Security & Trust
This page is maintained by Signum to answer common security and privacy questions about Signum. It describes controls that are enabled in the product today. It is not a certification, audit report, or independent verification.
Last updated July 25, 2026
Encryption everywhere
All traffic is served over TLS. Documents, form responses, and database records are encrypted at rest by the hosting platform.
Workspace isolation
Every table enforces row-level access rules scoped to your workspace. A query from one workspace cannot reach another's documents, fields, or responses.
Private document storage
Uploaded PDFs, generated versions, and page thumbnails live in private buckets. Files are reachable only through short-lived signed links issued to authorized users.
Authentication & access
Passwords are hashed and screened against known-breached credential lists. Google sign-in and SAML SSO are supported, and workspace roles limit what each member can do.
Tamper-evident audit trail
Uploads, field changes, sends, views, fills, and signatures are recorded with actor, timestamp, and technical metadata so a completed document can be defended.
Least-privilege operations
Administrative capability is separated from ordinary use, privileged actions are logged, and support access is limited to what a request requires.
Hosting and infrastructure
Signum runs on Lovable Cloud (managed Supabase infrastructure), with data hosted in United States. The platform handles infrastructure patching, network security, and automated database backups. Application secrets are stored in the platform's secret store and are never committed to source or exposed to browsers.
Shared responsibility
Security of a document workflow is split three ways. Understanding the split is the fastest way to know what to ask us for and what to configure yourself.
| Layer | Responsibility |
|---|---|
| Platform | Infrastructure, encryption at rest, network controls, backups, and patching. |
| Signum | Application access rules, workspace isolation, audit logging, secure defaults, and incident response. |
| You | Who you invite, which roles you grant, what data you place in documents, who you send links to, and offboarding members who leave. |
Data collection and use
- We store only what the service needs: account details, the documents you upload, the values recipients enter, and the metadata that proves a signature.
- Document content is never used to train general-purpose AI models.
- Field detection is optional and runs only on the document you choose, when you choose to run it.
- Payment card details are handled by Stripe and never reach our servers.
Full detail is in the Privacy Policy.
Retention and deletion
Documents you delete move to Trash and are purged from primary storage after the retention window. Audit records are retained longer so completed documents keep a defensible history.
Compliance posture
For how Signum is used in regulated settings — including FERPA-covered student records and HIPAA-covered health information — see the compliance page. Signum does not currently hold a SOC 2 or ISO 27001 certification, and we will not claim one we do not have.
Reporting a vulnerability
If you believe you have found a security issue, email security@admysterium.com with steps to reproduce. We acknowledge reports within two business days and will keep you updated through remediation. Please do not run automated scans against production, access another customer's data, or publicly disclose before we have had a chance to fix the issue. We will not pursue legal action against researchers who follow this process in good faith.
Security contact
General security questions, questionnaires, and procurement reviews: security@admysterium.com.