Trust & Security

Security & Compliance

Built on zero-retention transit processing and enterprise-grade directory authorization rules.

Zero Email Storage

WiseSignly processes email transits entirely in-memory. We never store your actual email body contents on our servers.

Transit & Rest Encryption

All connections run through TLS 1.3 transport security. Sensitive database configurations, client metadata, and secrets are encrypted at rest via AES-256.

Read-Only Scopes

Microsoft 365 Admin Consent and Google Workspace Domain-wide Delegation requests are locked strictly to read-only directory metadata (e.g. name, title, department).

Data Isolation

In-Memory Transit Routing

WiseSignly separates directory metadata management from email transit. Our Exchange and Gmail API routing operates on a stateless queue:

  • 1Transit mail headers evaluate sender identifiers against your active rules.
  • 2The matching signature template and campaign banner inject in-memory.
  • 3Email content relays instantly to the destination server; **zero trace is left behind**.

Stateless Mail Node

WiseSignly nodes execute signature assemblies without archiving database logs of outbound email messages.

Compliance Approved
Questions

IT Security FAQ

Does WiseSignly routing delay our corporate mail flow?

No. For server-side SMTP integrations, our routing engine runs on high-throughput, low-latency AWS nodes, In-memory transit operates with strict security isolation, ensuring no email bodies are stored. Our anti-bot filtering and department context isolation run seamlessly in parallel with routing.

How is directory synchronization secured?

Directory data is synchronized using OAuth 2.0 protocol over secure HTTPS. We only request read permissions for standard active directory profile values. We do not write back or modify any data in your Azure AD or Google Workspace Directory.

Where are our signature images and assets hosted?

All image assets (logos, user headshots, banners) are hosted on CDN endpoints with redundancy. We apply optimization compression and load them over secure HTTPS to ensure quick loading on any email client.

What is your stance on regulatory privacy compliance?

WiseSignly is designed with strict data privacy guidelines. We are fully aligned with GDPR and HIPAA requirements because we do not collect or archive personal mail content, only holding active directory names, titles, and department layouts.