Trust is
non-negotiable.
Enterprise-grade security isn't optional. It's built into every layer of Simpledot, from infrastructure to application.
SOC 2 Type II
Our security controls are independently audited under SOC 2 Type II, covering security, availability, and confidentiality. Reports are available to enterprise customers under NDA.
End-to-end encryption
All data is encrypted with AES-256 at rest and TLS 1.3 in transit. Encryption keys are managed through a dedicated key-management service with strict rotation policies.
Zero-trust architecture
Every request is authenticated and authorized at every layer. No implicit trust is granted based on network location — internal services verify identity on each call.
GDPR & HIPAA
We support GDPR data-subject rights and offer HIPAA-compliant handling for healthcare workloads, including Business Associate Agreements for eligible plans.
Certified and continuously audited.
Security built into every layer.
Infrastructure
- Hosted on SOC 2 compliant cloud infrastructure
- Isolated production environments
- Automated backups with point-in-time recovery
Access control
- Role-based access with least privilege
- Mandatory SSO and 2FA for all staff
- Full audit logging of privileged actions
Incident response
- 24/7 monitoring and alerting
- Documented incident response runbooks
- Customer notification within 72 hours
Data handling
- Prompts never used to train our models
- Data deletion on request
- Transparent list of sub-processors
Found a vulnerability? Report it to security@simpledot.in