Least access
Users receive role and project access appropriate to their responsibilities.
Public information about the controls used to protect simplcity accounts, projects, operations, and customer data.
Last reviewed July 15, 2026Users receive role and project access appropriate to their responsibilities.
Original evidence, derived knowledge, review state, and gaps remain meaningfully distinct.
Administrative, project, monitoring, and API surfaces are authenticated and excluded from search indexing.
This page describes control outcomes, not sensitive implementation details.
HTTPS, HSTS, a restrictive Content Security Policy, frame denial, MIME sniffing protection, limited browser permissions, and a no-referrer policy reduce common browser and transport risks.
Authenticated access uses signed, time-limited sessions with HttpOnly, Secure on HTTPS, and SameSite cookie protections. Sign-in attempts are rate limited.
Role-based permissions and customer-project scoping restrict access to administrative functions, project data, review actions, monitors, health views, and agent endpoints.
State-changing browser requests require CSRF validation. Origin and proxy-aware checks protect the canonical production boundary.
Service credentials and agent tokens remain server-side. Public forms and browser storage do not expose raw operational secrets.
Security-relevant events are recorded with sensitive values redacted. User-facing errors avoid returning backend credentials or detailed internals.
The canonical domain is enforced, the retired hosting hostname is disabled, and private routes receive explicit noindex protection.
Regression tests, deployment fingerprint verification, health reporting, and worker monitoring help detect unsafe or incomplete changes.
Email jason@simplsolutions.app with the affected URL, a clear description, reproduction steps, and potential impact. Do not include unnecessary personal data or credentials.
We will acknowledge good-faith reports and coordinate next steps. This statement does not create a paid bug bounty or authorize testing beyond applicable law.