Security at Simpra

Security built into how Simpra operates.

Simpra is designed to protect the policies, controls, evidence, and risk data that power your compliance program. Our infrastructure, access controls, encryption, and audit logging are built with security from the start.

Private VPC Encryption Audit Logging Tenant Isolation
Control posture · Simpra
LIVE
Encryption at rest (AES-256, AWS KMS) Enforced
Encryption in transit (TLS 1.2+) Enforced
MFA on all admin accounts Enforced
Dependency vulnerability scanning Automated
Quarterly access reviews On schedule
Agent execution audit log Immutable
Tenant data isolation Enforced
Infrastructure

Private by architecture, not just by policy.

Simpra is built on secure cloud infrastructure with encryption, tenant isolation, audit logging, and least-privilege access to protect your compliance data from day one.

Data Protection

Encryption everywhere

Customer data is encrypted at rest using AES-256 and in transit using TLS.

Tenant isolation

Customer data is logically isolated with tenant-level access controls.

Platform Security

Private VPC

Simpra runs inside a private AWS VPC with controlled network access and no unnecessary public exposure.

Least-privilege access

Role-based access controls ensure users only have access to the systems and data they need.

Operational Resilience

Audit logging

Platform and agent activity is logged with user, timestamp, and change history.

Backups & recovery

Encrypted backups and recovery procedures help protect against data loss and support business continuity.

Need more detail? We're happy to help.