Your data security is our foundation.
Simplify Your Work FZ-LLC builds enterprise-grade security into every layer of the platform. Aligned with ISO 27001 and SOC 2 standards, with full UAE PDPL compliance built in from day one.
Numbers that matter
AES-256
Encryption standard
0
Unprotected API routes, out of 2,000+ audited
72h
PDPL breach notification SLA
4
Vetted infrastructure subprocessors
Every one of our 2,000+ API endpoints requires authentication — none were found unprotected. The large majority also enforce session-based role and permission checks (RBAC); the remainder — webhooks, cron triggers, the login flow itself, and similar endpoints that are public or machine-to-machine by design — verify via signature, secret, or token instead, matched to what each endpoint is for.
Encryption at rest and in transit
All data stored in our database is encrypted at rest using AES-256-GCM, the same standard used by financial institutions. Sensitive fields including IP addresses and personally identifiable information receive an additional layer of column-level application encryption with dedicated keys.
Every connection between your browser and our servers is protected by TLS 1.3. Internal service-to-service communication runs over private networking — your database is never exposed to the public internet.
Tenant data isolation
Every organisation on the platform operates in a logically isolated environment. Row-level filtering enforced at the database query layer ensures that one tenant's data is never accessible to another. Every API request, every database query, and every background job is scoped to the authenticated tenant. Over 600 API routes are individually audited for tenant isolation.
Access control & MFA
Multi-factor authentication is available for all users and can be enforced organisation-wide by tenant administrators. MFA supports TOTP, SMS, email OTP, and hardware security keys.
Role-based access control (RBAC) with Owner, Manager, and Employee roles ensures users only access what they need. Platform admin access runs on a separate staff session with its own MFA requirement. Quarterly automated access reviews flag stale accounts, overprivileged users, and API keys due for rotation.
Compliance & governance
Our internal Compliance Center tracks every ISO 27001 Annex A control and SOC 2 Trust Services Criteria with implementation status and evidence links. A formal ISMS policy, risk register with 34 identified risks, and vendor risk assessments are maintained and version-controlled.
Governance documents are reviewed annually and after any significant incident. All policy changes are tracked with full version history.
UAE PDPL & GDPR compliance
Simplify Your Work is designed for full compliance with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection. Automated tools track the 72-hour breach notification deadline, manage data subject requests with 30-day fulfilment tracking, and maintain a Record of Processing Activities (ROPA) per GDPR Article 30.
Data retention policies are enforced automatically — security event logs are purged after the retention period via daily scheduled jobs. Data subject requests (access, correction, deletion, portability) are tracked end-to-end with deadline enforcement.
For details on data handling and your rights, see our Privacy Policy and Data Processing Addendum.
Incident response
Security incidents are classified by severity (P0 Critical through P3 Low) with defined response SLAs. Our incident management system tracks the full lifecycle from detection through containment, eradication, recovery, and post-mortem.
| Severity | Response Time | Example |
|---|---|---|
| P0 — Critical | 15 minutes | Confirmed data breach |
| P1 — High | 1 hour | Suspected unauthorised access |
| P2 — Medium | 4 hours | Elevated authentication failures |
| P3 — Low | 24 hours | Blocked penetration attempt |
Vulnerability management
Dependency vulnerabilities are continuously monitored through automated npm audit scans and GitHub Dependabot alerts. Findings are imported into our internal vulnerability tracker with severity-based remediation deadlines — critical vulnerabilities within 7 days, high within 14 days.
All code changes pass through a mandatory CI pipeline including TypeScript strict checking, ESLint security rules, schema validation, and automated test suites before deployment.
Continuous monitoring & audit trail
Every security-relevant event is logged to an immutable audit trail — authentication attempts, admin actions, rate limit breaches, MFA changes, and data exports. PII fields in the audit log are encrypted at the application layer with AES-256-GCM.
A real-time security posture score tracks MFA adoption, open incidents, open vulnerabilities, and event trends across all tenants. Daily automated snapshots provide a 30-day trend view of your platform's security health.
Infrastructure security
The platform runs on SOC 2 certified infrastructure with multiple layers of protection: Cloudflare Web Application Firewall (WAF) with OWASP rule sets blocks common attack vectors at the edge, rate limiting at both CDN and application layers prevents abuse, and DDoS mitigation handles volumetric attacks automatically.
The database is accessible only through private networking — it is never exposed to the public internet. Daily automated backups with 7-day retention support a 24-hour Recovery Point Objective.
Who handles your data
We use a small number of carefully vetted infrastructure partners. Each operates under contractual data protection obligations with formal Data Processing Agreements on file; SOC 2 certification status varies by vendor — see the table below for each one's status.
| Subprocessor | Role | Data Processed | Location | Certification (as recorded) |
|---|---|---|---|---|
| Railway | Application hosting and database | Tenant application data, database records | United States | Operates in SOC 2 certified data centers |
| Sentry | Error monitoring and performance | Error stack traces, request metadata (no PII) | EU (Frankfurt) | Not recorded — see the vendor's own trust page |
| Cloudflare | CDN, WAF, DDoS protection | HTTP request headers, IP addresses (transient) | Global edge network | Not recorded — see the vendor's own trust page |
| Upstash | Redis cache and rate limiting | Session keys, rate-limit counters (no PII) | US East | SOC 2 Type II certified |
Need more details?
We are happy to provide additional documentation for your security review, including our ISMS policy, risk register, SOC 2 control mapping, and vendor assessments. Contact us to discuss your compliance requirements.