Security
Student-First Security
Signpost was built by students who understand what it feels like to hand your webcam feed to an app and wonder where that footage goes. So we designed the system so that question never has to be asked.
The Core Principle
Your webcam feed is processed entirely inside your browser. Video frames never leave your device — not to our servers, not to any third party, not anywhere. The only data transmitted is numerical hand landmark coordinates (X/Y/Z joint positions), which contain no visual information and cannot be used to reconstruct images or identify you.
Infrastructure Security
Our infrastructure is built on modern, hardened foundations:
Encrypted in Transit
All communications use TLS 1.3. HSTS headers enforce HTTPS across all subdomains. Downgrade attacks are not possible.
Strict CSP Headers
Our Content Security Policy restricts script sources, blocks framing, prevents MIME sniffing, and disallows object embeds. We ship production headers, not defaults.
Zero Remote Images
Next.js image optimization is locked to local assets only. No external image domains are allowed, eliminating a common vector for content injection.
No Powered-By Header
We strip the X-Powered-By header in production. Attackers don't get free information about our stack.
Cross-Origin Isolation
COOP, COEP, and CORP headers are set to same-origin, preventing cross-origin data leaks and Spectre-class side-channel attacks.
Student Data Protection
A large portion of our users are students — many under 18, some using Signpost as part of school programs. We take that responsibility seriously:
- No targeted advertising. Ever. We do not serve ads, build behavioral profiles, or sell data to brokers. Students are learners, not products.
- Minimal data collection. We collect only what we need to provide the service: account info, learning progress, and de-identified landmark coordinates for model improvement.
- COPPA compliance. Users under 13 require verifiable parental or guardian consent. We do not knowingly collect personal information from children under 13 without it.
- FERPA awareness. For schools and districts that integrate Signpost into instruction, we work to align with the Family Educational Rights and Privacy Act. Educational institutions can contact us to establish appropriate agreements.
- Data deletion on request. Students (or their parents/guardians) can request full account and data deletion at any time. We process these requests within 30 days.
Application Security
On-Device Processing
Our computer vision pipeline runs entirely in-browser using optimized WebAssembly and WebGL. Hand detection, landmark extraction, and sign classification all happen on your device. This architecture was chosen specifically because it means we never need to see — and therefore never need to protect — raw video data.
Access Control
Internal access to production systems follows the principle of least privilege. Only a small number of team members have access to production databases, and all access is logged and audited. We do not grant broad administrative permissions.
Dependency Management
We run automated dependency audits through Dependabot and npm audit as part of our CI/CD pipeline. Known vulnerabilities in upstream packages are flagged and patched within the regular development cycle.
Source Code
Portions of our codebase, including this landing page, are open-source and available on GitHub. We believe openness is a security feature, not a liability. If you find a vulnerability, we want to hear about it.
Responsible Disclosure
If you discover a security vulnerability in Signpost, we ask that you disclose it to us responsibly:
- Email [email protected] with a clear description of the vulnerability, steps to reproduce, and potential impact.
- Give us a reasonable amount of time (at least 90 days) to investigate and remediate before any public disclosure.
- Do not access, modify, or delete data belonging to other users during your research.
We commit to acknowledging your report within 48 hours and providing status updates within 5 business days. While we do not currently operate a formal bug bounty program, we genuinely appreciate security researchers who help us keep the platform safe and will recognize contributions publicly with your permission.
Incident Response
In the unlikely event of a data breach, our response plan follows these steps:
- Containment — Immediately isolate affected systems and prevent further exposure.
- Assessment — Determine the scope and nature of the breach within 24 hours.
- Notification — Notify affected users and relevant authorities (including GDPR supervisory authorities within 72 hours where applicable).
- Remediation — Fix the root cause, deploy patches, and update security measures.
- Post-Mortem — Publish an internal (and, where appropriate, external) post-mortem to prevent recurrence.
What We Explicitly Don’t Do
Transparency means being clear about what’s not happening too:
- We do not record, store, or transmit webcam video.
- We do not perform facial recognition or biometric identification.
- We do not sell or share personal data with advertisers or data brokers.
- We do not build behavioral profiles for marketing.
- We do not embed third-party tracking pixels.
- We do not use dark patterns to coerce consent.
Related Policies
Report a Concern
Matrix Studios Software
Security: [email protected]
Privacy: [email protected]


