Preview build — Pull Request #115

Signature 365 reliability and security

Explore Signature 365 security, certifications, availability, data protection, and Microsoft 365 integration safeguards.

Signature 365 is a cloud service designed to meet the highest security, availability, and compliance standards. Symprex's team of engineers developed Signature 365 in compliance with both ISO 27001 (information security) and ISO 27018 (personal data protection in the cloud). Symprex is a Microsoft Certified Partner, and its solutions are recommended by Microsoft.

ISO 27001, 27018 and SOC2 Type 2

Symprex is ISO 27001, 27018, and SOC 2 Type 2 certified.

Symprex's compliance is continuously monitored by security partner Vanta, and a live status is available at https://trust.symprex.com where the ISO 27001 and SOC 2 certificates are also available for download.

GDPR and CCPA compliance

Signature 365 is compliant with GDPR and CCPA. Its security measures ensure that the personal data it processes is safe at all times.

Choice of geolocation

Your tenant is created in the appropriate geolocation based on the country you select during the registration process. This helps you stay GDPR and CCPA compliant. Current data centre locations are the United States, Canada, Europe, United Kingdom, United Arab Emirates, and Australia, with more planned.

Multifactor authentication

Signature 365 supports multifactor authentication for signing on to Signature 365, and when connecting Signature 365 to Microsoft 365. You will not need to disable multifactor authentication on your admin account.

Safeguarding credentials

Signature 365 uses OAuth 2.0 for authentication. This means it has no access to your credentials. Where you grant access, Signature 365 stores and uses access tokens to access Microsoft 365.

Secure email processing

When using server-side signatures, email is routed via the Signature 365 service in your geolocation to add signatures. The Signature 365 service is hosted on Microsoft Azure and your email therefore never leaves Microsoft data centres. If you do not want to route emails via the Signature 365 service, you can enable the client-side signature mode only where signatures are added directly to email in the Outlook client.

Private email processing

Signature 365 does not store or read your emails. Your emails remain entirely private. The Signature 365 service scans each email for any reply/forward separator, injects the relevant signature in the correct place, and immediately routes the email back to Microsoft 365 for delivery.

Microsoft Azure infrastructure

Signature 365 is hosted exclusively on Microsoft Azure offering the highest security and SLA standards. Microsoft Azure data centres are certified to the following standards:

  • ISO 27001, 27017 and 27018
  • SOC 1 and 2

Security measures

The information in this section is a copy of Appendix 2: Security Measures in Symprex's Data Processing Agreement (DPA) available at https://www.signature365.com/legal/data-processing-agreement. It describes the security measures in place to protect your data and ensure service performance and reliability.

Confidentiality

The Supplier has controls in place to maintain the confidentiality of Customer Data, in accordance with the Services Agreement. All Supplier employees and contract personnel are bound by the Supplier’s internal policies regarding maintaining confidentiality of Customer Data and contractually commit to these obligations.

Access control

Preventing unauthorized product access

Outsourced processing: The Signature 365 Service is hosted with outsourced cloud infrastructure providers. Additionally, contractual relationships are maintained with vendors to provide the Signature 365 Service in accordance with the DPA. Contractual agreements, privacy policies, and vendor compliance programs are relied on to protect data processed or stored by these vendors.

Physical and environmental security: Product infrastructure is hosted with multi-tenant, outsourced infrastructure providers. The physical and environmental security controls are audited for SOC 2 Type II and ISO 27001 compliance, among other certifications.

Authentication: A uniform password policy is implemented for Symprex's customer products. Customers who interact with the products via the user interface must authenticate before accessing non-public customer data.

Authorisation: Customer Data is stored in multi-tenant storage systems accessible to Customers via only application user interfaces and application programming interfaces. Customers are not allowed direct access to the underlying application infrastructure. The authorisation model in each product is designed to ensure that only the appropriately assigned individuals can access relevant features, views, and customisation options. Authorisation to data sets is performed through validating the user’s permissions against the attributes associated with each data set.

Application Programming Interface (API) access: Public product APIs may be accessed using an API key or through OAuth authorisation.

Preventing unauthorized product use

Industry standard access controls and detection capabilities are implemented for the internal networks that support Symprex's products.

Access controls: Network access control mechanisms are designed to prevent network traffic using unauthorized protocols from reaching the product infrastructure. The technical measures implemented differ between infrastructure providers and include Virtual Private Cloud (VPC) implementations, security group assignment, and traditional firewall rules.

Intrusion detection and prevention: A Web Application Firewall (WAF) solution is implemented to protect hosted customer websites and other internet-accessible applications. The WAF is designed to identify and prevent attacks against publicly available network services.

Static code analysis: Security reviews of code stored in Symprex's source code repositories are performed, checking for coding best practices, and identifiable software flaws.

Penetration testing: Relationships are maintained with industry recognised penetration testing service providers. The intent of the penetration tests is to identify and resolve foreseeable attack vectors and potential abuse scenarios.

Vulnerability disclosure policy: A vulnerability disclosure policy invites and incentivises independent security researchers to ethically discover and disclose security flaws. This widens the available opportunities to engage with the security community and improve the product defences against sophisticated attacks.

Limitations of privilege & authorisation requirements

Product access: A subset of Symprex employees have access to the products and to customer data via controlled interfaces. The intent of providing access to a subset of employees is to provide effective customer support, to troubleshoot potential problems, to detect and respond to security incidents and implement data security. Access is enabled through “just in time” requests for access; all such requests are logged. Employees are granted access by role, and reviews of high risk privilege grants are initiated daily. Employee roles are reviewed at least once every six months.

Background checks: All Symprex employees undergo a third-party background check before being extended an employment offer, in accordance with and as permitted by the applicable laws. All Symprex employees are required to conduct themselves in a manner consistent with company guidelines, non-disclosure requirements, and ethical standards.

Employee training: At least once a year, employees must complete security and privacy training covering security policies, security best practices, and privacy principles.

Transmission control

In-transit: All data in transit is encrypted using TLS 1.2 or higher using industry standard algorithms and certificates.

At-rest: User passwords are stored following policies that follow industry standard practices for security. Technologies are implemented to ensure that stored data is encrypted at rest.

Input control

Detection: The infrastructure is designed to log extensive information about the system behaviour, traffic received, system authentication, and other application requests. Internal systems aggregate log data and alert appropriate employees of malicious, unintended, or anomalous activities. Symprex personnel, including security, operations, and support personnel, are responsive to known incidents.

Response and tracking: A record of known security incidents is maintained that includes description, dates and times of relevant activities, and incident disposition. Suspected and confirmed security incidents are investigated by security, operations, or support personnel; and appropriate resolution steps are identified and documented. For any confirmed incidents, appropriate steps are taken to minimise product and Customer damage or unauthorized disclosure. Notification to you will be in accordance with the terms of the Services Agreement and DPA.

Availability control

Infrastructure availability: The infrastructure providers use commercially reasonable efforts to ensure a minimum of 99.95% uptime. The providers maintain a minimum of N+1 redundancy to power, network, and HVAC services.

Fault tolerance: Backup and replication strategies are designed to ensure redundancy and fail-over protections during a significant processing failure. Customer Data is backed up to multiple durable data stores and replicated across multiple availability zones.

Online replicas and backups: Where feasible, production databases are designed to replicate data between no less than 1 primary and 1 secondary database. All databases are backed up and maintained using at least industry standard methods.

Signature 365 products are designed to ensure redundancy and reliable failover. The server instances that support the products are also designed with a goal to prevent single points of failure. This design assists ongoing operations in maintaining and updating the product applications and backend while limiting downtime.