Annually re-audited by independent third-parties.
SOC 2 Type II
Independently audited annually
GDPR
EU data protection compliant
POPIA
South African data privacy
ISO 27001
Information security management
CSA Star
Cloud security alliance
CCPA
California consumer privacy
Built into every line of code, every database row, every API call.
AES-256 at rest. TLS 1.3 in transit. Every byte of customer data is encrypted by default.
We never request more access than needed. No "read all email" scopes — ever.
Choose where your data lives. EU, US, ZA — your data, your jurisdiction.
Enterprise authentication, role-based permissions, and full audit trails.
Multi-region deployment with isolated tenancy and 24/7 monitoring.
Public status page, security disclosures, and a clear incident response process.
Other signature platforms ask for full mailbox access. We don't. Our integration scopes are limited to directory metadata (names, titles, departments) and signature settings. Email bodies, subjects, attachments and recipients stay completely invisible to us.
What we access
What we never access
| SOC 2 Type II audited | Yes |
| Data encryption (at rest) | AES-256 |
| Data encryption (in transit) | TLS 1.3 |
| OAuth scopes | Least privilege |
| Email content access | Never |
| SAML 2.0 SSO | Yes |
| SCIM provisioning | Yes |
| Audit logs | 7 years |
| Data residency | EU / SA / US |
| Bug bounty | Yes |
All available on request from your account manager.