SignetMail docs Open portal →

#Security

SignetMail writes text into every outgoing e-mail, so a compromise would let an attacker add links or content to your company's mail. The system is therefore designed defensively at every layer. This page explains what is built in and what you still have to do.

#Layers of protection

Layer Measures
Network Cloud firewall in front of the server (22 from your IP only, 80, 443) plus firewalld on the host with SSH rate limiting. The API container is not published on the host; only the reverse proxy can reach it.
Host Key-only SSH, no root login, fail2ban, automatic security updates, SELinux enforcing, kernel hardening via sysctl.
Containers All Linux capabilities dropped, no-new-privileges, memory and process limits, log rotation, the application runs as an unprivileged user.
Reverse proxy Automatic HTTPS (Let's Encrypt), HSTS, request bodies limited to 2 MB, Server header hidden, /dev paths blocked, optional IP allow-list for the portal (PORTAL_ALLOWED_IPS).
Application Content Security Policy for the portal (no inline scripts), X-Frame-Options: DENY, nosniff, strict referrer policy, no-store for API responses, rate limiting (600/min per IP, 120/min on public paths), header and body size limits, /health that leaks nothing.
Templates Output is always HTML-encoded; Liquid is sandboxed with step and nesting limits and no ranges; scripts, event handlers and javascript: are rejected; images are PNG/JPEG/GIF by content (no SVG); banner and destination addresses must be https.
Data Database access only through parameterised queries; campaign destinations are stored server-side (no open redirect); statistics are aggregate only.
Identity Entra ID sign-in, certificate (not secret) for Graph, role-based access with an approval step for publishing, immutable version history, audit log of every change.
Backups Encrypted (AES-256) before leaving the server, sent to a private repository with a write-only-to-that-repo deploy key.

#What you must do

These cannot be enforced by the software:

  1. Entra → Enterprise applications → SignetMail → Properties → Assignment required = Yes, and assign only administrators.
  2. Conditional Access: require MFA (and preferably a compliant device) for the SignetMail application.
  3. Grant Graph only User.Read.All, Group.Read.All, GroupMember.Read.All as application permissions; use the certificate, no client secret.
  4. Note the certificate expiry (730 days) and renew in time.
  5. Set PORTAL_ALLOWED_IPS to your office/VPN addresses when administrators work from known places.
  6. Keep the cloud firewall tight: SSH only from your own IP.
  7. Update regularly: sudo docker compose pull && sudo docker compose up -d, and read docker compose logs now and then.
  8. Test your restore at least once on a clean server.
  9. Never run the public server with ASPNETCORE_ENVIRONMENT=Development (it enables header-based dev sign-in and /dev pages).
  10. Use a password manager for the backup passphrase. Without it, backups cannot be opened.
  11. Delete the GitHub token used for docker login after pulling the image, and never paste secrets into chats or tickets.
  12. Keep the number of Owners/Admins small and review the list of people under Access periodically.

#Who can publish what

The publishing workflow is a security control:

  • Editors can change drafts but cannot publish; an Admin reviews the actual preview and publishes with a comment.
  • Campaigns prepared by an Editor are inactive until an Admin approves, and any later Editor change withdraws the approval.
  • Every version is immutable and restorable; every action is in the audit log. If something wrong is published, Disable the signature or restore the previous version.

#Data protection

  • SignetMail stores organization and access data, signature versions, rules, campaign settings and aggregate statistics. The directory itself is read from Entra ID on a schedule; it is not something you have to back up.
  • Campaign statistics contain no personal data of recipients (see Campaigns).
  • Logs contain technical request information; they are rotated and not shipped anywhere by default.
  • Document SignetMail in your record of processing activities and, if you operate it for other companies, agree a data-processing agreement with them.

#Reporting a vulnerability

If you find a security issue, do not open a public issue. Contact the maintainers privately (see the project repository) with steps to reproduce.

SignetMail documentation · version main