Skip to content

Security

Looking after your people's details

Signed holds names, job titles and contact details for everyone in your organisation. Here's how we protect them, in plain English.

  • Hashed passwords

    Stored with bcrypt, never in plain text.

  • Secure sessions

    httpOnly cookies that scripts can't read.

  • Separate organisations

    Every request checked against its organisation.

  • Read-only directory access

    Signed can't change your Microsoft 365 directory.

  • Payments by Stripe

    Card details never touch our servers.

  • Two-factor for staff

    A password and an authenticator app code.

Accounts and sessions

Signing in to Signed is protected at each step, from the password you choose to the cookie that keeps you signed in.

  • Passwords are hashed with bcrypt before they're stored. We never keep them in plain text and can't see them.
  • When you sign in, we create a random session token and keep it in an httpOnly, SameSite=Lax cookie, so scripts on the page can't read it.
  • We only store a SHA-256 hash of each session token. A copy of our database alone wouldn't be enough to sign in as you.
  • Sign-in and sign-up are rate limited to slow down password guessing and automated abuse.
  • The whole service runs over HTTPS, so everything between your browser and Signed is encrypted.

Keeping organisations apart

Many organisations use Signed, and some people belong to more than one. Each organisation's data stays in its own organisation.

  • Each organisation's people, templates, rules, banners and settings are kept separate from every other organisation's.
  • Every request is checked against the organisation it's for. Anything that doesn't belong to that organisation is refused.
  • People only see the organisations they belong to.
  • Team roles control who can change what within an organisation.
  • Signature previews in the portal are shown in sandboxed frames, so template code can't run scripts or reach the rest of the portal.
  • Signed is hosted on Amazon Web Services in its London region (eu-west-2), so your data is stored in the UK.

Microsoft 365 access

Connecting Microsoft 365 lets Signed fill in names, job titles and contact details for you. It asks for as little as it can.

  • Signed asks for read-only directory access, using the User.Read.All permission. It can read user profiles but can't change them.
  • That permission doesn't give access to mailboxes, calendars or files.
  • An admin in your organisation has to give consent before anything is connected.
  • Signed confirms which directory you're connecting with a second sign-in, so you can be sure the right Microsoft 365 directory is linked.
  • You choose whether to sync by hand or once a day.

The Outlook add-in

The add-in is what puts signatures on emails. It only needs to know who's sending.

  • Your Microsoft 365 admin deploys it centrally from the Microsoft 365 admin centre and chooses who gets it.
  • Each organisation's add-in has its own client key, so it can only fetch that organisation's signatures.
  • When someone writes an email, the add-in sends Signed the From address and gets the matching signature back. The content of the email isn't sent to Signed.
  • You can download your organisation's add-in manifest from Settings and review it before you deploy it.

Payments

We use Stripe for billing, so we never have to handle card numbers ourselves.

  • When you choose a plan, you pay through Stripe Checkout.
  • Card details are handled by Stripe and never touch Signed's servers.
  • We keep a record of your plan and invoices, but not your card number.

Staff access

An internal console lets Signed staff help customers and run the service. Getting into it takes more than a password.

  • Staff sign in to the internal console with a password and a code from an authenticator app.
  • Staff sessions are kept separate from customer sessions.
  • Changes are recorded in an audit log. On every plan, your organisation's audit log shows who changed templates, rules, banners, people and settings, and when.

Found something?

Report a security issue

If you think you've found a vulnerability in Signed, please tell us. Email hello@usesigned.co.uk with Security in the subject line.

Our contact details are also published at /.well-known/security.txt.

Please include

  • What you found and where
  • Steps to reproduce it
  • What you think the impact could be

Please don't

  • Access, change or delete data that isn't yours
  • Disrupt the service or run load tests against it
  • Share the issue publicly before we've had a chance to fix it

We'll acknowledge your report and keep you updated while we look into it.

Want the detail on what personal data we hold, why and for how long? It's all in our privacy policy.

Privacy policy

Questions

Security questions

Can't see your question? Ask us directly.

Does Signed read our emails?

No. The Microsoft 365 connection only has read-only access to user details in your directory, which doesn't include mailboxes. The Outlook add-in sends Signed the sender's email address so it can fetch the right signature, and the email itself stays in Outlook. If you use the API's stamp endpoint, your relay sends the message body so Signed can add the signature, and Signed sends it straight back without keeping it.

What access does the Microsoft 365 connection need?

Read-only directory access through the User.Read.All permission. That lets Signed read names, job titles, departments and contact details. It can't change your directory, and an admin in your organisation has to give consent.

Do you store card details?

No. Payments go through Stripe Checkout, so card details are handled by Stripe and never reach Signed's servers.

Can people in one organisation see another organisation's data?

No. Each organisation's data is kept separate, people only see organisations they belong to and every request is checked against the organisation it's for.

Can our IT team review the add-in before we deploy it?

Yes. Download your organisation's add-in manifest from Settings in the portal and review it before you upload it in the Microsoft 365 admin centre.

How do I report a security issue?

Email hello@usesigned.co.uk with Security in the subject line. Tell us what you found and how to reproduce it, and please give us a chance to fix it before sharing it with anyone else.

Every email, signed

Signed is coming soon. Register your interest and we'll let you know when you can start a 14-day free trial of Pro.

  • Coming soon
  • 14-day free trial at launch
  • From £0.49 per user per month