An SF-86 holds your identifiers, finances, travel, relationships and history. We treat it that way. This page lists what protects it today, what's still in progress, and who else touches it.
Questions, document requests or a vulnerability report go to [email protected].
Three principles run through the whole system, and they're enforced in code, not left to policy.
No source can run until you type your consent. Each source runs only inside the scopes you chose and the accounts you connected. Revoking stops everything and leaves a record.
Tokens and extracted personal data are encrypted with a separate key for each file. Only you can decrypt them, and only when you ask. Every mailbox search is logged and shown to you word for word.
We don't sell data or show ads. Employers see an anonymous handle until you accept. Your handoff package goes wherever you take it, and nowhere else.
Preclear is in early access, and we'd rather show you real status than a wall of badges. “Designed to” means we built against the standard and checked it ourselves. It has not yet been audited by a third party.
| Framework | Scope | Status |
|---|---|---|
| NIST SP 800-63B, AAL2 | Sign-in, second factor, sessions and recovery | Designed to |
| OWASP ASVS Level 2 | Web application and API | Designed to |
| U.S. state privacy laws (CCPA/CPRA and others) | Consumer rights, limits on sensitive data, no sale or sharing | In place |
| FCRA | Consumer reports pulled on the applicant's written instruction, for their own use | In place |
| NIST SP 800-53 Rev. 5, Moderate | Control mapping for the whole service | In progress |
| SOC 2 Type II | Security, confidentiality and privacy | Planned |
| Independent penetration test | Application, API and infrastructure | Planned |
| FedRAMP-authorized hosting (AWS GovCloud) | Government-facing deployments | Planned |
What protects your file today, grouped by area. Open circles mark work on our roadmap. We list it here so you can see the gaps as well as the controls.
__Host- session cookies: 12 h maximum, 30 min idleThese vendors process personal data on our behalf. Record sources you direct us to query, such as credit bureaus, the IRS and your schools, aren't subprocessors. They receive only what they need to find your record. We update this list before any new subprocessor receives personal data.
| Vendor | Purpose | Data | Location | Status |
|---|---|---|---|---|
| Amazon Web Services | Hosting, database, key and secret storage, transactional email (SES) | All service data | United States | Active |
| Cloudflare | DNS, content delivery, web application firewall | Traffic in transit, IP addresses | United States / global edge | Active |
| Persona | Identity verification, used only when the silent check can't confirm you | Identifiers, ID document image, selfie | United States | Not yet live |
| Plaid | Bank account linking (optional, higher clearance levels only) | Account balances and locations | United States | Not yet live |
| Google / Microsoft | Mailbox connection, only if you connect one | Messages matching logged searches | United States | Not yet live |
| Anthropic | Plain-language narration of results. Never used for decisions. | Minimum needed for the explanation | United States | Not yet live |
Public policies are linked. Detailed security documentation is available to prospective employers, agency partners and researchers on request.
If you find a security issue, we want to hear about it, and we won't pursue anyone who reports in good faith.
Email [email protected] with “Security vulnerability” in the subject. Include steps to reproduce, the affected URL or endpoint, and the impact. We'll acknowledge within 3 business days, keep you updated while we fix it, and credit you if you'd like.
Research on preclear.signet-systems.com that follows this policy is authorized. We won't take legal action over it. Use only accounts you created. Don't access, change or keep anyone else's data. Stop and tell us if you reach real personal data. No denial-of-service, social engineering or physical testing. Give us reasonable time to fix before you disclose publicly.
No. Signet Systems is an independent company. Preclear helps you prepare your file. DCSA and the other investigating and adjudicating agencies decide eligibility, and Preclear doesn't submit anything to them for you.
Access to production is limited to the people who operate the service. The data that matters most, such as mailbox results, tokens and extracted identifiers, is sealed with your file's key and decrypted only when you ask. Our operations dashboard never reads SF-86 content, and revealing even an account's email address there is a deliberate, logged action.
No. Your data isn't used to train any model. Where a model is used at all, it only writes plain-language explanations of results that fixed rules already produced.
Only if you opt in to the marketplace: an anonymous profile under a sig- handle, with your readiness level, skills and the preferences you publish. They never see your SF-86 content. They see your name only after you accept their introduction.
Your file, sessions, tokens, history and account are deleted immediately. Database backups roll off within 7 days, and logs within 30. We keep no archive.
In the United States, on Amazon Web Services (us-east-1). It is encrypted in transit and at rest. For government-facing deployments, we plan to move to FedRAMP-authorized hosting.
Email [email protected]. For vulnerabilities, follow the disclosure policy above.