Trust center
Security & compliance
OwnSig handles your employee directory and sits inside every email your company sends. We built the platform and company portal to clear a serious security review — here is exactly how.
SOC 2 & ISO/IEC 27001
The platform and organisation are built to SOC 2 Trust Services Criteria and ISO/IEC 27001 Annex A control standards, with certification audits on our public roadmap. Control documentation is available under NDA.
GDPR
Processor DPA with SCCs, published subprocessors, regional data cells, per-employee residency pinning, recipient tracking that collects no personal data, and DSAR export/deletion workflows.
Responsible disclosure
Report vulnerabilities to security@ownsig.com. We acknowledge within 2 business days and do not pursue good-faith research conducted within our policy.
Control mapping (summary)
Illustrative mapping of how product and operations controls address common auditor themes. This is not a certification claim.
| Framework | Theme | Evidence in OwnSig |
|---|---|---|
| SOC 2 CC6 / ISO A.9 | Logical access | Tenant RBAC, staff RBAC, SSO/SCIM, MFA, password policy, sessionVersion revocation, quarterly staff access review |
| SOC 2 CC7 / ISO A.12 & A.16 | Monitoring & incidents | Append-only AuditEvent log, Cloud Logging export, security burst alerts, status page, IR runbook, 72h breach notice |
| SOC 2 CC6 / ISO A.8 | Cryptography | TLS in transit, AES-256 at rest / CMEK, vault AES-256-GCM (+ KMS envelope in production) |
| SOC 2 A / ISO A.17 | Availability | Multi-AZ compute, PITR, encrypted backups, restore drills, public /status |
| SOC 2 C & P / ISO A.5 & A.18 | Confidentiality & privacy | Tenant isolation / dedicated cells, residency pinning, DSAR/erasure, DPA + SCCs, published subprocessors |
| SOC 2 CC8 / ISO A.8 | Change management | PR review, OwnSig CI (lint/typecheck/build/audit/gitleaks), immutable image deploy via WIF |
Product architecture
- Microservice separation: the recipient-facing edge (link redirects, image hosting) runs independently from the application, so a dashboard incident never breaks links in already-sent email
- Mail never routes through OwnSig — deployment uses native Microsoft 365 and Google Workspace APIs
- Server-side click tracking with no cookies, no scripts, and no recipient personal data
- This website itself runs zero third-party trackers: no ad pixels, no social tags, no session recording — first-party, consent-governed analytics only (see the cookie policy)
- Per-tenant isolation enforced at the data layer; every query is scoped to the organisation; Enterprise dedicated cells isolate database, services, and edge
Data protection
- TLS 1.2+ for all connections; AES-256 encryption at rest (CMEK on production databases and backups)
- Tenant secrets (integration credentials, AI keys) are AES-256-GCM encrypted; production uses Cloud KMS envelope encryption when configured
- Regional data cells (US, EU, UK, Canada, Australia) with per-employee residency pinning on Enterprise Sovereign
- Data export and deletion workflows for GDPR data-subject requests; published DPA and subprocessor list
Access control (platform & company portal)
- Role-based access control in-product: Owner, Admin, Editor, Team lead, Member (plus custom roles) with least-privilege defaults
- Local passwords: minimum 12 characters, common-password blocklist, bcrypt cost factor 12; sessions are HttpOnly, Secure, SameSite=Lax JWTs with sessionVersion revocation
- Optional organisation-wide MFA for local passwords; TOTP step-up at login; SAML 2.0 / OIDC SSO and SCIM provisioning on Enterprise
- Audit log of administrative and security-relevant actions, exportable, retained 1 year; tamper-evident temporal chain for signature history
- OwnSig staff access to customer data is gated by staff RBAC, logged, MFA-capable, and reviewed quarterly
Operations
- Multi-AZ deployments with health probes feeding the public status page
- Point-in-time database recovery; encrypted backups with restore drills
- Documented incident response: severity matrix, on-call rotation, customer notification within 72 hours for personal-data breaches
- CI-enforced code review, dependency audit (high/critical fail), secret scanning (gitleaks), and annual third-party penetration testing on the roadmap
Need more?
Security questionnaires, countersigned DPAs, architecture deep-dives, and NDA control packs are handled by the security team. Formal SOC 2 / ISO certification audits remain on the public roadmap.