All our data storages – S3 buckets and databases – are using securely encrypted storage. This guarantees that even a physical leak of the stored data will not expose any readable decipherable data to an adversary.
We employ TLS version1.2 or higher for any data transmission over public/insecure networks. This protects against an attacker who is able to intercept the traffic – they will observe only an indecipherable stream of bytes.
SSL certificates are managed by AWS Certificate Manager, encryption keys are stored in AWS Key Management System, and all other secrets are contained in AWS Secrets Manager.
Onboarding
All new engineers complete a mandatory security training covering security aspects of development and explaining security practices and policies enforced at Simpleem
Training
All Simpleem employees undergo security training annually. Our engineers and other personnel are educated to detect and prevent human-centric attacks like social engineering
Access Management
We use Microsoft Office 365 as an identity management solution and single sign-on on other platforms. Such accounts are deprovisioned upon employee termination, and any access granted to them is revoked immediately