Trust
Security and control
SignalDesk is designed around isolated workspaces, scoped connections, visible approvals, small usage limits, and receipt-backed work.
Effective July 26, 2026 · Beta versionWorkspace isolation
Every customer receives a separate workspace. Membership is checked before workspace data, tasks, connections, and settings are returned. Mobile sessions and runner credentials are separately scoped.
Authentication and transport
The web app uses Sign in with ChatGPT. The ChatGPT app uses OAuth with PKCE and short-lived authorization codes. Supported webhook providers are checked using signatures and replay windows. Production traffic is encrypted in transit.
Approval boundaries
SignalDesk distinguishes reading and recommendation from actions that change external systems. Sends, publishing, destructive changes, purchases, and other high-consequence work should require explicit approval. Custom workflows begin in recommend or approval mode.
Data minimization
Tools should return only the context needed for the request. SignalDesk avoids returning authentication secrets, raw debug payloads, and unrelated personal data to AI conversations.
Usage and cost controls
Background AI is metered by workspace and stops when the included balance is exhausted. New pilot workspaces begin with a deliberately small allowance.
Responsible disclosure
If you believe you found a security issue, do not access other users’ information or disrupt service. Use the signed-in support flow, label the request “Security,” and include reproducible steps without real customer data.