Security at SimpleAMS
How we protect your data: per-tenant isolation, encryption, access control and EU hosting - with the legal documents to back it up.
Controls in place today
An honest summary of what we run in production. No marketing claims - the same answers we give in security questionnaires.
Per-tenant isolation
Every customer workspace runs in its own dedicated MariaDB database. No shared tables, no cross-tenant queries. A bug in one tenant cannot leak data into another.
Encryption
TLS 1.2+ on every request (HTTPS-only, HSTS enabled). Passwords hashed with bcrypt (cost 12). Integration secrets (API keys, OAuth tokens) encrypted at rest with AES-256 via the Laravel app key.
Access control
Role-based permissions, optional TOTP two-factor auth, Google / SAML / LDAP SSO and SCIM 2.0 provisioning. CSRF on every state-changing route, XSS-safe Blade output, rate-limited login + register + password reset.
EU hosting & daily backups
Application and databases run on Hetzner Cloud in Nuremberg, Germany (EU). Hetzner takes a daily backup of the entire application server, retained per their backup policy. Hetzner data centres are ISO 27001 certified.
Privacy by design
EU GDPR + Bulgarian Personal Data Protection Act compliant. Pre-signed DPA, published subprocessor list, documented GDPR Art. 15-22 rights workflow (30-day response). Customer data is never used to train AI models.
Audit trail & breach SLA
Every create, update, delete, checkout and login recorded in a per-tenant activity log with user, IP and timestamp - exportable for auditors. Personal data breaches notified to affected Controllers within 72 hours per GDPR Art. 33.
Compliance
Where we stand against the standards procurement teams ask about. We do not claim what we do not hold.
| Standard / framework | Status | Notes |
|---|---|---|
| EU GDPR | Compliant | Acting as data processor for customer data. Pre-signed DPA available. |
| Bulgarian Personal Data Protection Act | Compliant | Local processor obligations met. Registered with the Commission for Personal Data Protection. |
| ISO/IEC 27001 (hosting infrastructure) | Inherited | Hetzner Cloud data centres are ISO 27001 certified. Certificate available on request. |
| SOC 2 Type I (SimpleAMS) | Planned | Target: within 12 months. Tooling via Vanta or Drata under evaluation. |
| ISO/IEC 27001 (SimpleAMS) | Planned | Target: within 18 months, after SOC 2 Type I. |
| PCI-DSS | Not in scope | All payment data is handled exclusively by Stripe (PCI-DSS Level 1). We never see card numbers. |
Trusted stack
The vetted suppliers behind the service. Full list and roles at subprocessors.
Documents & policies
The agreements and policies behind our security posture.
- Security questionnaireCAIQ Lite, pre-filled. Printable.
- Data Processing (DPA)Pre-signed, GDPR Art. 28, 72-hour breach SLA.
- SubprocessorsSuppliers we share data with.
- Privacy PolicyWhat we collect + GDPR Art. 15-22 process.
- Service Level AgreementUptime and response commitments.
- Billing & Refunds14-day money-back, dunning policy, invoices.
- Acceptable UseWhat is and is not allowed.
- Terms of ServiceCommercial terms.
- Open-Source LicensesThird-party libraries we attribute.
Security questions?
For security or compliance enquiries, or to report a vulnerability, get in touch.
- Security enquiries
- hello@simpleams.co.uk
- Vulnerability reports
- security@simpleams.co.uk
- Response SLA
- 48 hours, business days
- Disclosure window
- 90 days, coordinated