Security & trust

Security at SimpleAMS

How we protect your data: per-tenant isolation, encryption, access control and EU hosting - with the legal documents to back it up.

Per-tenant isolation

Every customer workspace runs in its own dedicated database - no shared tables and no cross-tenant access.

Encryption

TLS for all traffic in transit; sensitive secrets encrypted at rest and passwords hashed with bcrypt.

Access control

Role-based permissions, optional two-factor authentication and SSO (Google, SAML, LDAP), CSRF protection and rate-limited logins.

EU hosting & backups

The application and databases are hosted in the European Union, with regular backups.

Privacy by design

EU GDPR and Bulgarian data-protection compliance, a Data Processing Addendum and a published subprocessor list.

Operational security

Least-privilege staff access, activity logging and a responsible-disclosure path for security researchers.

Documents & policies

The agreements and policies behind our security posture.

Compliance

We operate under the EU GDPR and the Bulgarian Personal Data Protection Act. We do not currently hold a SOC 2 or ISO 27001 report; if your procurement process requires one, contact us to discuss scope and timelines.


Security questions?

For security or compliance enquiries, or to report a vulnerability, get in touch.

Contact us