Security architecture
Who can technically access your email — and how to keep the answer "no one".
This page describes the data flow, trust boundaries and operational responsibilities of both SignaGrid deployment models, written for the people who run the security review.
Data flow in both models
CloudProcessed by SignaGrid · Returned immediately
PrivateProcessed in your cloud · Never received by SignaGrid
The trust boundary, stated plainly
A hosted signature service can be well secured and still create an additional trust boundary. SignaGrid gives enterprises the option to remove our infrastructure from the email-processing path entirely.
Responsibility matrix
| Area | Cloud | Private |
|---|---|---|
| Email path during signature processing | SignaGrid-managed relay | Customer environment |
| Keys and secrets | Managed by SignaGrid | Customer-owned |
| Processing logs | SignaGrid-operated, minimal metadata | Customer environment |
| Updates | Automatic | Customer-controlled or approved |
| Support access | Standard SaaS | None or just-in-time |
| Relay hosts, network, HA | SignaGrid | Customer |