Trust & security
Security
A clear overview of the controls, responsibilities, and operating practices used to protect the Signature Studio experience.
1. Security overview
MA Signature Studio is designed to help organizations create, govern, approve, and deploy professional employee email signatures through controlled administrative and employee workflows. This page explains our current security approach and the responsibilities shared by MA Signature Studio, workspace administrators, employees, and technology providers.
Security practices evolve with the service. This overview is informational and does not claim a certification, audit result, or contractual security commitment unless expressly stated in a signed customer agreement.
2. Identity and access control
- Administrative areas require authenticated access and approved administrator permissions.
- Role-aware controls separate administrative management from employee signature workflows.
- Private employee request links use long, employee-specific tokens and should be shared only with the intended recipient.
- Workspace administrators are responsible for granting access only to authorized personnel and removing access when it is no longer required.
Users should protect their credentials, devices, recovery methods, and private links and should promptly report suspected unauthorized access.
3. Data protection
The platform processes the information needed to operate signature workflows, including administrator account data, employee business contact information, brand assets, configuration settings, approval records, and integration state. Data is transmitted over encrypted HTTPS connections supported by our hosting and service providers.
We seek to limit collection to information relevant to the service and avoid exposing private employee form data in exported link files. Detailed collection, use, retention, and deletion practices are described in our Privacy Policy.
4. Infrastructure and service providers
MA Signature Studio uses established cloud and software providers to host the application, store service data, deliver authentication, and support integrations. These currently include Vercel for application hosting and delivery and Supabase for database and authentication capabilities.
Provider security and availability remain subject to their own systems, terms, controls, and service conditions. Use of a provider does not mean that MA Signature Studio independently holds that provider’s certifications.
5. Google and Microsoft integrations
Google Workspace and Microsoft 365 connections use provider-managed authorization flows. Access is requested only for the functionality presented to the user or administrator, and integration credentials or tokens are handled through protected server-side workflows where supported.
Customers should configure provider accounts, scopes, administrators, and test or production access carefully. Disconnecting an integration may prevent future platform actions but may not reverse changes already completed in the connected service.
6. Application operations and monitoring
- Administrative and approval activity may be recorded to support operational review and accountability.
- Input validation and permission checks are used on sensitive workflows.
- Private request paths are excluded from website analytics, and analytics URLs are stripped of query strings and fragments before transmission.
- Dependencies, integrations, and application behavior are reviewed as the platform changes.
No internet service can guarantee absolute security. We assess issues according to their nature, likelihood, and potential impact and work to address confirmed risks responsibly.
7. Security incidents
If we confirm a security incident affecting information under our control, we will investigate, take reasonable containment and remediation steps, and provide notices when required by applicable law or a governing customer agreement.
Customers remain responsible for maintaining accurate security and administrative contacts so that important communications can reach the appropriate people.
8. Report a security concern
To report a suspected vulnerability, unauthorized access, or other security concern, email hello@masignaturestudio.com with a clear description, affected URL or feature, reproduction steps, and any supporting evidence.
Please do not access, modify, download, or disclose data belonging to others; disrupt the service; use destructive testing; or publicly disclose a suspected issue before we have had a reasonable opportunity to investigate and respond.
9. Updates and contact
We may update this Security overview as the platform, providers, controls, or risks change. The effective date above identifies the current version.
Questions about this page may be sent to hello@masignaturestudio.com.
