Compliance

This page is maintained by Signum and describes how Signum is configured and operated for regulated document workflows. It states our current posture honestly — including where we do not yet offer something — and is not a certification or independent audit.

Last updated July 25, 2026

How to read this page

Software is not "FERPA compliant" or "HIPAA compliant" on its own. Both laws apply to the organization that holds the records, and compliance depends on the contract in place, how the tool is configured, and how staff use it. What we can tell you is which controls exist in Signum, which contractual arrangements we will sign, and where the line sits.

FERPA

Supported

We will sign a school-official agreement and operate under the school's direct control of student records.

HIPAA

No BAA — do not upload PHI

We do not currently execute Business Associate Agreements, so covered entities should not place protected health information in Signum.

FERPA — student education records

The Family Educational Rights and Privacy Act governs education records held by schools that receive U.S. Department of Education funding. Schools may disclose records to a vendor acting as a school official with a legitimate educational interest when the vendor performs a function the school would otherwise do itself, stays under the school's direct control, and does not redisclose or repurpose the data.

Signum will operate as a school official under those conditions. In practice that means:

  • The school remains the owner and controller of every record; we process only on the school's instructions.
  • We do not sell, share, or use student data for advertising, profiling, or general AI model training.
  • We do not redisclose records except as the school directs or as law requires.
  • Access is limited to workspace members the school invites, with roles the school assigns.
  • Records are deleted or returned on request and on the retention schedule in our processing terms.
  • Every access, fill, and signature is captured in the audit trail so the school can meet its own recordkeeping and inspection obligations.

Schools should execute our data processing addendum with the FERPA school-official rider — request it from legal@admysterium.com.

Your responsibility: annually designate vendors as school officials in your FERPA notice, decide which staff get workspace access, remove departing staff, and honor parent and eligible-student inspection requests. Signum gives you the export and audit tools; the determinations are the school's.

HIPAA — protected health information

HIPAA applies to covered entities — providers, health plans, clearinghouses — and to their business associates. A vendor that stores or transmits protected health information must have a signed Business Associate Agreement in place before any PHI is shared with it.

We do not currently sign Business Associate Agreements. If you are a covered entity or business associate, do not place protected health information in Signum — including intake forms, diagnoses, treatment details, insurance identifiers, or any document that ties a person to their care. Use it for administrative paperwork that contains no PHI.

Several of the safeguards a BAA requires are already in place — unique accounts and role-based access, encryption in transit and at rest, workspace isolation, audit controls over every document event, and defined retention and deletion. What is missing is the executed agreement and the formal HIPAA program around it. If a BAA is a requirement for your organization, contact legal@admysterium.com and tell us your timeline.

Electronic signature law — ESIGN and UETA

Signum is built to satisfy the four requirements U.S. law places on a valid electronic signature:

  • Intent to sign — the signer takes a deliberate action to draw, type, or adopt a signature.
  • Consent to do business electronically — signers are told they are signing electronically before they complete the document.
  • Association with the record — the signature is bound to the specific document version and field it was applied to.
  • Record retention — the completed document and its audit trail remain available for download and reproduction.

Each signature is stamped with a timestamp, the signer's email, and the IP address and user agent captured at signing. Some documents still require wet ink or notarization — certain wills, family-law filings, and court orders among them. Confirm with counsel before moving a category of document to electronic signature.

Privacy laws — GDPR, UK GDPR, and U.S. state laws

For customers subject to GDPR, UK GDPR, CCPA/CPRA, or similar state privacy laws, Signum acts as a processor or service provider for document content. Our data processing addendum covers processing scope, subprocessors, security measures, breach notification, transfer mechanisms, and deletion. We do not sell personal information or share it for cross-context behavioral advertising.

Certifications

Signum does not currently hold SOC 2, ISO 27001, or an equivalent third-party certification, and we will not claim one we do not have. We do complete security questionnaires and vendor reviews — send yours to security@admysterium.com.

Not legal advice

This page describes product capabilities and contractual arrangements. It is not legal advice, and it does not certify that your particular use of Signum satisfies any law. Work with your own counsel or compliance officer on that determination.

Procurement pack

Need documents for a vendor review? Email legal@admysterium.com for a countersigned processing addendum, a completed security questionnaire, and the subprocessor list.