Your data
What ReleaseSignoff stores, and where
A release heat map is a client deliverable. Before you put one anywhere, you should know exactly what is being uploaded and who can reach it. This page says so plainly, including the parts that are still limitations.
What gets uploaded
Two files per release, and only these:
- The What's New heat map as your tenant delivers it: feature names, descriptions, functional areas, and the highlighting your team applied.
- Your owner roster: the names, email addresses and functional areas of the people who review.
- Optionally, the Feature Release Testing Workbook, if you use one: test scenario names, descriptions and execution status.
No worker data is uploaded, and none is needed. ReleaseSignoff never connects to your tenant, holds no Workday credentials, and has no integration that could reach employee records. It reads spreadsheets you upload and nothing else.
Where it is hosted
The application runs on Cloudflare's network. Data is stored in a managed Postgres database hosted on AWS in the United States, with encryption in transit and at rest. If your organisation needs data resident in a specific region, say so before you upload anything, because that is not something I can currently offer and I would rather tell you now.
Who can see what
Access is enforced in the database itself, not just in the interface, using row-level security. Every table is scoped to an organisation, and a query from a user who is not a member of that organisation returns nothing at all, regardless of what the application asks for.
| Who | Can see |
|---|---|
| A reviewer | Only the organisations they are a member of. Within those, the features and scenarios for that release. |
| An organisation admin | The same, plus import and roster management for their own organisations. |
| Someone with an account but no membership | Nothing. Authenticating is not the same as being authorised, and an account with no organisation membership returns no rows. |
| Another organisation | Nothing. There is no shared view and no cross-organisation reporting. |
Accounts
Sign-in is by emailed link, so there is no password to store or leak. A password option exists for shared demonstration accounts only. There is no self-serve signup: an account has to be added to an organisation deliberately, which means a stranger who requests a sign-in link gets an account that can see nothing.
Deleting your data
Ask and an organisation's data is deleted, including its releases, features, rosters and review history. There is no retention period I need to hold it for. If you would rather remove a single release, that works too.
What this page is not
ReleaseSignoff is a new product built by one person. It has not been through SOC 2, ISO 27001, or a third-party penetration test, and it would be dishonest to imply otherwise. If your procurement process requires any of those, it is not ready for you yet, and I would rather say that here than three weeks into an evaluation.
Question this page does not answer?
Ask before you upload anything. I would rather answer a hard question now.