SignetPreclear
Trust Center

Built for the most sensitive file you own.

An SF-86 holds your identifiers, finances, travel, relationships and history. We treat it that way. This page lists what protects it today, what's still in progress, and who else touches it.

Security & privacy contact

Questions, document requests or a vulnerability report go to [email protected].

Disclosure
Policy & safe harbor
security.txt
/.well-known/security.txt
Updated
24 September 2026

Overview

Three principles run through the whole system, and they're enforced in code, not left to policy.

Consent before collection

No source can run until you type your consent. Each source runs only inside the scopes you chose and the accounts you connected. Revoking stops everything and leaves a record.

Sealed, then shown

Tokens and extracted personal data are encrypted with a separate key for each file. Only you can decrypt them, and only when you ask. Every mailbox search is logged and shown to you word for word.

Nothing leaves unless you send it

We don't sell data or show ads. Employers see an anonymous handle until you accept. Your handoff package goes wherever you take it, and nowhere else.

AES-256-GCM
A separate data key for each file, bound to its purpose
AAL2
Password + TOTP sign-in, designed to NIST SP 800-63B
0
Third-party scripts, fonts or trackers in the app
U.S. only
Hosted on AWS us-east-1

Compliance

Preclear is in early access, and we'd rather show you real status than a wall of badges. “Designed to” means we built against the standard and checked it ourselves. It has not yet been audited by a third party.

FrameworkScopeStatus
NIST SP 800-63B, AAL2Sign-in, second factor, sessions and recoveryDesigned to
OWASP ASVS Level 2Web application and APIDesigned to
U.S. state privacy laws (CCPA/CPRA and others)Consumer rights, limits on sensitive data, no sale or sharingIn place
FCRAConsumer reports pulled on the applicant's written instruction, for their own useIn place
NIST SP 800-53 Rev. 5, ModerateControl mapping for the whole serviceIn progress
SOC 2 Type IISecurity, confidentiality and privacyPlanned
Independent penetration testApplication, API and infrastructurePlanned
FedRAMP-authorized hosting (AWS GovCloud)Government-facing deploymentsPlanned

Controls

What protects your file today, grouped by area. Open circles mark work on our roadmap. We list it here so you can see the gaps as well as the controls.

In placeOn the roadmap

Data protection

  • Envelope encryption: a separate AES-256-GCM key for each fileEach encrypted item is bound to its file and purpose, so it can't be read in any other context
  • OAuth tokens and extracted personal data are never stored in plaintext
  • Database storage encrypted at rest (AES-256)
  • TLS on every connection, with HSTS and preload
  • Tamper-evident handoff package (SHA-256 digest)
  • Master key wrapping moved into AWS KMS
  • Field-level encryption for SSN and date of birth

Identity & access

  • Argon2id password hashing with a secret pepper kept outside the database
  • TOTP second factor and single-use recovery codes
  • HttpOnly __Host- session cookies: 12 h maximum, 30 min idle
  • Lockout for each account and each IP address
  • Password plus a second factor again before sensitive changes
  • Email alert for every credential change and new-device sign-in
  • Passkeys (WebAuthn)

Application security

  • Strict Content-Security-Policy: no inline or third-party scripts
  • CSRF defenses: SameSite=Strict, a required header and origin checks
  • Anti-clickjacking, nosniff, no-referrer and COOP headers
  • Host allowlist, request-size caps and per-IP rate limits
  • Each file is resolved only from your session. No file ID from the browser is ever trusted.
  • Generic error responses that never expose internal details
  • Independent penetration test

Infrastructure

  • AWS us-east-1: ECS Fargate, RDS PostgreSQL, Secrets Manager
  • Origin reachable only through Cloudflare; web application firewall and edge rate limits
  • Containers run as non-root with no-new-privileges
  • Production refuses to start with default secrets or insecure settings
  • Deploys use short-lived OIDC credentials, never long-lived keys
  • FedRAMP-authorized hosting (AWS GovCloud)

Privacy by design

  • Typed consent gates every source, in code
  • Each value carries its provenance: source, confidence and confirmation
  • Readiness is scored by fixed, inspectable rules. A language model only narrates.
  • Anonymous marketplace handles; identity released only when you accept
  • Account deletion is a hard delete, not a soft flag
  • First-party telemetry with no identifiers; GPC and Do Not Track honored

Operations

  • Every change passes the automated test suite and a dependency audit (pip-audit) before deploy
  • Monitoring and alerting on errors, latency and data stores
  • Operations dashboard never reads SF-86 content; unmasking an email is a logged action
  • Every action on your file is recorded in an append-only log, which you can see
  • Backups kept 7 days; logs kept 30 days
  • Audit log streamed to a store that can't be edited, with retention locks
  • Container image scanning and SBOM

Subprocessors

These vendors process personal data on our behalf. Record sources you direct us to query, such as credit bureaus, the IRS and your schools, aren't subprocessors. They receive only what they need to find your record. We update this list before any new subprocessor receives personal data.

VendorPurposeDataLocationStatus
Amazon Web ServicesHosting, database, key and secret storage, transactional email (SES)All service dataUnited StatesActive
CloudflareDNS, content delivery, web application firewallTraffic in transit, IP addressesUnited States / global edgeActive
PersonaIdentity verification, used only when the silent check can't confirm youIdentifiers, ID document image, selfieUnited StatesNot yet live
PlaidBank account linking (optional, higher clearance levels only)Account balances and locationsUnited StatesNot yet live
Google / MicrosoftMailbox connection, only if you connect oneMessages matching logged searchesUnited StatesNot yet live
AnthropicPlain-language narration of results. Never used for decisions.Minimum needed for the explanationUnited StatesNot yet live

Documents

Public policies are linked. Detailed security documentation is available to prospective employers, agency partners and researchers on request.

Privacy Policy Public Terms of Service & End-User License Public Security & threat-model overview Request Authentication design (AAL2) Request Encryption inventory Request Security questionnaire (CAIQ / custom) Request
Penetration test summary Planned
SOC 2 report Planned

Vulnerability disclosure

If you find a security issue, we want to hear about it, and we won't pursue anyone who reports in good faith.

How to report

Email [email protected] with “Security vulnerability” in the subject. Include steps to reproduce, the affected URL or endpoint, and the impact. We'll acknowledge within 3 business days, keep you updated while we fix it, and credit you if you'd like.

Safe harbor

Research on preclear.signet-systems.com that follows this policy is authorized. We won't take legal action over it. Use only accounts you created. Don't access, change or keep anyone else's data. Stop and tell us if you reach real personal data. No denial-of-service, social engineering or physical testing. Give us reasonable time to fix before you disclose publicly.

Frequently asked

Is Preclear part of the government?

No. Signet Systems is an independent company. Preclear helps you prepare your file. DCSA and the other investigating and adjudicating agencies decide eligibility, and Preclear doesn't submit anything to them for you.

Can Signet employees read my SF-86?

Access to production is limited to the people who operate the service. The data that matters most, such as mailbox results, tokens and extracted identifiers, is sealed with your file's key and decrypted only when you ask. Our operations dashboard never reads SF-86 content, and revealing even an account's email address there is a deliberate, logged action.

Do you train AI models on my data?

No. Your data isn't used to train any model. Where a model is used at all, it only writes plain-language explanations of results that fixed rules already produced.

What can employers see?

Only if you opt in to the marketplace: an anonymous profile under a sig- handle, with your readiness level, skills and the preferences you publish. They never see your SF-86 content. They see your name only after you accept their introduction.

What happens when I delete my account?

Your file, sessions, tokens, history and account are deleted immediately. Database backups roll off within 7 days, and logs within 30. We keep no archive.

Where is my data stored?

In the United States, on Amazon Web Services (us-east-1). It is encrypted in transit and at rest. For government-facing deployments, we plan to move to FedRAMP-authorized hosting.

How do I report a security or privacy concern?

Email [email protected]. For vulnerabilities, follow the disclosure policy above.