SignaSigna
PlatformFeaturesAPIEnterprisePricing
Sign InRequest Access
SIGNA
TermsPrivacySecurityDPACookiesDashboard →
Contents
OverviewData ProtectionAccess ControlMonitoring & LoggingThird-Party InfrastructureAPI & Programmatic SecurityVulnerability DisclosureEnterprise Inquiries
FieldCrest Ventures LLC

Security & Trust

How we protect the Signa platform and your data

Effective April 13, 2026
Version 1.1
Entity FieldCrest Ventures LLC

To report a security vulnerability, email security@fieldcrestventures.com. We investigate all credible reports and respond promptly. We do not authorize automated scanning or penetration testing of production systems without prior written agreement.

Overview

Signa is designed with security, reliability, and controlled access in mind. We take a pragmatic, security-first approach to protecting user data and maintaining system integrity. Our platform is built to support secure access, controlled data handling, and reliable operation across individual and enterprise use cases.

Data Protection

We implement a range of technical and organizational safeguards, including:

  • Secure authentication and multi-factor account verification
  • Encryption of sensitive credentials and personal data at rest
  • TLS/HTTPS encryption for all data in transit
  • Infrastructure-level protections via our cloud hosting providers
  • Monitoring and logging of system activity for abuse detection
  • Access controls limiting internal system access to authorized personnel
  • Session cookies configured with Secure, HttpOnly, and SameSite protections

Access Control

User accounts are protected by industry-standard authentication systems including Google OAuth and password authentication with secure storage. API access is secured via unique, per-user API keys with mandatory 90-day rotation. MCP and A2A access requires Agent-ID identification on every request. Access levels are restricted based on subscription tier, enforced at the middleware layer on every request. Step-up verification is required before broker connections, API key creation, and trade execution.

System Monitoring and Logging

We monitor system usage and activity to:

  • Detect and prevent unauthorized access and abuse
  • Enforce rate limits and usage policies
  • Maintain system performance and reliability
  • Investigate potential violations of our Terms of Use
  • Verify compliance with API and data attribution requirements

All API and MCP requests are logged. Audit logs are maintained for all broker actions, API key operations, and subscription changes. Logs are retained for security, compliance, and operational purposes as described in our Privacy Policy.

Third-Party Infrastructure

We rely on trusted, enterprise-grade infrastructure and service providers for cloud hosting and database services, payment processing (Stripe, Inc.), and market data and financial data APIs. We conduct due diligence on our infrastructure providers and require contractual data protection obligations. We do not control third-party systems and are not responsible for their independent security practices.

API and Programmatic Security

The Signa API, MCP Server, and A2A Protocol implement the following security controls:

  • Bearer token authentication required on all requests
  • Unique API key per Subscriber — keys are non-transferable
  • API keys stored as bcrypt hashes — raw keys shown once and not retained
  • Mandatory API key rotation every 90 days
  • Agent-ID header required for MCP and A2A access
  • Rate limiting enforced by subscription tier, per-account and per-agent
  • Automated monitoring for anomalous usage patterns
  • Right to revoke access immediately upon detection of abuse
  • Watermark signals injected into API feeds for redistribution detection
  • Idempotency enforcement on trade execution routes to prevent replay

Vulnerability Disclosure

If you discover a potential security vulnerability in the Signa platform, please report it responsibly to security@fieldcrestventures.com. Include:

  • A description of the vulnerability and affected component
  • Steps to reproduce (if possible)
  • Your assessment of potential impact

We investigate all credible reports and will respond within 72 hours of receipt. We do not authorize automated security scanning, penetration testing, fuzzing, or load testing of our production systems without prior written agreement. Testing must be conducted against staging environments only.

Enterprise Inquiries

For enterprise security documentation requests, vendor security questionnaires, Data Processing Agreement requests, or compliance-related discussions:

  • Enterprise security: legal@fieldcrestventures.com
  • Data Processing Agreement: legal@fieldcrestventures.com
  • Security incident reports: security@fieldcrestventures.com

WHILE WE TAKE REASONABLE STEPS TO PROTECT DATA, NO INTERNET-BASED SYSTEM CAN GUARANTEE ABSOLUTE SECURITY. USE OF THE PLATFORM INVOLVES INHERENT RISKS ASSOCIATED WITH INTERNET-BASED SERVICES.

© 2026 Signa · Operated by FieldCrest Ventures LLC · All rights reserved
TermsPrivacyDPASecurityCookies
Signa is a research and analytical platform. It does not provide investment advice, brokerage services, or personalized recommendations. Past performance is not indicative of future results. All investments involve risk of loss.
SignaSigna

The first trading platform built for the age of AI agents.

Platform

FeaturesAgentsAgent MarketplaceTechnology & APIAPI DocsPricingFlow ScannerNews FeedBroker Setup

Company

CommunityEnterpriseContact

Legal

Terms of UsePrivacy PolicyData Processing AgreementSecurity & TrustCookie Policy

Not Financial Advice. Signa is a quantitative research and analytical platform operated by FieldCrest Ventures LLC. It does not provide investment advice, brokerage services, or personalized financial recommendations. FieldCrest Ventures LLC is not a registered investment adviser, broker-dealer, commodity trading adviser, or financial planner. Signal Outputs are for informational purposes only. Past performance is not indicative of future results. Trading involves substantial risk of loss. You are solely responsible for all investment decisions you make.

© 2026 FieldCrest Ventures LLC. All rights reserved. Signa is a trade name of FieldCrest Ventures LLC.
Start Free Trial →