Security

Your email is yours.

We hold the least we can, encrypt what we keep, and make it simple to take it all back.

Encrypted in transit

Every connection uses modern TLS, end to end. No plaintext hops.

Encrypted at rest

Recipient addresses and subjects are sealed with authenticated encryption under per-workspace keys.

Least-privilege access

We ask Google for the narrowest scopes that work — send, and your own threads. Never full-mailbox access.

Yours to revoke

Disconnect Google and delete your data in one click, any time. Bodies are never stored.

Sealed when we’re not serving it.

The identifying parts of your data — who you wrote to, and the subject line — are encrypted at rest. They’re only ever readable to hand them back to you when you sign in.

Message bodies aren’t stored at all. When reply detection needs to read a thread, it reads and discards.

At restsealed
recipient
▚a72bf98de1�c▞4▚a
subject
▚a72bf98de1�c▞4▚a72bf
Readable only while serving it back to you. Sealed the rest of the time.

Least access, by design

Signum requests only the Google permissions its features need: sending the emails and follow-ups you configure, and reading your own threads to know when someone replies. We deliberately do not request full-mailbox access, and we cannot permanently delete your mail. The full breakdown is in our Privacy Policy.

Compliance posture

We’re candid about where we are: Signum is an independent product and has not yet completed a third-party certification. Our technical controls — encryption in transit and at rest, least-privilege access, and access logging — are in place today, and we’re working toward a first formal report. If your procurement needs a security questionnaire or a DPA, we’re happy to complete one.

Responsible disclosure

Found something? We want to hear from you before anyone else does. Email [email protected]with the details and steps to reproduce. We’ll acknowledge quickly, keep you posted, and credit you if you’d like. Please give us a reasonable window to fix before disclosing publicly, and don’t access data that isn’t yours while testing.

Get in touch

Security questions, DPAs, or compliance questionnaires: [email protected].