Version 2026-10-10

Security

How Geco Signatures protects your tenant, your mail and your account.

Mail in transit

Mail reaches the relay from Microsoft 365 over TLS and is returned to Microsoft 365 over TLS. The relay only accepts mail from Exchange Online for tenants that have connected, verified by the tenant-specific connector. Messages are processed in memory and are not written to disk; nothing of the body or attachments is retained after the message is handed back.

Every message carries a per-tenant processing marker so it can never be signed twice, including when mail passes between two tenants that both use the service.

Tenant isolation

Each workspace is bound to one Microsoft 365 tenant. All data access is scoped by workspace on the server, and every request is checked against the signed-in user’s membership and role. Media such as logos and photos is served from per-tenant paths that cannot be enumerated.

Microsoft 365 permissions

Connecting a tenant uses Microsoft Entra admin consent with the minimum application permissions the service needs to read directory attributes and manage its own transport connector and rules. We never see a user’s password and never ask for mailbox read permissions. Consent can be withdrawn from the Microsoft 365 admin centre at any time.

Secrets and encryption

Tenant credentials, authenticator secrets and other sensitive values are encrypted at rest with AES-256-GCM under a master key held only on the application servers. Passwords are hashed with scrypt. All web traffic is HTTPS with HSTS.

Accounts and access

Password accounts can enable two-step verification with an authenticator app, with backup codes for recovery; sign-in is throttled against brute force. Our own staff portal requires two-step verification for every staff member, runs on a separate host and database, and records every administrative action in an audit log. Staff never see the content of your mail.

Hosting and operations

The platform runs on dedicated infrastructure in Germany (European Union), behind a reverse proxy with automatic TLS, in isolated containers with separate databases for customer data and for the staff portal. Databases are backed up daily and backups are encrypted. Dependencies are kept current and the code is reviewed for security before release.

Logging and retention

Sign-in and security events are kept for 90 days. Mail delivery logs hold sender, recipient count, rule and outcome, never content. Workspace data is deleted 30 days after a workspace closes.

Reporting a vulnerability

If you find a security issue, email security@gecosign.com. We acknowledge reports within two working days and will not take action against good-faith research that avoids privacy violations, data destruction and service disruption.

Security · Geco Signatures