Security at MoleSignal
Last updated: August 25, 2026
MoleSignal Cloud is designed to receive and analyze operational telemetry. We use layered technical and organizational controls to protect customer accounts, workspace configuration, and Customer Data throughout collection, processing, storage, and access. This page summarizes the security practices that support the hosted service.
1. Security principles
Our approach to protecting MoleSignal Cloud is guided by four operating principles:
- Least privilege. People and services receive only the access needed for an authorized purpose.
- Tenant isolation. Organization and workspace context is enforced throughout authentication, authorization, and data-access paths.
- Defense in depth. Identity controls, service boundaries, monitoring, and response procedures work together so that protection does not depend on a single control.
- Secure operation. Changes are reviewed, sensitive actions are controlled, and security issues are prioritized according to risk.
2. Data protection
MoleSignal Cloud processes account information, workspace configuration, and observability data to provide the service. We apply controls appropriate to each type of information:
- Data in transit. Customer-facing web and API connections use HTTPS/TLS to protect information while it travels between supported clients and MoleSignal Cloud.
- Data isolation. Customer Data is associated with an organization and workspace and is accessed through authorization controls that preserve that context.
- Sensitive values. Credentials, tokens, and service secrets are treated as sensitive information, with access limited to authorized service paths and personnel.
- Retention and deletion. Customer Data is retained according to the applicable plan, workspace settings, customer instructions, and service agreement, then removed through the applicable deletion workflow.
- Data minimization. Customers should collect only the telemetry needed for observability and use available filtering, masking, sampling, and retention controls for their environment.
3. Identity and access
Access to MoleSignal Cloud is governed by authenticated identities and workspace authorization:
- Account access. Users access the service through authenticated sessions, and product actions are evaluated against their organization and workspace permissions.
- Customer administration. Workspace owners and administrators control membership, roles, integrations, and other settings that determine who can access Customer Data.
- Privileged access. Internal access to production systems is restricted to authorized personnel with a legitimate operational or support need and is subject to review.
- Credential protection. MoleSignal will not ask a user to disclose a password by email. Customers should rotate credentials and API tokens whenever compromise is suspected.
4. Secure development and operations
Security is incorporated into how the hosted service is developed, changed, and operated:
- Engineering controls. Changes are reviewed and tested before release, with additional attention given to authentication, authorization, tenant isolation, ingestion, and data-access paths.
- Dependency management. We monitor relevant software dependencies and prioritize security updates based on exploitability, exposure, and potential customer impact.
- Monitoring and logging. Service health, errors, and security-relevant activity are monitored to support detection, investigation, and recovery.
- Change management. Production changes follow controlled deployment procedures designed to reduce risk and support rollback or containment when necessary.
Current availability and operational incident updates are published on the MoleSignal Status page
5. Incident response
MoleSignal maintains an incident-response process for events that may affect the confidentiality, integrity, or availability of the hosted service:
- Assess. We validate alerts, establish severity, identify affected systems and customers, and preserve information needed for investigation.
- Contain and remediate. We limit ongoing impact, address the underlying cause, and apply mitigations or fixes according to risk.
- Recover and learn. We restore normal operation, verify that controls are effective, and use the findings to improve the service and our procedures.
- Communicate. If an incident affects Customer Data, we notify affected customers without undue delay as required by applicable law or contract and provide relevant updates as the investigation develops.
6. Report a vulnerability
Please report a suspected vulnerability privately before sharing technical details publicly.
Private vulnerability reports: security@molesignal.com
A useful report includes:
- The affected MoleSignal Cloud URL, API endpoint, feature, or workflow.
- A clear description of the issue, the security impact, and the conditions required to reproduce it.
- Safe reproduction steps, request samples, screenshots, or other evidence created with an account and data you are authorized to use.
- Contact details for follow-up and any timing considerations for coordinated disclosure.
Research guidelines
- Test only with accounts, workspaces, systems, and data you own or are explicitly authorized to use.
- Stop testing and notify us if you encounter another customer's data; do not retain, copy, or share it.
- Do not disrupt the service, degrade availability, send spam, use social engineering, or perform destructive testing.
- Use the minimum access necessary to demonstrate the issue, follow applicable law, and allow reasonable time for investigation and remediation.
What to expect
- We aim to acknowledge a report within 3 business days.
- We aim to provide an initial triage within 7 business days, or request the information needed to continue.
- We will coordinate remediation and any disclosure with the reporter. With permission, we may credit the reporter after the issue is resolved.
7. Customer responsibilities
Cloud security is shared with each customer. Workspace owners and users should:
- Manage access carefully. Grant the minimum permissions required, review administrators, and remove access promptly when a person changes role or leaves.
- Protect credentials. Keep passwords, API keys, agent tokens, and integration secrets private and rotate them after suspected exposure.
- Configure data collection intentionally. Apply appropriate filtering, masking, sampling, retention, and integration settings for the data entering the workspace.
- Report suspicious activity. Contact MoleSignal promptly if you suspect unauthorized account access, token misuse, or unexpected access to Customer Data.
8. Contact and updates
For a security concern or private vulnerability report, contact security@molesignal.com
For security documentation, procurement questions, or account support, contact support@molesignal.com
We may update this page as MoleSignal Cloud, our controls, or applicable requirements change. A signed customer agreement or data-processing addendum controls if it states different commitments.