Security

The short version: your signatures never leave your server

Signature Foundry runs as a plugin inside your own WordPress installation. There is no vendor database holding your employees’ names, titles, direct lines and photographs.

New message — Re: Q3 partnership review MO Maya Okonkwo Head of Client Partnerships Northlight Studio +1 (503) 555-0142 · maya@northlight.studio in X Dr Spring campaign banner Scheduled 1–30 April · Sales team

How the product is built

Your infrastructure

Signature data lives in your WordPress database, under your backup policy and your jurisdiction.

Least privilege

Capabilities are granular: editing your own signature, managing the brand kit, running banners and viewing analytics are four separate permissions.

Signed tracking links

Click and impression endpoints verify an HMAC bound to the banner and sender, so counters cannot be inflated by hand-built URLs.

Output filtering

Every signature passes a fixed tag and attribute allowlist before it reaches a browser, on top of per-value escaping.

No recipient data

Impressions and clicks are counted per banner, per sender, per day. No IP, no user agent, no open time, no recipient.

Audit trail

Dated records of every brand kit, signature and banner change, available from the Platform plan.

What we ask of you

Because the plugin lives on your server, the perimeter is yours. Three things matter more than anything we can do at our end:

Reporting a vulnerability

Write to security@signaturefoundry.com with reproduction steps. We acknowledge within one working day, and we will not take legal action against good-faith research that stays within your own installation.

Send it to your security team before you buy.

Most reviews come back clean in a day because there is no vendor data flow to assess.