseSignal for calls in which protected health information is discussed, disclosed, or recorded. This includes calls between a healthcare provider and a patient, calls involving patient records or treatment information, and any use in which CloseSignal would act as a business associate under HIPAA. We do not offer Business Associate Agreements at this time.
If you work in healthcare and your sales conversations are with clinics, providers, or administrators rather than patients, and no patient information is discussed, CloseSignal is generally appropriate for that use. If you are unsure whether your use falls inside this boundary, contact us before you start and we will tell you plainly.
Responsible Disclosure
If you have found a security issue in CloseSignal, we want to hear about it directly. Email [email protected] with enough detail to reproduce the issue.
We will acknowledge your report within two business days and keep you updated until it is resolved. We ask that you give us reasonable time to fix an issue before disclosing it publicly. We will not pursue legal action against researchers who report in good faith and do not access, modify, or destroy customer data in the process.
Roadmap
We would rather list this than let you assume it is already done.
An immutable record of every administrative action, including user changes, role changes, and plan changes.
A record of logins, failed logins, and token failures.
A retention window for call transcripts, set by you, enforced automatically.
In progress. We will update this page when it is complete.
Security questions go to the address below. If you are evaluating CloseSignal for a team and need to talk to someone about how we handle your data, we will get on a call.
[email protected]Last updated: August 2026