SignalCheckBack to checker
Security

Security & Incident Response

SignalCheck uses layered controls to reduce abuse and follows a documented process when a security incident is suspected.

Effective July 30, 2026 · Last updated July 30, 2026
01

Service protections

  • Encrypted connections, managed secret storage, and restricted payment-provider callbacks.
  • Short-term request limits and daily limits on AI screenshot analysis to reduce automated abuse and unexpected provider costs.
  • File-type and size checks before screenshot analysis. Submitted screenshots are processed for the requested check and are not intentionally stored in the application database.
  • Signed payment webhook verification and replay protection for subscription events.
02

If we detect an incident

  1. Contain the issue by limiting or temporarily disabling affected features.
  2. Preserve relevant logs and assess the scope without exposing submitted check content.
  3. Rotate affected credentials, remove unauthorized access, and deploy the fix.
  4. Restore service gradually and monitor for repeat activity.
  5. Document the incident and improve the relevant controls.
03

What users should do

If you see an unexpected payment, a suspicious account action, or a result that appears to expose private information, stop using that feature and contact the payment provider or the published support contact. Do not send passwords, verification codes, API keys, or full payment-card details in a report.

SignalCheck
PrivacyTerms