Security & Compliance
Last updated: August 2026
Our approach to security
SignSyncer is built and operated by Xpert Group FZE-LLC. Protecting the data our customers trust us with is a foundational requirement of the product, not an add-on — this page describes the practices we follow today and the certifications we're working toward.
Where we stand today
SignSyncer is a pre-launch product. We have not yet completed third-party audits such as SOC 2 Type II or ISO/IEC 27001, and we do not claim these certifications. We're building toward them as the product and customer base mature. If your organization requires a specific certification before onboarding, contact us and we'll let you know our current status and timeline honestly.
Data handling principles
- No email content access. SignSyncer never reads or stores the body of your emails — only the signature data you explicitly provide is used.
- Read-only directory sync. Where SignSyncer connects to a directory (Google Workspace, Microsoft Entra ID, Active Directory), that connection is read-only. SignSyncer never requests write access to your directory.
- Encryption in transit. Data moving between your browser, our servers, and connected platforms is encrypted using TLS.
- Role-based access control. Admin, IT, and marketing roles are scoped separately, so each team member only has access to what their role requires.
- Data minimization. We only collect the information needed to build and deploy signatures — name, title, contact details, and similar fields you choose to include.
Reporting a security issue
If you believe you've found a security vulnerability in SignSyncer, please report it to support@signsyncer.com with a description of the issue. We take all reports seriously and will respond as quickly as we can.
Contact
Xpert Group FZE-LLC
Sharjah, United Arab Emirates
Phone: +971 50 433 4829
Email: support@signsyncer.com