Skip to content
Every

Every contract protected.
Every access controlled.

Each organisation's data stays separate, with three permission levels, secure sessions, single sign on, and lockout.

Every
How it works

From organisation isolation to document protection in 4 steps

Data stays separate per organisation, sign in is protected, roles control access, tampering is flagged.

1

Data Isolation

Each organisation's data stays separate

Every organisation operates in its own isolated space. Contracts, templates, signers, audit trails, and reports for one cannot be seen by another. The separation is built into the foundation, not configurable rules.

  • Strict Isolation
  • Per Organisation
  • No Cross Access
  • Built In
2

Sign In Protection

Sign in protected by multiple layers

Secure sessions protect every signed in user from forged requests and session hijacking. Single sign on lets the team use the company's existing identity system. Automatic lockout stops guess attacks after repeated failures.

  • Secure Sessions
  • Single Sign On
  • Auto Lockout
  • Multiple Layers
3

Role Permissions

Permissions control what each role can see

Three permission levels match real teams. Admin has full control over settings and data. Manager can create, send, and manage contracts but not change organisation settings. Viewer can see assigned contracts but not modify anything.

  • Admin · Manager
  • Viewer
  • Matched To Role
  • No Over Access
4

Document Protection

Document fingerprinting catches tampering

When a document is signed, the platform creates a unique fingerprint from its exact contents. Any later change, even one character, gives a different fingerprint. Throttling slows unusual access, and consistent timing hides information.

  • Document Fingerprint
  • Activity Throttling
  • Consistent Timing
  • Layered Protection
Why Teams Choose SIGI

Six reasons security reviews actually pass

Organisation isolation, three permission levels, single sign on, automatic lockout, document fingerprinting, activity throttling.

Organisation data isolation prevents cross team leaks

Organisation data isolation prevents cross team leaks

A platform shared by many organisations must keep each one's data fully separate. Strict isolation means contracts are never visible to another.

Three permission levels match real team structures

Three permission levels match real team structures

Admin, manager, viewer cover the access patterns real teams need. Junior members get viewer access, senior members manage workflows, only admins control organisation settings.

Single sign on works with the company's existing identity

Single sign on works with the company's existing identity

Teams using a company identity system shouldn't keep separate passwords per tool. Single sign on lets members use one identity, managed centrally.

Automatic lockout stops repeated guess attempts

Automatic lockout stops repeated guess attempts

Repeated failed sign in attempts from the same source trigger automatic lockout, so the attacker can't keep guessing. The legitimate user gets a clear path to recover access.

Document fingerprinting protects signed contracts

Document fingerprinting protects signed contracts

A signed contract quietly changed later defeats the purpose. Fingerprinting creates a unique pattern at signature that matches only the original.

Suspicious activity throttling catches patterns early

Suspicious activity throttling catches patterns early

Attackers often probe systems with high volume requests. Activity throttling slows unusual patterns, and consistent timing leaks nothing usable.

Who uses SIGI security & access control
Deepak MehrotraDeepak MehrotraDeepak MehrotraDeepak Mehrotra

13200+

Teams running on platform security their reviewers actually approve

Built for teams whose security and compliance reviews are not negotiable

Security teams evaluating the platform who need real controls, not claims. Compliance teams verifying controls for audit and procurement. IT teams managing access and sign in flows. Legal ops leads responsible for data protection.

Organisation

Isolation Strict

3 Permission

Levels

Single Sign On

Supported

Document

Fingerprint Active

Access Layer

Organisation isolation, role permissions, secure sign in

Each organisation's data fully separated. Three permission levels (admin, manager, viewer) match real teams. Secure sessions protect signed in users, and single sign on integrates with the existing identity system.

Features

Everything the security layer ships with

Organisation isolation, three permission levels, secure sign in and SSO, lockout, fingerprinting, throttling.

Organisation Data Isolation

Each organisation operates in its own isolated space. Contracts, templates, and reports cannot be accessed by another.

Three Permission Levels

Admin controls all settings and data. Manager can create, send, and manage contracts but not settings. Viewer can see, not modify.

Secure Sign In and Single Sign On

Secure sessions protect every signed in user from forged requests and hijacking. Single sign on uses the company's identity system.

Automatic Lockout After Failed Attempts

Repeated failed sign in attempts from the same source trigger automatic lockout, so guessing stops. The user gets a clear path back.

Document Fingerprinting

At signature, the platform creates a unique fingerprint from the exact contents. Any later change, even one character, is revealed.

Suspicious Activity Throttling

Unusual access patterns get automatically slowed, making attacks impractical and giving security teams time to investigate.

Questions & Answers

Everything you need to know

Common questions on organisation isolation, permission levels, SSO, lockout, and fingerprinting.

Every organisation operates in its own isolated space. Contracts, templates, signers, audit trails, reports, and every other data type are tagged to a specific organisation at creation. The data layer refuses to return any data tagged to a different organisation than the requesting user's. This separation is built into the foundation rather than enforced through rules that could be misconfigured, so cross organisation access is structurally impossible.
Three levels cover the access patterns real teams need. Admin has full control over organisation settings, billing, team membership, integrations, and all contracts. Manager can create, send, and manage contracts, templates, and workflows but cannot change organisation settings. Viewer can see contracts they have been granted access to but cannot create, modify, or share anything. Each member's level matches their actual responsibility.
The platform integrates with the company's existing identity system, so members sign in with the same identity they use everywhere else. The identity team configures the connection during onboarding, after which signing in routes through the company's provider. Access is managed centrally, so when someone leaves and is removed from the identity system, they automatically lose access to the platform without anyone revoking it separately.
Multiple failed sign in attempts from the same source within a short window. The threshold balances security with usability. Three or four failures is normal because users mistype passwords. A burst well beyond that is almost certainly a guess attack. Lockout temporarily blocks further attempts from that source while the legitimate user recovers access through verified email or the identity system. It stops guessing without locking out users for normal mistakes.
At the moment of signature, the platform creates a unique fingerprint from the exact contents of the document, stored alongside it. Any later change, even a single character, gives a completely different fingerprint. Comparing the stored fingerprint to a current calculation reveals tampering instantly. A signed contract that gets quietly modified cannot pass the check, so the team and any auditor can verify it is exactly as signed.
Attackers can sometimes learn information from how long a system takes to respond. A sign in for a real user might take slightly longer than one for a non-existent user, revealing which usernames exist. The platform deliberately makes responses take the same time regardless of the outcome, so attackers cannot extract information by comparing response times. This subtle protection matters for serious reviews and rules out a class of attack.
Sigi · AI documents and e-signature

Sigi drafts, sends, and gets it signed without the chasing.

Turn a contract into a signed, audited document in minutes while AI flags risky clauses before they reach your signer.

5 min
average time to signed
0
risky clauses missed
100%
documents with audit trail
6
signing workflows supported
Worksbuddy© 2026 Worksbuddy