footr.

Security & data protection

This is what footr stores, where it lives and who can access it. We describe the boundaries as they are — not as they sound best.

Where the data lives

Storage — Stockholm

All customer data is stored in Supabase in the AWS region eu-north-1 (Stockholm). The region is fixed: it is chosen when the database is created and is never moved by the provider.

Processing — Stockholm

The server functions that handle customer data run in Vercel region arn1 (Stockholm). Employee data is processed in Sweden, not in the US.

Global CDN

Static pages are served from a global CDN and the session check runs in a global edge network — neither sees customer data.

What we store — and what we never store

Stored

  • Signature templates and rules you create in the portal.
  • Your organization name and Microsoft Entra tenant ID.
  • Email address for the portal administrator login.

Never stored

  • Employee details (name, title, department, phone, email) are fetched from Microsoft Graph the moment an email is composed, embedded in the signature and never saved.
  • Group memberships are read per request to select the right rule and never saved.
  • Access tokens for Microsoft exist only in memory for the lifetime of a server instance — never in the database.

Security model

  • The Outlook add-in sends only its Microsoft-issued token. Identity, organization and group membership are derived server-side from the validated token — the client is never trusted.
  • Access to your directory is based on an organization-wide Admin Consent that your administrator can revoke at any time. Revoked consent shuts off all access immediately.
  • Every database query is bound to your organization — signatures and rules cannot be read across organization boundaries.
  • No secrets or passwords are stored in the database.

Sub-processors

footr uses the following providers to run the service:

VercelApplication hosting and operationsFunction region Stockholm (arn1)
SupabaseDatabaseAWS eu-north-1 (Stockholm)
MicrosoftIdentity and directory data — through your own Microsoft 365 tenantGoverned by your Microsoft agreement

GDPR

footr processes personal data as a data processor on behalf of your organization. Employee data is never stored — it is fetched, used and forgotten per email.

When the agreement ends, all of your organization’s templates, rules and account details are permanently deleted, and you revoke our directory access in your own Microsoft environment. Instructions are part of the offboarding.

[GAP: A Data Processing Agreement (DPA) under Article 28 GDPR is being prepared and will form an integral part of the Terms of Service. Until published, a draft is available on request.]

What we do not claim

footr is not ISO 27001 certified and we make no certification claims we cannot back. For customers covered by NIS2, we are prepared to answer supplier questions and provide the documentation required.

Security questions and vulnerabilities

Questions about security or data protection, or reporting a suspected vulnerability: security@footr.app