Your compliance program is your data. Here's how to secure it, get it out, and delete it.
Multi-factor authentication (MFA)
Turn on MFA/TOTP under your security settings using any authenticator app. It's optional but strongly encouraged for any account holding evidence — a second factor is what stops a stolen or phished password from becoming a breach of your evidence.
Exporting your data
You are never locked in. The audit pack is a full export of your program and evidence — controls, statuses, notes, gaps, and files — that you can generate any time, on your schedule.
Deleting your data
You can delete your data and your account entirely (right to erasure). Deletion removes your program and evidence from the isolated store; back up anything you need first with an export.
Retention & backups
Evidence is retained for as long as you keep it in the workspace and is covered by encrypted, isolated backups with tested restore. Deleting an account or its data removes it from active storage per the retention policy.
One account for life — services attach, data doesn't move
The workspace is free and additive. If you later purchase intSignal services (managed IT, security, UCaaS, and so on), they are provisioned onto the same account via entitlements. Your identity and your compliance program persist untouched — there is no migration, no export/import, and no second login. A free workspace user and a full intSignal customer are the same account, with different entitlements.
Getting help
- Docs — you're reading them; start at the overview.
- Sales / managed compliance — if you'd rather have us run the program, talk to sales.
- Security questions — see the security & isolation model or contact us for a deeper review.
