1. Parties and acceptance
These Terms of Service govern access to and use of the Signet7 software, websites, dashboards, verification services, provider integrations, evidence records, documentation, and related services (the “Services”).
The provider will be the formed legal entity identified in an applicable order form or activation record (“Signet7,” “Provider,” “we,” “us,” or “our”). The customer is the person or entity identified there (“Customer,” “you,” or “your”). Provider’s legal name, jurisdiction, business address, and formal-notice contact must be inserted before these Terms can become operative.
An individual accepting for an organization represents that the individual is at least 18 and authorized to bind it. A technician, mailbox user, recipient, or integration provider does not bind Customer unless designated as an authorized administrator.
The operative agreement will include the executed order form or activation record, these Terms, approved privacy/data-processing, security, support, and acceptable-use schedules, and any incorporated addendum. The order form controls customer-specific selections.
The Services may record the version, date, tenant, accepting administrator, and timestamp of electronic acceptance. That record shows the submitted acceptance event; it does not independently prove legal authority.
2. Services and automated operation
Signet7 evaluates supported cryptographic, sender/key, lifecycle, coverage, timing, replay, and protected-message-component evidence associated with consequential email.
After Customer’s authorized setup, the configured Services may monitor selected Google Workspace or Microsoft 365 mailboxes, fetch provider data needed for verification, retry temporary failures, classify results, retain content-minimized evidence history, apply labels or categories, push material notices, and provide a dashboard for history, warnings, integration health, evidence, acknowledgements, reports, and configuration.
Normal, adequately verified results are intended to remain quiet. Routine protection is not intended to require an administrator to watch the dashboard or a recipient to approve every normal message.
The Services are limited to the programs, tenants, mailboxes, integrations, volumes, retention settings, and support expressly authorized in the applicable order form or activation record.
3. Evidence limits
A Signet7 result is an evidence result—not a universal safety, fraud, truth, legal, or payment verdict.
A successful supported check may establish that covered message components match the signed representation and that reported sender/key and lifecycle checks produced the stated result. It does not establish that a message, sender, invoice, attachment, link, bank account, payment instruction, contract, request, or transaction is honest, accurate, authorized, lawful, malware-free, confidential, or prudent.
Unknown, unsealed, unsupported, expired, revoked, incomplete, or temporarily unavailable does not by itself establish fraud or malicious intent.
A dashboard acknowledgement, dismissal, hold, report, or confirmation records a Customer declaration. It does not perform or prove an action in a bank, accounting platform, ERP, payment system, email provider, or other external system. External execution may be described only when the responsible external system supplies a trustworthy receipt bound to the event.
4. Installation and administrator authorization
Initial installation may require administrator work, OAuth or tenant consent, provider application registration, mailbox selection, webhook or subscription configuration, service-account or application authorization, label/category provisioning, policy selection, and secure credential storage.
Customer authorizes access only to the tenants, mailboxes, provider resources, and data categories selected during installation. Customer must obtain its required organizational approvals, notices, permissions, and user communications.
Customer will review requested provider permissions, select the minimum practical scope, protect administrator and integration credentials, maintain current escalation contacts, and remove access when authority ends. Credentials must not be sent through ordinary email or support fields not designed for secrets.
5. Notices and warning fatigue
Provider notifications can be delayed, duplicated, omitted, reordered, or temporarily unavailable. Signet7 may reconcile provider history or delta state and retry processing.
- Supported evidence verified: quiet history.
- No Signet7 evidence: normally no interruption or a neutral marker.
- Temporary failure: automatic retry and, when material, a caution.
- Incomplete, unsupported, or unresolved evidence: visible caution.
- Protected-content mismatch, invalid signature, adverse key lifecycle state, or material replay condition: visible warning.
No automated system eliminates false positives, false negatives, unsupported content, provider failures, configuration errors, or user error.
6. Customer responsibilities
Customer will use the Services only for authorized, lawful business purposes; maintain ordinary email, endpoint, identity, recovery, fraud-prevention, callback, dual-control, and business-approval controls; independently confirm unusual or consequential requests through a known channel; and decide whether an external system should hold, approve, reject, or execute an action.
Customer is responsible for authorized users, accurate configuration, protection of exported evidence, custody after export, and retention, legal-hold, disclosure, and deletion decisions for systems it controls.
7. Customer data, evidence, and privacy
Customer retains its rights in Customer data. Customer grants Provider a limited right to process Customer data only as necessary to provide, secure, support, and improve the contracted Services, follow documented instructions, and meet applicable legal obligations.
The default background design stores content-minimized evidence rather than complete readable email. Records may include protected mailbox and provider-message identifiers, content fingerprints, provider name, state and reason codes, selected verification facts, timestamps, acknowledgements, and signed or hash-chained ledger information.
Readable message bodies and attachments are intended to remain in Customer-controlled mailboxes unless Customer separately authorizes a complete-content vault. Any such vault must be encrypted, access-controlled, retention-governed, and expressly approved. It is not included by default.
Provider access tokens, refresh tokens, client secrets, private keys, and passwords must not be written into evidence history or ordinary logs. Pseudonymized identifiers may remain linkable and are not represented as anonymous merely because transformed.
Data roles, purposes, locations, subprocessors, transfers, security, rights support, retention, return, deletion, incident handling, and legal holds must be stated in approved privacy/data-processing and security schedules before production processing. Review the current privacy status.
8. Third-party services
The Services may interoperate with Google Workspace, Gmail, Microsoft 365, Microsoft Graph, banks, accounting platforms, ERPs, payment providers, and cloud infrastructure. Third-party systems have their own terms, permissions, availability, security, and data practices.
Provider does not control third-party outages, delays, transformations, authorization changes, suspensions, or execution records. An integration does not make Provider the operator of the third party’s system or make the third party a guarantor or endorser of Signet7.
9. Accounts and security
Customer will protect credentials, use available multifactor authentication, maintain current administrator and recovery contacts, and promptly report suspected unauthorized access.
Provider may take proportionate emergency measures to protect the Services, Customer data, other customers, or third parties. Final suspension, notice, review, restoration, and security commitments must be stated in approved operative schedules.
Source code, tests, local demonstrations, authored controls, or cloud-service eligibility are not certifications, warranties, or proof of production deployment.
10. Programs, fees, billing, renewal, and cancellation
Program names, included capabilities, limits, fair-use thresholds, fees, billing period, taxes, renewal, cancellation, grace, suspension, refunds, credits, disputes, and invoice terms are controlled only by an executed order form and approved billing disclosures.
No public page, source file, demonstration, test checkout, or unactivated record creates a charge, subscription, refund promise, automatic renewal, or commercial offer.
A free recipient-verification path remains subject to reasonable technical, security, cost, and abuse controls and creates no uptime, support, preservation, or continued-availability commitment unless expressly stated.
11. License, intellectual property, feedback, and acceptable use
Subject to the operative agreement, Provider grants Customer a limited, non-exclusive, non-transferable, non-sublicensable, revocable right during the term to use the Services for authorized internal business purposes.
Provider and its licensors retain rights in the Services, software, protocols, documentation, designs, marks, and service-generated improvements, subject to third-party and open-source licenses. Customer retains rights in Customer data and Customer marks.
Publicly licensed source code remains governed by its applicable license. These Terms do not narrow rights granted by that license.
Voluntary feedback may be used to improve the Services without publicly identifying Customer. This does not transfer Customer data, confidential information, or Customer inventions.
Customer must not use the Services unlawfully; enroll a sender, domain, mailbox, key, organization, or tenant without authority; forge or misrepresent evidence or warnings; represent a result as universal safety or fraud proof; bypass controls; distribute malicious content; access another tenant; conduct unauthorized probing or extraction; or use the Services for solely automated legally significant decisions without a separately established lawful process.
12. Confidentiality
Each party will protect the other’s non-public information using at least reasonable care and use it only to perform or receive the Services. Standard exclusions apply for information lawfully known, independently developed, publicly available without breach, or lawfully received without duty.
Compelled disclosure, duration, return or destruction, remedies, and heightened handling rules must be completed in the operative agreement.
13. Changes, availability, and support
Provider may update the Services for functionality, security, compatibility, or legal compliance. Material reductions, deprecation notice, migration support, service levels, maintenance windows, response targets, and credits must be stated in the order form or support schedule.
The Services may be interrupted by maintenance, provider outages, network failure, subscription expiration, authorization revocation, Customer configuration, unsupported content, attacks, or events beyond Provider’s reasonable control.
No service level, delivery guarantee, warning-delivery guarantee, recovery objective, or support response commitment exists unless expressly stated in an approved operative schedule.
14. Warranties, liability, and indemnity
The operative agreement must identify any express service warranty and exclusive remedy. Except for an express warranty there and to the fullest extent permitted by law, the Services will be provided “as is” and “as available,” with implied warranties disclaimed where legally permitted.
Provider does not warrant uninterrupted or error-free operation; detection of every alteration, replay, identity problem, provider failure, or malicious message; prevention of fraud or loss; preservation of every message; satisfaction of every legal or audit requirement; or action by an external person or system.
The liability cap, cap period, excluded damages, special-risk carve-outs, indemnities, defense process, and insurance requirements remain unresolved business and legal decisions. No draft or local candidate establishes them.
15. Term, suspension, and termination
The term begins only as stated in an executed order form. Subscription cancellation, cure periods, suspension, termination, end-of-service export, return, deletion, backup treatment, verification continuity, and surviving provisions must be stated in the operative agreement.
Records subject to a valid legal hold or legal obligation may be preserved only under an approved retention and hold process.
16. Compliance and electronic records
Each party is responsible for laws applicable to its own conduct. No general privacy, healthcare, financial, securities, public-sector, records, artificial-intelligence, evidentiary, or industry-specific compliance representation is made unless an executed schedule identifies the exact role, scope, control, and evidence.
Electronic records and signatures may be used where legally effective. A technical event record can support history but does not by itself establish identity, authority, intent, attribution, admissibility, or truth.
17. Governing law, disputes, and general terms
Governing law, venue, informal dispute process, arbitration or court process, class or representative treatment, limitation periods, injunctive relief, and fees remain decisions for the formed Provider. Founder or pre-formation agreements do not automatically govern customer contracts.
The final agreement must also address assignment, subcontracting, force majeure, notices, publicity, audit, conflict, severability, waiver, third-party beneficiaries, relationship of the parties, counterparts, and entire agreement.
Updating a web page must not retroactively alter an executed order form or avoid a contractual notice obligation.
18. Contact and formal notices
The formed Provider’s legal name, jurisdiction, business address, formal-notice email, privacy contact, security contact, and support channel must be inserted before activation.
Until then, founder and design-partner email addresses are discussion channels only and are not formal legal-notice addresses.