Security at Simplae
Security at Simplae
Trust matters when customer conversations flow through your business. This page explains how Simplae protects your data in plain language — no engineering degree required.
Our commitments
- Encryption in transit — web and API traffic uses modern TLS (HTTPS).
- Encryption at rest — sensitive stored data is protected using industry-standard encryption from our infrastructure providers.
- Backups — production data is backed up on a regular schedule so we can recover from hardware or software failures.
- Access controls — Simplae staff access production systems on a need-to-know basis with logging.
- Secure development — code changes are reviewed and monitored before they reach production.
- Vendor diligence — hosting, SMS, email, and payment partners are vetted for security practices.
Authentication
You sign in with email and password. We support session security best practices and encourage a strong, unique password.
What you can do: use a strong password and sign out on shared devices.
Authorization
Simplae accounts are single-owner today — one login per business, with full access to that business's conversations, knowledge, and billing.
Tenant isolation
Each business account is logically separated. Your knowledge, conversations, and settings belong to your organization — other customers cannot access them through the product.
Data ownership
You own the content you upload and the customer messages your business handles. We process that content only to operate the service you subscribed to, as described in our Privacy Policy.
Data deletion
When you close an account or request deletion, we remove or anonymize data according to our retention policies and legal obligations. Some records (such as invoices or abuse-prevention logs) may be kept for a limited time where required by law.
To request deletion, contact support@simplae.com.
Infrastructure
Simplae runs on modern cloud infrastructure with redundancy, automated deployments, and environment separation between development and production. We do not run your data on employee laptops.
Monitoring
We monitor production systems for errors, unusual traffic, and security events. Alerts help our team respond quickly to incidents.
Vulnerability reporting
If you discover a security issue affecting Simplae, we want to hear from you. Please report it responsibly — do not test against other customers' accounts or data.
How to report: email support@simplae.com with subject line "Security report" and enough detail for us to reproduce the issue.
Responsible disclosure
We appreciate researchers and customers who give us time to fix issues before public disclosure. We will acknowledge reports, investigate promptly, and notify affected customers when required by law or contract.
Your account security
- Use a unique, strong password.
- Do not share your login or verification codes.
Data you control
You choose what knowledge to upload. Avoid putting full credit card numbers, government IDs, or medical records into knowledge unless you have a compliant reason and safeguards.
Incident response
If we detect a security issue affecting customers, we will investigate, mitigate, and notify affected accounts as required by law and contract.
Compliance support
Industry-specific regimes (HIPAA, PCI, etc.) may require additional agreements — contact support before relying on Simplae for regulated use cases.
Questions?
Visit Contact for security or privacy questions. Read our Privacy Policy and documentation for product setup help.