Tested & Attested by
All our operations follow the guidelines below
Security controls should be applied consistently across the whole system, preventing accidental misconfiguration and exposure of sensitive data.
Security controls and restrictions are revised and monitored 24/7/365 to stay up to date with new attack techniques and react to dangerous signals immediately.
Data Protection
Our customers entrust us with highly sensitive data, so we apply multiple layers of protection to prevent breaches.
1
2
3
We employ TLS version1.2 or higher for any data transmission over public/insecure networks. This protects against an attacker who is able to intercept the traffic – they will observe only an indecipherable stream of bytes.
SSL certificates are managed by AWS Certificate Manager, encryption keys are stored in AWS Key Management System, and all other secrets are contained in AWS Secrets Manager.
We evaluate all dependencies and vendors to identify and prioritize the areas that require the strongest security focus.

Vulnerability Scanning
We scan all production container images and code for known vulnerabilities using Snyk. Scans run with every deployment, ensuring rapid detection of newly disclosed vulnerabilities. We follow a defined remediation process, with actions based on the severity and relevance of each finding.

Vendor-Associated Risks
All our decisions related to integration of external vendors are based on initial risk assessment. Inherent risk is determined based on multiple factors, such as the categories of data it can access and the potential impact on Simpleem’s production systems.
Humans are often the weakest part of an otherwise secure system. Here’s why we take it seriously and enforce the following rules.
1
2
3
All new engineers complete a mandatory security training covering security aspects of development and explaining security practices and policies enforced at Simpleem.
Training
All Simpleem employees undergo security training annually. Our engineers and other personnel are educated to detect and prevent human-centric attacks like social engineering.
Microsoft Office 365 serves as our identity management and single sign-on solution. When an employee leaves, their account is immediately deprovisioned and all access is revoked.












