Security

Security and trust

Footer365 runs in the Microsoft cloud, with least-privilege access, encryption in transit and at rest, and a full audit trail.

Microsoft sign-in

Everyone authenticates through Microsoft Entra ID. We never see or store passwords, and there are no separate credentials to manage.

Least-privilege access

We request only the permissions needed to sync your directory and manage mail-flow connectors. A Global Administrator grants consent, and can revoke it at any time.

Encryption

All traffic is encrypted in transit with TLS. Data at rest is encrypted, and stored secrets are protected with application-level encryption.

Data residency

Choose the region where your data is processed and stored, including UK and EU options.

Minimal data

We process the directory attributes needed to build signatures. We do not read or retain the body of your messages beyond injecting the signature.

Audit trail

Configuration changes, provisioning steps and mail-processing outcomes are logged, so you can see who changed what and when.

Reporting a vulnerability

If you believe you have found a security issue, please email [email protected] with the details and steps to reproduce. We investigate all reports and will acknowledge yours. Please do not publicly disclose an issue before we have had a chance to address it.

Sub-processors and data processing

We use a small number of vetted sub-processors to run the service. See our sub-processors list and our data processing terms for details, including our role as a data processor for the personal data in your directory.