SignaGrid

Security architecture

Who can technically access your email — and how to keep the answer "no one".

This page describes the data flow, trust boundaries and operational responsibilities of both SignaGrid deployment models, written for the people who run the security review.

Data flow in both models

CloudProcessed by SignaGrid · Returned immediately
Your Microsoft 365SignaGrid Managed RelayRecipient
In SignaGrid Cloud, Microsoft 365 routes selected outbound messages to the SignaGrid Managed Relay via connectors. The relay applies the signature, disclaimer and banner, and returns the message to Microsoft 365 for delivery. The platform is designed not to persist message bodies or attachments.
PrivateProcessed in your cloud · Never received by SignaGrid
Customer-controlled environmentYour Microsoft 365Customer-hosted Private RelayRecipient
In SignaGrid Private, the processing layer runs inside your own cloud environment. Microsoft 365 routes messages to a relay under your control; signatures are applied without the message crossing into SignaGrid infrastructure. SignaGrid never receives message bodies or attachments.

The trust boundary, stated plainly

A hosted signature service can be well secured and still create an additional trust boundary. SignaGrid gives enterprises the option to remove our infrastructure from the email-processing path entirely.

Responsibility matrix

AreaCloudPrivate
Email path during signature processingSignaGrid-managed relayCustomer environment
Keys and secretsManaged by SignaGridCustomer-owned
Processing logsSignaGrid-operated, minimal metadataCustomer environment
UpdatesAutomaticCustomer-controlled or approved
Support accessStandard SaaSNone or just-in-time
Relay hosts, network, HASignaGridCustomer