Insly Host
Security & Compliance

Security you can audit.
Compliance you can prove.

Enterprise-grade security for every signature you deploy. SOC 2, GDPR, POPIA — and a transparent commitment to never read your email.

4.7 out of 5 from 15 Google reviews

Certified, audited, accountable.

Annually re-audited by independent third-parties.

SOC 2 Type II

Independently audited annually

GDPR

EU data protection compliant

POPIA

South African data privacy

ISO 27001

Information security management

CSA Star

Cloud security alliance

CCPA

California consumer privacy

Six pillars

Our security promise

Built into every line of code, every database row, every API call.

Encryption everywhere

AES-256 at rest. TLS 1.3 in transit. Every byte of customer data is encrypted by default.

  • AES-256 at rest in PostgreSQL
  • TLS 1.3 between every service
  • Encrypted backups with KMS-managed keys
  • HSTS, HTTP/3 and certificate pinning

Least-privilege OAuth

We never request more access than needed. No "read all email" scopes — ever.

  • Read directory metadata only
  • No access to email body content
  • Refresh tokens stored in HashiCorp Vault
  • Scopes auditable in real-time

Data residency

Choose where your data lives. EU, US, ZA — your data, your jurisdiction.

  • EU-hosted: Frankfurt, Dublin
  • SA-hosted: Cape Town, Johannesburg
  • US-hosted: Virginia, Oregon
  • Subprocessor list published publicly

SSO & access control

Enterprise authentication, role-based permissions, and full audit trails.

  • SAML 2.0 SSO (Okta, Azure AD, Google)
  • SCIM 2.0 user provisioning
  • Role-based permissions
  • 2FA enforced for admins

Infrastructure

Multi-region deployment with isolated tenancy and 24/7 monitoring.

  • Multi-AZ deployment
  • Tenant isolation at database level
  • 24/7 security operations centre
  • Quarterly penetration testing

Transparency

Public status page, security disclosures, and a clear incident response process.

  • Live status at status.inslyhost.co.za
  • Public incident reports
  • Security bug bounty programme
  • Annual transparency report
Our zero-content promise

We never read your email content.

Other signature platforms ask for full mailbox access. We don't. Our integration scopes are limited to directory metadata (names, titles, departments) and signature settings. Email bodies, subjects, attachments and recipients stay completely invisible to us.

What we access

  • • Directory: names, titles, departments
  • • Signature settings only
  • • Click tracking (your own banners)

What we never access

  • • Email content, subjects or attachments
  • • Contacts or address books
  • • Calendar or Drive content

Security at a glance

SOC 2 Type II auditedYes
Data encryption (at rest)AES-256
Data encryption (in transit)TLS 1.3
OAuth scopesLeast privilege
Email content accessNever
SAML 2.0 SSOYes
SCIM provisioningYes
Audit logs7 years
Data residencyEU / SA / US
Bug bountyYes

Compliance documents

All available on request from your account manager.

SOC 2 Type II Report
GDPR Data Processing Agreement
POPIA Compliance Statement
Subprocessor List
Penetration Test Summary
Business Continuity Plan
Incident Response Procedure
Privacy Impact Assessment
Information Security Policy

Have specific security or compliance requirements?

Our security team is happy to walk through your questionnaire, review architecture, or sign your custom DPA.