Security at SimpleAMS

How we protect your data: per-tenant isolation, encryption, access control and EU hosting - with the legal documents to back it up.

Hosting Hetzner Cloud
Region Nuremberg, Germany (EU)
Backups Daily, whole application
Posture reviewed May 2026

Controls in place today

An honest summary of what we run in production. No marketing claims - the same answers we give in security questionnaires.

Per-tenant isolation

Every customer workspace runs in its own dedicated MariaDB database. No shared tables, no cross-tenant queries. A bug in one tenant cannot leak data into another.

Encryption

TLS 1.2+ on every request (HTTPS-only, HSTS enabled). Passwords hashed with bcrypt (cost 12). Integration secrets (API keys, OAuth tokens) encrypted at rest with AES-256 via the Laravel app key.

Access control

Role-based permissions, optional TOTP two-factor auth, Google / SAML / LDAP SSO and SCIM 2.0 provisioning. CSRF on every state-changing route, XSS-safe Blade output, rate-limited login + register + password reset.

EU hosting & daily backups

Application and databases run on Hetzner Cloud in Nuremberg, Germany (EU). Hetzner takes a daily backup of the entire application server, retained per their backup policy. Hetzner data centres are ISO 27001 certified.

Privacy by design

EU GDPR + Bulgarian Personal Data Protection Act compliant. Pre-signed DPA, published subprocessor list, documented GDPR Art. 15-22 rights workflow (30-day response). Customer data is never used to train AI models.

Audit trail & breach SLA

Every create, update, delete, checkout and login recorded in a per-tenant activity log with user, IP and timestamp - exportable for auditors. Personal data breaches notified to affected Controllers within 72 hours per GDPR Art. 33.

Compliance

Where we stand against the standards procurement teams ask about. We do not claim what we do not hold.

Standard / frameworkStatusNotes
EU GDPR Compliant Acting as data processor for customer data. Pre-signed DPA available.
Bulgarian Personal Data Protection Act Compliant Local processor obligations met. Registered with the Commission for Personal Data Protection.
ISO/IEC 27001 (hosting infrastructure) Inherited Hetzner Cloud data centres are ISO 27001 certified. Certificate available on request.
SOC 2 Type I (SimpleAMS) Planned Target: within 12 months. Tooling via Vanta or Drata under evaluation.
ISO/IEC 27001 (SimpleAMS) Planned Target: within 18 months, after SOC 2 Type I.
PCI-DSS Not in scope All payment data is handled exclusively by Stripe (PCI-DSS Level 1). We never see card numbers.

Trusted stack

The vetted suppliers behind the service. Full list and roles at subprocessors.

Hetzner Cloud
Hosting · EU region · ISO 27001
Stripe
Payments · PCI-DSS Level 1 · SOC 2
Anthropic
Claude API for AI assistant · no training on traffic
OpenAI
GPT API for AI assistant · no training on API data
Cloudflare
DNS · TLS termination · DDoS protection