Skip to content

Security

What protects your data, stated plainly

In transit and at rest

  • All traffic is encrypted with TLS (HTTPS). There is no unencrypted access.
  • Session cookies are encrypted and signed; forms are CSRF-protected.
  • Database backups are automated by our hosting provider and expire after a limited retention window (at most 30 days).

Credentials

  • Passwords are stored as bcrypt hashes. We cannot read them, and neither can anyone who reads the database.
  • Passkeys (WebAuthn) are supported for passwordless sign-in; we store only public keys.
  • API keys are shown once at creation and stored as SHA-256 hashes.

Integrations

  • Payments run entirely through Stripe — card numbers never reach our servers.
  • Outbound webhooks are signed with HMAC-SHA256 so your endpoint can verify each delivery came from us.
  • Inbound SMS webhooks are signature-verified before we act on them, so opt-out handling cannot be spoofed.
  • API access is scoped per organization and rate-limited per plan.

What we do not have

We are a small operation and describe ourselves honestly: there is no SOC 2 report, no penetration-test certificate, no compliance department. What you get instead is a small attack surface — no ad tech, nothing third-party on the pages volunteers use except Cloudflare’s bot check, few moving parts — and direct access to the people who run the service.

Reporting a vulnerability

Found something? Email support@signupsavant.com with enough detail to reproduce it. We will acknowledge quickly, fix it as a priority, and credit you if you want credit. Please do not test against other people's data.