Security & Trust

This page is maintained by Signum to answer common security and privacy questions about Signum. It describes controls that are enabled in the product today. It is not a certification, audit report, or independent verification.

Last updated July 25, 2026

Encryption everywhere

All traffic is served over TLS. Documents, form responses, and database records are encrypted at rest by the hosting platform.

Workspace isolation

Every table enforces row-level access rules scoped to your workspace. A query from one workspace cannot reach another's documents, fields, or responses.

Private document storage

Uploaded PDFs, generated versions, and page thumbnails live in private buckets. Files are reachable only through short-lived signed links issued to authorized users.

Authentication & access

Passwords are hashed and screened against known-breached credential lists. Google sign-in and SAML SSO are supported, and workspace roles limit what each member can do.

Tamper-evident audit trail

Uploads, field changes, sends, views, fills, and signatures are recorded with actor, timestamp, and technical metadata so a completed document can be defended.

Least-privilege operations

Administrative capability is separated from ordinary use, privileged actions are logged, and support access is limited to what a request requires.

Hosting and infrastructure

Signum runs on Lovable Cloud (managed Supabase infrastructure), with data hosted in United States. The platform handles infrastructure patching, network security, and automated database backups. Application secrets are stored in the platform's secret store and are never committed to source or exposed to browsers.

Shared responsibility

Security of a document workflow is split three ways. Understanding the split is the fastest way to know what to ask us for and what to configure yourself.

LayerResponsibility
PlatformInfrastructure, encryption at rest, network controls, backups, and patching.
SignumApplication access rules, workspace isolation, audit logging, secure defaults, and incident response.
YouWho you invite, which roles you grant, what data you place in documents, who you send links to, and offboarding members who leave.

Data collection and use

  • We store only what the service needs: account details, the documents you upload, the values recipients enter, and the metadata that proves a signature.
  • Document content is never used to train general-purpose AI models.
  • Field detection is optional and runs only on the document you choose, when you choose to run it.
  • Payment card details are handled by Stripe and never reach our servers.

Full detail is in the Privacy Policy.

Retention and deletion

Documents you delete move to Trash and are purged from primary storage after the retention window. Audit records are retained longer so completed documents keep a defensible history.

Compliance posture

For how Signum is used in regulated settings — including FERPA-covered student records and HIPAA-covered health information — see the compliance page. Signum does not currently hold a SOC 2 or ISO 27001 certification, and we will not claim one we do not have.

Reporting a vulnerability

If you believe you have found a security issue, email security@admysterium.com with steps to reproduce. We acknowledge reports within two business days and will keep you updated through remediation. Please do not run automated scans against production, access another customer's data, or publicly disclose before we have had a chance to fix the issue. We will not pursue legal action against researchers who follow this process in good faith.

Security contact

General security questions, questionnaires, and procurement reviews: security@admysterium.com.