Skip to content

Data handling and security

What data Signal stores, how accounts are protected, how to export or delete data, and which providers process it.

Updated

Manifest FTS builds Signal around the same data-trust principles it applies to client work: collect what the product needs, be clear about where it goes, and make it easy to take out.

What Signal stores

Account details (name, email, a salted scrypt password hash), workspace configuration (brand, domain, competitors, prompts, facts), observations (answer text, citations, analysis), audits, tasks, reports, and an activity log. Signal does not need and does not request access to your website, analytics, or ad accounts.

Account protection

Sessions use random tokens stored in HTTP-only, secure cookies; only a hash of each token is kept server-side. Sign-in, password reset, and public tools are rate limited. You can review and sign out other sessions from Account → Security.

Processors

Live observations send your prompts (not your account data) to the answer-engine APIs you enable. Email is delivered through Mailjet and payments through Stripe. Hosting and database providers are listed in the privacy policy.

Export and deletion

Owners and admins can export a workspace as JSON from Settings → General. Owners can delete a workspace, which permanently removes its prompts, observations, audits, tasks, and reports. You can delete your account from Account; if you are the only owner of a workspace, transfer or delete it first.

Reporting a vulnerability

Email security reports to signal@manifestfts.com. See the security page for scope.