Security at Simpra

You're trusting us with your compliance program. We don't take that lightly.

Simpra manages your policies, controls, evidence, and risk register — the most sensitive artifacts in your information security program. We run our own security program in Simpra. If it isn't good enough for us, it isn't good enough for you.

SOC 2 AWS Private VPC ISO 27001 Runs on Simpra
Control posture · Simpra
LIVE
Encryption at rest (AES-256, AWS KMS) Enforced
Encryption in transit (TLS 1.2+) Enforced
MFA on all admin accounts Enforced
Dependency vulnerability scanning Automated
Quarterly access reviews On schedule
Agent execution audit log Immutable
Tenant data isolation Enforced
Our posture

We run Simpra on Simpra.

Our internal compliance program — policies, controls, evidence collection, risk register — runs on the same agentic platform we offer customers. When our agents flag a gap in our own program, we fix it. That's not a marketing claim; it's how we caught three control gaps in our first minutes running on our own platform.

How we compare — our own program
Traditional approach
Simpra (us)
Evidence
Manual collection
Agent-collected
Risk register
Quarterly spreadsheet
Living, agent-managed
Audit log
System logs
Compliance artifact
Gap detection
Pre-audit review
Continuous
Human approval
Ad hoc
Platform-enforced
Infrastructure

Private by Architecture, not by Policy.

Simpra's infrastructure runs entirely on AWS inside a private VPC. No public-facing compute. No shared infrastructure between tenants. Every agent runs in an isolated ECS container — the security boundary is architectural, not just configured.

Private VPC, no public compute

All ECS containers run inside a private VPC. No agent or service is directly reachable from the public internet. Traffic routes through controlled ingress only.

Tenant isolation

Each customer's data lives in a logically isolated tenant with row-level security enforced at the database layer. Cross-tenant queries are structurally impossible.

Encryption everywhere

AES-256 at rest via AWS KMS with automated key rotation. TLS 1.2+ in transit. Vector embeddings encrypted at storage. Keys never leave the KMS boundary.

Least-privilege access

RBAC with granular permissions. MFA enforced on all admin accounts. Break-glass access is time-bounded and logged at the audit trail level.

Immutable audit logging

Every platform and agent action is logged with user, timestamp, and change detail. Immutable, retained per your policy, surfaced directly to auditors.

Backups & recovery

Encrypted daily backups with point-in-time recovery. DR tested quarterly against defined RTO and RPO. US and EU data residency, elected at onboarding.

Security Questions Get Answered by Security People

Need more detail? We're happy to share.