Data handling and security
What data Signal stores, how accounts are protected, how to export or delete data, and which providers process it.
Updated
Manifest FTS builds Signal around the same data-trust principles it applies to client work: collect what the product needs, be clear about where it goes, and make it easy to take out.
What Signal stores
Account details (name, email, a salted scrypt password hash), workspace configuration (brand, domain, competitors, prompts, facts), observations (answer text, citations, analysis), audits, tasks, reports, and an activity log. Signal does not need and does not request access to your website, analytics, or ad accounts.
Account protection
Sessions use random tokens stored in HTTP-only, secure cookies; only a hash of each token is kept server-side. Sign-in, password reset, and public tools are rate limited. You can review and sign out other sessions from Account → Security.
Processors
Live observations send your prompts (not your account data) to the answer-engine APIs you enable. Email is delivered through Mailjet and payments through Stripe. Hosting and database providers are listed in the privacy policy.
Export and deletion
Owners and admins can export a workspace as JSON from Settings → General. Owners can delete a workspace, which permanently removes its prompts, observations, audits, tasks, and reports. You can delete your account from Account; if you are the only owner of a workspace, transfer or delete it first.
Reporting a vulnerability
Email security reports to signal@manifestfts.com. See the security page for scope.