simplcity
01

Least access

Users receive role and project access appropriate to their responsibilities.

02

Source trust

Original evidence, derived knowledge, review state, and gaps remain meaningfully distinct.

03

Private operations

Administrative, project, monitoring, and API surfaces are authenticated and excluded from search indexing.

Current application controls

Layered protection without public architecture disclosure.

This page describes control outcomes, not sensitive implementation details.

Transport and browser protection

HTTPS, HSTS, a restrictive Content Security Policy, frame denial, MIME sniffing protection, limited browser permissions, and a no-referrer policy reduce common browser and transport risks.

Authentication and sessions

Authenticated access uses signed, time-limited sessions with HttpOnly, Secure on HTTPS, and SameSite cookie protections. Sign-in attempts are rate limited.

Authorization

Role-based permissions and customer-project scoping restrict access to administrative functions, project data, review actions, monitors, health views, and agent endpoints.

Request integrity

State-changing browser requests require CSRF validation. Origin and proxy-aware checks protect the canonical production boundary.

Secrets and APIs

Service credentials and agent tokens remain server-side. Public forms and browser storage do not expose raw operational secrets.

Audit and error handling

Security-relevant events are recorded with sensitive values redacted. User-facing errors avoid returning backend credentials or detailed internals.

Search and domain controls

The canonical domain is enforced, the retired hosting hostname is disabled, and private routes receive explicit noindex protection.

Quality and deployment checks

Regression tests, deployment fingerprint verification, health reporting, and worker monitoring help detect unsafe or incomplete changes.

Responsible disclosure

Found a security issue?

Email jason@simplsolutions.app with the affected URL, a clear description, reproduction steps, and potential impact. Do not include unnecessary personal data or credentials.

Please avoid
  • Accessing or changing data that is not yours.
  • Disrupting service availability or worker operations.
  • Social engineering, spam, or physical testing.
  • Public disclosure before we have had a reasonable opportunity to investigate and remediate.

We will acknowledge good-faith reports and coordinate next steps. This statement does not create a paid bug bounty or authorize testing beyond applicable law.

Security and privacy questions

Talk directly with SimplSolutions.

Contact us