Security

Trust is
non-negotiable.

Enterprise-grade security isn't optional. It's built into every layer of Simpledot, from infrastructure to application.

SOC 2 Type II

Our security controls are independently audited under SOC 2 Type II, covering security, availability, and confidentiality. Reports are available to enterprise customers under NDA.

End-to-end encryption

All data is encrypted with AES-256 at rest and TLS 1.3 in transit. Encryption keys are managed through a dedicated key-management service with strict rotation policies.

Zero-trust architecture

Every request is authenticated and authorized at every layer. No implicit trust is granted based on network location — internal services verify identity on each call.

GDPR & HIPAA

We support GDPR data-subject rights and offer HIPAA-compliant handling for healthcare workloads, including Business Associate Agreements for eligible plans.

Compliance

Certified and continuously audited.

SOC 2 Type IIISO 27001HIPAAGDPRCCPA

Security built into every layer.

Infrastructure

  • Hosted on SOC 2 compliant cloud infrastructure
  • Isolated production environments
  • Automated backups with point-in-time recovery

Access control

  • Role-based access with least privilege
  • Mandatory SSO and 2FA for all staff
  • Full audit logging of privileged actions

Incident response

  • 24/7 monitoring and alerting
  • Documented incident response runbooks
  • Customer notification within 72 hours

Data handling

  • Prompts never used to train our models
  • Data deletion on request
  • Transparent list of sub-processors

Found a vulnerability? Report it to security@simpledot.in

Security you can build on.