Security
What protects your data, stated plainly
In transit and at rest
- All traffic is encrypted with TLS (HTTPS). There is no unencrypted access.
- Session cookies are encrypted and signed; forms are CSRF-protected.
- Database backups are automated by our hosting provider and expire after a limited retention window (at most 30 days).
Credentials
- Passwords are stored as bcrypt hashes. We cannot read them, and neither can anyone who reads the database.
- Passkeys (WebAuthn) are supported for passwordless sign-in; we store only public keys.
- API keys are shown once at creation and stored as SHA-256 hashes.
Integrations
- Payments run entirely through Stripe — card numbers never reach our servers.
- Outbound webhooks are signed with HMAC-SHA256 so your endpoint can verify each delivery came from us.
- Inbound SMS webhooks are signature-verified before we act on them, so opt-out handling cannot be spoofed.
- API access is scoped per organization and rate-limited per plan.
What we do not have
We are a small operation and describe ourselves honestly: there is no SOC 2 report, no penetration-test certificate, no compliance department. What you get instead is a small attack surface — no ad tech, nothing third-party on the pages volunteers use except Cloudflare’s bot check, few moving parts — and direct access to the people who run the service.
Reporting a vulnerability
Found something? Email support@signupsavant.com with enough detail to reproduce it. We will acknowledge quickly, fix it as a priority, and credit you if you want credit. Please do not test against other people's data.