Last updated August 4, 2026

Security approach

NameSignal is designed to investigate suspicious domains without sending customers into harm’s way.

Safe review by design

Suspected domains are defanged and are never linked from alert screens or emails. Passive investigations query registration and DNS records only; the application does not load the suspected website.

Account and data isolation

Authentication is verified on the server. Tenant data is scoped by database row-level policies, while sensitive billing and worker operations use server-only credentials. Free accounts receive a small server-rendered alert preview, so locked domain details are not sent to the browser.

Payments and secrets

Card details are handled by Stripe and do not pass through NameSignal. API keys and service credentials stay in server-side environment storage and are not included in client bundles or health responses.

Limitations

Certificate Transparency is an early signal, not a complete map of the internet. A domain without a public certificate may not appear, public data may be delayed or incomplete, and a similarity match may be benign. Customers should validate evidence before taking action.

Reporting a concern

If you discover a security issue, use the account or billing support channel and include a clear description and reproduction steps. Do not access other users’ data, disrupt service, or publish sensitive details before there has been reasonable time to investigate.