Trust center
Security, privacy, and data practices
This page is maintained by Intelica Analytics to answer common security and privacy questions about Defense Signals. It describes practices currently in place — it is not an independent audit or certification.
Last reviewed February 2026 · Published by Intelica Analytics
Shared responsibility
Defense Signals runs on the Lovable platform, which provides hosting, the managed database, authentication, and storage. Intelica Analytics is responsible for how the application uses those services: access control rules, what data is collected, retention, and who inside the organisation can reach it. Customers are responsible for their own account credentials, the data they submit, and how they distribute content licensed to them.
Accounts and access
- Accounts are authenticated by the platform's managed authentication service; passwords are never stored by the application.
- Traffic to defensesignals.com is served over HTTPS.
- Application data is protected by row-level access rules enforced by the database, so a signed-in account can only read the records its role permits.
- Roles are stored separately from user profiles and checked server-side; they cannot be changed from the browser.
- Administrative and workspace surfaces are excluded from search-engine indexing and require an authenticated session.
Data we collect
- Account data — email address and profile details you provide.
- Subscription data — plan, entitlements, and billing status.
- Usage data — privacy-friendly, aggregate site analytics without third-party advertising cookies.
- Content you submit — contact-form messages, saved items, and research queries you enter into Ask Signal™ and semantic search.
Full detail, including legal bases and retention, is in the Defense Signals privacy notice.
Subprocessors and integrations
The application relies on these categories of provider:
- Hosting, database, authentication, storage — the Lovable platform.
- Payments — Stripe, for subscription checkout, billing, and invoicing. Card details are handled by Stripe and never reach our servers.
- Email delivery — Beehiiv for newsletter distribution and transactional publication email.
- Analytics — Plausible, a cookie-free, privacy-focused analytics service.
- AI models — third-party model providers accessed through a managed gateway for summarisation, embeddings, and retrieval-augmented answers.
AI features and your inputs
Ask Signal™ answers from Defense Signals content and cites the pieces it used. Queries you submit are processed to produce your answer and to operate and improve the feature. Do not submit classified, export-controlled, or otherwise restricted material to any Defense Signals input field — the platform is not accredited for it, and our terms prohibit it.
Cookies and tracking
We use cookies that are necessary to keep you signed in and to remember your preferences. Our analytics provider does not set advertising cookies and does not track individuals across sites. We do not sell personal data.
Retention, export, and deletion
Account and subscription records are kept for as long as your account is active and for the period required to meet legal, tax, and accounting obligations. You may request access, correction, export, or deletion of your personal data at any time by writing to legal@defensesignals.com. We respond to verified requests within the timeframes required by applicable law.
Reporting a security issue
Report suspected vulnerabilities or account compromise to security@defensesignals.com. Please include reproduction steps and give us a reasonable window to remediate before public disclosure. Do not run automated scanning or penetration testing against production without written consent.
Compliance status
Defense Signals does not currently hold SOC 2, ISO 27001, FedRAMP, or equivalent third-party certification, and nothing on this page should be read as such a claim. If your procurement process requires a security questionnaire or a data processing agreement, contact enterprise@defensesignals.com.