FAQ
Practical answers to the questions that come up most when a firm rolls HighSign out.
Do staff need an account?
No. Staff reach HighSign through shared links on the capture plane: a link to check a tool, request a review, attest to a policy or report a near-miss. There is nothing to sign up for and nothing to log into. Only your risk or compliance team logs in, on the control plane, to write policy and manage the register.
Is checking a tool anonymous?
Yes. A check records that it happened (the tool, the data class and the verdict), so admins can see adoption and demand, but we do not record who made the check. Staff can look a tool up as many times as they like with nothing tied back to them.
Can AI change a verdict?
No. Verdicts are computed by a deterministic engine: the same rules, tool facts and data class always produce the same answer, with no AI model anywhere in the decision path. AI tool intelligence can help research and draft a tool's facts, but it only ever proposes a profile for a human to review and confirm. Setting an override is a separate, deliberate action by an owner or admin, recorded as a time-boxed exception.
What happens when a vendor changes its terms?
Vendor Watch detects the change and raises a re-review item, it never updates anything automatically. It shows what changed and previews which verdicts would move if the new facts were confirmed. An owner or admin then either confirms and recomputes, which applies the new facts and updates every affected verdict, or dismisses the item if the change turns out not to be material.
How do I prove compliance to a client, insurer or regulator?
Generate the evidence pack: your live policy documents, the register snapshot, exceptions, decisions, incidents and attestations, each stamped with the current policy hash. Because verdicts are deterministic and every one cites the rule it came from, you can trace any answer a staff member saw back to the exact rule and policy version behind it.
Is my data hosted in Australia?
Yes. Customer data is hosted in Australia, and HighSign takes reasonable steps to protect it consistent with the Australian Privacy Principles. HighSign is offered to customers internationally: if you are outside Australia, including in the EU or United Kingdom, you can request a data processing agreement and details of how your data is handled by contacting us. See Security and hosting for the full breakdown.
Is HighSign legal advice?
No. HighSign provides operational governance tooling, not legal advice. It helps you run governance and show your working, and a qualified professional should validate any control before you rely on it. See Security and hosting.
What does a "not-assessed" result mean?
It means HighSign has no rule in scope for that tool-and-data-class combination yet, not that the tool is approved. Treat it the same way you would treat a red: don't use it for that data until it has been reviewed. See Verdicts explained.
What if the tool I need isn't on the register?
Flag it by name from the tool check. This gets you a not-assessed result with a request form pre-filled, which is the usual way a new tool first surfaces to your risk or compliance team.
How long does a request take to be decided?
Requests land in the admin Inbox against a service-level clock and are typically decided within 72 hours. Whatever is decided updates the register immediately, so the next person who checks that same tool sees the new answer straight away.
Can an exception last forever?
No. Every exception is time-boxed with an expiry date, and once it passes HighSign reverts automatically to whatever the policy engine computes. Exceptions are for a specific, justified, temporary case, not a permanent way around a rule.