Security & Privacy

at Simpleem

Security & Privacy

at Simpleem

Security of our customers is the topmost priority – we work hard to maintain the security and integrity of your conversations data.

Security of our customers is the topmost priority – we work hard to maintain the security and integrity of your conversations data.

Security & Privacy

at Simpleem

Security of our customers is the topmost priority – we work hard to maintain the security and integrity of your conversations data.

Tested & Attested by

Simpleem is independently audited and follows industry best practices for data security

Simpleem is independently audited and follows industry best practices for data security

Simpleem is independently audited and follows industry best practices for data security

Core Access Policies

Core Access Policies

Core Access Policies

All our operations follow the guidelines below

1

1

Least Privilege Principle

Least Privilege Principle

Access must be limited to people and systems who have legitimate reasons to have it for business operations.


Access must be limited to people and systems who have legitimate reasons to have it for business operations.

2

2

Secure by Design

Secure by Design

Security is built into the foundation of every feature and system, minimizing the attack surface and preventing unauthorized access.


Security is built into the foundation of every feature and system, minimizing the attack surface and preventing unauthorized access.

3

3

Consistency

Consistency


Security controls should be applied consistently across the whole system, preventing accidental misconfiguration and exposure of sensitive data.

4

4

Recurrence

Recurrence


Security controls and restrictions are revised and monitored 24/7/365 to stay up to date with new attack techniques and react to dangerous signals immediately.

Data Protection

Our customers entrust us with highly sensitive data, so we apply multiple layers of protection to prevent breaches.

1

2

3

At rest

Signal Capture

Signal Capture

All our data storages – S3 buckets and databases – are using securely encrypted storage. This guarantees that even a physical leak of the stored data will not expose any readable decipherable data to an adversary.

All our data storages – S3 buckets and databases – are using securely encrypted storage. This guarantees that even a physical leak of the stored data will not expose any readable decipherable data to an adversary.

In transit

In transit

We employ TLS version1.2 or higher for any data transmission over public/insecure networks. This protects against an attacker who is able to intercept the traffic – they will observe only an indecipherable stream of bytes.

Secrets Storage

Secrets Storage

SSL certificates are managed by AWS Certificate Manager, encryption keys are stored in AWS Key Management System, and all other secrets are contained in AWS Secrets Manager.

Risk Evaluation

Risk Evaluation

We evaluate all dependencies and vendors to identify and prioritize the areas that require the strongest security focus.

Risk Evaluation

Vulnerability Scanning

We scan all production container images and code for known vulnerabilities using Snyk. Scans run with every deployment, ensuring rapid detection of newly disclosed vulnerabilities. We follow a defined remediation process, with actions based on the severity and relevance of each finding.

Supply Chain Security

All software dependencies, including transitive ones, are pinned to a hash. During updates, we review the source code of all new or updated packages to prevent supply chain attacks and malicious code.

Supply Chain Security

All software dependencies, including transitive ones, are pinned to a hash. During updates, we review the source code of all new or updated packages to prevent supply chain attacks and malicious code.

Vendor-Associated Risks

All our decisions related to integration of external vendors are based on initial risk assessment. Inherent risk is determined based on multiple factors, such as the categories of data it can access and the potential impact on Simpleem’s production systems.


Human Resources

Human Resources

Humans are often the weakest part of an otherwise secure system. Here’s why we take it seriously and enforce the following rules.

Human Resources

1

2

3

Onboarding

Signal Capture

Signal Capture

All new engineers complete a mandatory security training covering security aspects of development and explaining security practices and policies enforced at Simpleem.

Training

All Simpleem employees undergo security training annually. Our engineers and other personnel are educated to detect and prevent human-centric attacks like social engineering.

Access Control

Access Control

Microsoft Office 365 serves as our identity management and single sign-on solution. When an employee leaves, their account is immediately deprovisioned and all access is revoked.

Integrate Behavioral Intelligence

Integrate Behavioral Intelligence

Integrate Behavioral Intelligence