Security posture

Access control

Services are designed around scoped access, account/session controls, private administrative surfaces, and separation between public and operational systems.

Least privilege

Sensitive operations, account actions, exports, and regulated workflows should use the least access needed for the task.

Encryption and storage

Encrypted transport and storage protections may be used where applicable through hosting, WordPress, database, browser, or provider capabilities.

Monitoring and recovery

Logging, diagnostics, security plugins, backups, health checks, and operational reports may be used to detect errors, abuse, failed workflows, and security-relevant events.

Responsible disclosure

Report suspected vulnerabilities through Support, Contact, or hello@emailsign.design. Include affected URL, steps to reproduce, impact, screenshots or logs if safe, and contact information for follow-up.

  • Do not run destructive tests.
  • Do not access, alter, or copy private data.
  • Do not test third-party systems without authorization.
  • No bug bounty is promised unless separately agreed in writing.