Skip to main content

Trust center

Security & compliance

OwnSig handles your employee directory and sits inside every email your company sends. We built the platform and company portal to clear a serious security review — here is exactly how.

SOC 2 & ISO/IEC 27001

The platform and organisation are built to SOC 2 Trust Services Criteria and ISO/IEC 27001 Annex A control standards, with certification audits on our public roadmap. Control documentation is available under NDA.

GDPR

Processor DPA with SCCs, published subprocessors, regional data cells, per-employee residency pinning, recipient tracking that collects no personal data, and DSAR export/deletion workflows.

Responsible disclosure

Report vulnerabilities to security@ownsig.com. We acknowledge within 2 business days and do not pursue good-faith research conducted within our policy.

Control mapping (summary)

Illustrative mapping of how product and operations controls address common auditor themes. This is not a certification claim.

FrameworkThemeEvidence in OwnSig
SOC 2 CC6 / ISO A.9Logical accessTenant RBAC, staff RBAC, SSO/SCIM, MFA, password policy, sessionVersion revocation, quarterly staff access review
SOC 2 CC7 / ISO A.12 & A.16Monitoring & incidentsAppend-only AuditEvent log, Cloud Logging export, security burst alerts, status page, IR runbook, 72h breach notice
SOC 2 CC6 / ISO A.8CryptographyTLS in transit, AES-256 at rest / CMEK, vault AES-256-GCM (+ KMS envelope in production)
SOC 2 A / ISO A.17AvailabilityMulti-AZ compute, PITR, encrypted backups, restore drills, public /status
SOC 2 C & P / ISO A.5 & A.18Confidentiality & privacyTenant isolation / dedicated cells, residency pinning, DSAR/erasure, DPA + SCCs, published subprocessors
SOC 2 CC8 / ISO A.8Change managementPR review, OwnSig CI (lint/typecheck/build/audit/gitleaks), immutable image deploy via WIF

Product architecture

  • Microservice separation: the recipient-facing edge (link redirects, image hosting) runs independently from the application, so a dashboard incident never breaks links in already-sent email
  • Mail never routes through OwnSig — deployment uses native Microsoft 365 and Google Workspace APIs
  • Server-side click tracking with no cookies, no scripts, and no recipient personal data
  • This website itself runs zero third-party trackers: no ad pixels, no social tags, no session recording — first-party, consent-governed analytics only (see the cookie policy)
  • Per-tenant isolation enforced at the data layer; every query is scoped to the organisation; Enterprise dedicated cells isolate database, services, and edge

Data protection

  • TLS 1.2+ for all connections; AES-256 encryption at rest (CMEK on production databases and backups)
  • Tenant secrets (integration credentials, AI keys) are AES-256-GCM encrypted; production uses Cloud KMS envelope encryption when configured
  • Regional data cells (US, EU, UK, Canada, Australia) with per-employee residency pinning on Enterprise Sovereign
  • Data export and deletion workflows for GDPR data-subject requests; published DPA and subprocessor list

Access control (platform & company portal)

  • Role-based access control in-product: Owner, Admin, Editor, Team lead, Member (plus custom roles) with least-privilege defaults
  • Local passwords: minimum 12 characters, common-password blocklist, bcrypt cost factor 12; sessions are HttpOnly, Secure, SameSite=Lax JWTs with sessionVersion revocation
  • Optional organisation-wide MFA for local passwords; TOTP step-up at login; SAML 2.0 / OIDC SSO and SCIM provisioning on Enterprise
  • Audit log of administrative and security-relevant actions, exportable, retained 1 year; tamper-evident temporal chain for signature history
  • OwnSig staff access to customer data is gated by staff RBAC, logged, MFA-capable, and reviewed quarterly

Operations

  • Multi-AZ deployments with health probes feeding the public status page
  • Point-in-time database recovery; encrypted backups with restore drills
  • Documented incident response: severity matrix, on-call rotation, customer notification within 72 hours for personal-data breaches
  • CI-enforced code review, dependency audit (high/critical fail), secret scanning (gitleaks), and annual third-party penetration testing on the roadmap

Need more?

Security questionnaires, countersigned DPAs, architecture deep-dives, and NDA control packs are handled by the security team. Formal SOC 2 / ISO certification audits remain on the public roadmap.

Contact security & support