Security
The short version: your signatures never leave your server
Signature Foundry runs as a plugin inside your own WordPress installation. There is no vendor database holding your employees’ names, titles, direct lines and photographs.
Signature Foundry runs as a plugin inside your own WordPress installation. There is no vendor database holding your employees’ names, titles, direct lines and photographs.
Signature data lives in your WordPress database, under your backup policy and your jurisdiction.
Capabilities are granular: editing your own signature, managing the brand kit, running banners and viewing analytics are four separate permissions.
Click and impression endpoints verify an HMAC bound to the banner and sender, so counters cannot be inflated by hand-built URLs.
Every signature passes a fixed tag and attribute allowlist before it reaches a browser, on top of per-value escaping.
Impressions and clicks are counted per banner, per sender, per day. No IP, no user agent, no open time, no recipient.
Dated records of every brand kit, signature and banner change, available from the Platform plan.
Because the plugin lives on your server, the perimeter is yours. Three things matter more than anything we can do at our end:
Write to security@signaturefoundry.com with reproduction steps. We acknowledge within one working day, and we will not take legal action against good-faith research that stays within your own installation.
Most reviews come back clean in a day because there is no vendor data flow to assess.