Skip to main content
Skip to main content
Built in Dubai
Sign in
Trust & Security

Your data security is our foundation.

Simplify Your Work FZ-LLC builds enterprise-grade security into every layer of the platform. Aligned with ISO 27001 and SOC 2 standards, with full UAE PDPL compliance built in from day one.

SOC 2 AlignedISO 27001 AlignedUAE PDPL CompliantGDPR ReadyAES-256 Encrypted
Security at a Glance

Numbers that matter

AES-256

Encryption standard

0

Unprotected API routes, out of 2,000+ audited

72h

PDPL breach notification SLA

4

Vetted infrastructure subprocessors

Every one of our 2,000+ API endpoints requires authentication — none were found unprotected. The large majority also enforce session-based role and permission checks (RBAC); the remainder — webhooks, cron triggers, the login flow itself, and similar endpoints that are public or machine-to-machine by design — verify via signature, secret, or token instead, matched to what each endpoint is for.

Encryption at rest and in transit

All data stored in our database is encrypted at rest using AES-256-GCM, the same standard used by financial institutions. Sensitive fields including IP addresses and personally identifiable information receive an additional layer of column-level application encryption with dedicated keys.

Every connection between your browser and our servers is protected by TLS 1.3. Internal service-to-service communication runs over private networking — your database is never exposed to the public internet.

Tenant data isolation

Every organisation on the platform operates in a logically isolated environment. Row-level filtering enforced at the database query layer ensures that one tenant's data is never accessible to another. Every API request, every database query, and every background job is scoped to the authenticated tenant. Over 600 API routes are individually audited for tenant isolation.

Access control & MFA

Multi-factor authentication is available for all users and can be enforced organisation-wide by tenant administrators. MFA supports TOTP, SMS, email OTP, and hardware security keys.

Role-based access control (RBAC) with Owner, Manager, and Employee roles ensures users only access what they need. Platform admin access runs on a separate staff session with its own MFA requirement. Quarterly automated access reviews flag stale accounts, overprivileged users, and API keys due for rotation.

Compliance & governance

Our internal Compliance Center tracks every ISO 27001 Annex A control and SOC 2 Trust Services Criteria with implementation status and evidence links. A formal ISMS policy, risk register with 34 identified risks, and vendor risk assessments are maintained and version-controlled.

Governance documents are reviewed annually and after any significant incident. All policy changes are tracked with full version history.

UAE PDPL & GDPR compliance

Simplify Your Work is designed for full compliance with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection. Automated tools track the 72-hour breach notification deadline, manage data subject requests with 30-day fulfilment tracking, and maintain a Record of Processing Activities (ROPA) per GDPR Article 30.

Data retention policies are enforced automatically — security event logs are purged after the retention period via daily scheduled jobs. Data subject requests (access, correction, deletion, portability) are tracked end-to-end with deadline enforcement.

For details on data handling and your rights, see our Privacy Policy and Data Processing Addendum.

Incident response

Security incidents are classified by severity (P0 Critical through P3 Low) with defined response SLAs. Our incident management system tracks the full lifecycle from detection through containment, eradication, recovery, and post-mortem.

SeverityResponse TimeExample
P0 — Critical15 minutesConfirmed data breach
P1 — High1 hourSuspected unauthorised access
P2 — Medium4 hoursElevated authentication failures
P3 — Low24 hoursBlocked penetration attempt

Vulnerability management

Dependency vulnerabilities are continuously monitored through automated npm audit scans and GitHub Dependabot alerts. Findings are imported into our internal vulnerability tracker with severity-based remediation deadlines — critical vulnerabilities within 7 days, high within 14 days.

All code changes pass through a mandatory CI pipeline including TypeScript strict checking, ESLint security rules, schema validation, and automated test suites before deployment.

Continuous monitoring & audit trail

Every security-relevant event is logged to an immutable audit trail — authentication attempts, admin actions, rate limit breaches, MFA changes, and data exports. PII fields in the audit log are encrypted at the application layer with AES-256-GCM.

A real-time security posture score tracks MFA adoption, open incidents, open vulnerabilities, and event trends across all tenants. Daily automated snapshots provide a 30-day trend view of your platform's security health.

Infrastructure security

The platform runs on SOC 2 certified infrastructure with multiple layers of protection: Cloudflare Web Application Firewall (WAF) with OWASP rule sets blocks common attack vectors at the edge, rate limiting at both CDN and application layers prevents abuse, and DDoS mitigation handles volumetric attacks automatically.

The database is accessible only through private networking — it is never exposed to the public internet. Daily automated backups with 7-day retention support a 24-hour Recovery Point Objective.

Subprocessors

Who handles your data

We use a small number of carefully vetted infrastructure partners. Each operates under contractual data protection obligations with formal Data Processing Agreements on file; SOC 2 certification status varies by vendor — see the table below for each one's status.

SubprocessorRoleData ProcessedLocationCertification (as recorded)
RailwayApplication hosting and databaseTenant application data, database recordsUnited StatesOperates in SOC 2 certified data centers
SentryError monitoring and performanceError stack traces, request metadata (no PII)EU (Frankfurt)Not recorded — see the vendor's own trust page
CloudflareCDN, WAF, DDoS protectionHTTP request headers, IP addresses (transient)Global edge networkNot recorded — see the vendor's own trust page
UpstashRedis cache and rate limitingSession keys, rate-limit counters (no PII)US EastSOC 2 Type II certified
Enterprise Security

Need more details?

We are happy to provide additional documentation for your security review, including our ISMS policy, risk register, SOC 2 control mapping, and vendor assessments. Contact us to discuss your compliance requirements.