Lawful · Permission-based · Auditable

The command center for lawful public-source investigations.

Create subject dockets, collect public-source intelligence, organize evidence, map relationships, collaborate with your team, and generate professional reports — from one secure platform built for licensed investigators, legal teams, corporate security, compliance, and authorized research teams.

Public-source intelligence · Verified workflows · Secure investigations

signalable / dockets / corporate-due-diligence-review
secure
Active dockets
12
+3 this week
Sources monitored
284
98 verified
Review queue
47
needs analyst
Firecrawl ingestion
press.example.com/q3-reportcaptured
news.example.org/article/8421extracting
gov.example.com/registry/lookupqueued
Review queue
Entity: Vale Holdings Ltd.unverified · 72%
Timeline: Public filing 2024-04-12unverified · 88%
Alias: J. Vale → Jordan Valeunverified · 64%

NOTICE · Signalable collects only lawful, publicly available, user-provided, client-authorized, or properly licensed data. Not for employment, housing, credit, insurance, or eligibility screening unless configured by counsel for FCRA-compliant workflows. Findings are not determinations of fact unless independently verified.

Modules

Built for the full investigation lifecycle.

Every module is permission-aware, audit-logged, and isolated to your organization with row-level security.

Subject dockets

Central case files with legal-basis gating, sensitivity tiers, retention, and team assignment.

Public-source collection

Firecrawl scrape, search, and crawl run server-side only — keys never touch the browser.

Evidence locker

Hashed (SHA-256), versioned, chain-of-custody logged. Signed URLs, private bucket.

Graph mapping

Nodes and edges across subjects, organizations, articles, and events with verification tags.

Timeline builder

Auto-organize public-source findings by date with confidence and analyst-review status.

Report generation

Drag-and-drop sections, legal-basis block, disclaimers, redactions, PDF export.

Team collaboration

Ten role tiers, docket-level permissions, review queue, client-safe report sharing.

Compliance controls

FCRA, CCPA/CPRA, GDPR, GLBA, DPPA, and platform-ToS awareness baked into the workflow.

SOC 2-readiness

Designed to support SOC 2 audit preparation. Not a claim of certification.

Security model

Server-side keys. Org-isolated rows. Hashed evidence.

Every record is scoped to an organization through Postgres row-level security. Firecrawl, Lovable AI, and any other privileged calls happen only inside server functions — API keys never reach the browser. Evidence files live in a private bucket behind short-lived signed URLs and are SHA-256 hashed at upload with a chain-of-custody log entry.

  • Row-level security on every table
  • Role-based access (10 roles)
  • Audit log for sensitive actions, append-only
  • Server-only Firecrawl + Lovable AI calls
  • Hashed, versioned evidence with chain-of-custody
  • Retention policies + privacy request tracking
  • MFA-ready auth + Google sign-in
  • Session timeout + signed-URL downloads
Defense in depth
Auth
Supabase + Google · MFA-ready
Database
Postgres + RLS · org-scoped
Audit
Append-only log · admin + auditor read
Storage
Private bucket · signed URLs
Legal basis
Required before any collection
Findings
Default to 'unverified' until analyst review
Compliance

Lawful by design.

Signalable enforces compliance posture at the workflow level — not as a checkbox. Collection cannot begin until a docket has a lawful-purpose confirmation and a documented legal basis.

FCRA

Not for employment, housing, credit, insurance, or eligibility screening unless configured by counsel.

CCPA / CPRA

Subject rights workflow with privacy-request tracking and retention controls.

GDPR

Legal-basis tracking, data minimization defaults, deletion + export logs.

GLBA · DPPA

Source registry + blocked-domain controls keep regulated data out of collection.

Platform ToS

No login/session scraping, CAPTCHA bypass, or scraping behind authentication.

Provenance

Every datum carries source URL, timestamp, method, confidence, and review status.

Ready to bring your investigations into one secure command center?

Request a guided walkthrough. We'll set up a demo organization with sample dockets, sources, and reports so your team can evaluate the workflow end-to-end.