Everything a security or procurement review usually asks for, in one place: our documents, where your data lives, what we are and are not certified for, and the security features your IT team can switch on.
Stored in the EU (Google Cloud Firestore, multi-region eur3) and processed in London (europe-west2).
Read-only. Sigbot asks Microsoft for Mail.Read, User.Read and offline_access, never your password. Email bodies are read in memory to find the signature and are not stored.
SIGBOT LTD, a UK company registered in England and Wales, company number 16997653.
Registered with the Information Commissioner's Office as a data controller: ZC202535.
We are a young company and would rather tell you where we stand than imply more. Today Sigbot holds no security certification.
| Standard | Status | What that means |
|---|---|---|
| CSA security questionnaire (CAIQ v4.1) | Completed | Our answers to the Cloud Security Alliance's Consensus Assessments Initiative Questionnaire, completed 30 September 2026, with a plain "No" wherever a control is not yet in place. Request a copy. |
| UK GDPR | In place | ICO-registered (ZC202535), with a published privacy policy and Data Processing Addendum. |
| Microsoft publisher verification | Completed | Since 5 October 2026, Microsoft's approval screen shows Sigbot as a verified publisher (SIGBOT LTD). Most companies still approve mail access once, for everyone; the brief for IT administrators explains how. |
| Cyber Essentials | Planned | We are working towards the UK government-backed certification. This page will show the certificate once it is issued. |
| Independent penetration test | Planned | None has been carried out yet. We will commission one before our first Enterprise pilot and publish its date and a summary on the Security Overview. |
| SOC 2 | Not certified | We will start a SOC 2 audit when a customer contract requires it. |
| ISO/IEC 27001 | Not certified | Not planned at present. |
Our infrastructure providers hold their own independent certifications: Google Cloud, which stores and processes customer data, and Vercel, which serves the web app, both publish ISO/IEC 27001 and SOC 2 reports.
Every team plan includes:
The Enterprise plan adds:
The detail is in the Security Overview and DPA Annex D.
Most organisations on Microsoft's default settings need an IT administrator to approve Sigbot once for the whole organisation before staff can connect their Outlook mailboxes. The brief for IT administrators explains exactly what Sigbot can read and how to approve it.
Security review? We send our completed CAIQ and will answer your own security questionnaire.
Request our security questionnaire (CAIQ)
Security: security@sigbot.co · Privacy and legal: legal@sigbot.co · Everything else: support@sigbot.co. We reply within one working day.