Security FAQ

Simple Marketing Solutions delivers its products through a Software as a Service (SaaS) model. Security and data residency are among the first questions our customers' procurement and risk teams ask, so we have set out our answers here in full.

The answers below describe the Simple platform that underpins Simple Admation, Simple Asset Manager, Simple RetailPath and Simple Brand Manager. Where a product differs, we say so. If your security questionnaire asks something this page does not cover, contact us and we will answer it directly.

Application Hosting and Availability

Where is Simple hosted? 

Simple is hosted on dedicated infrastructure in NextDC data centres in Melbourne, Australia. Our production site is certified to Uptime Institute Tier III standards. Access to the facility requires two-factor biometric fingerprint entry with IDAC, and the site is intruder resistant with 24/7 security and CCTV. Further detail on the specific facilities is available on request. 

Does customer data leave Australia? 

No. All customer data is hosted, stored and backed up in Australia, on infrastructure Simple owns and controls. Production and disaster recovery are both in Melbourne, and replication between them runs over a private connection that stays within the country. Simple operates no offshore data centres, holds no offshore backups and uses no offshore sub-processors. Customer data is not replicated, stored or archived outside Australia at any point. 

Does Simple use sub-processors or other third parties? 

No. Simple has no data sub-processors. The only third parties involved in delivering the platform are our data centre provider, NextDC, which hosts our production and disaster recovery sites, and Telstra, which provides our internet access and cyber security infrastructure. Simple does not use subcontractors. 

Does Simple have a backup site? 

Yes. Our disaster recovery site is a second NextDC facility in Melbourne, in a separate location on a separate power grid, certified to Uptime Institute Tier IV standards. Production and disaster recovery are connected by a secure 1Gb private connection. Our disaster recovery procedure is tested annually. 

Is my data backed up? 

Yes. Simple uses a real-time backup strategy. Production databases are replicated continuously to the disaster recovery site across a secure 1Gb private connection, and files are copied across on upload. This allows us to switch to disaster recovery with minimal or no data loss. 

What are Simple’s recovery objectives? 

Our Recovery Time Objective is 5 hours, and in practice we can switch from production to the disaster recovery site within 30 minutes. Our Recovery Point Objective is under 15 minutes. Because backup is real-time, the only data at risk is a file mid-upload, which the user can simply upload again. 

Is Simple available 24 × 7 × 365? 

Yes. Other than scheduled maintenance, the application is always available. We commit to a service level availability of 99.8%. 

Do you regularly undertake penetration testing? 

Yes. An independent third party conducts penetration testing on our systems annually, with the most recent test completed in August 2026. Findings are remediated through our vulnerability and patch management processes. 

Does Simple have any compliance certifications? 

Yes. Simple is SOC 2 certified, following an independent audit of our information security controls. Simple also operates in compliance with the GDPR and the Australian Privacy Principles. Our hosting provider, NextDC, holds ISO/IEC 27001, SOC 1 Type II, SOC 2 Type II and PCI DSS certification, and our network and cyber security infrastructure is provided by Telstra. 

Our Information Security Policy Statement can be accessed here (https://www.simple.io/information-security-policy-statement/).

Data Security

Is the data encrypted? 

Yes. Simple uses AES-256 encryption for data at rest and TLS 1.2 or higher for data in transit, including all authentication credentials passed between the browser and the application. Cryptographic keys, certificates and application secrets are generated, stored and managed separately from application data, with access restricted on least-privilege principles. 

How are user credentials stored? 

User passwords are never stored using reversible encryption. They are securely hashed using an industry-standard adaptive password hashing algorithm, which means no one can retrieve a user’s password, including our own support team. If a user forgets their password, they must reset it. 

Is my data separated from other customers’ data? 

Yes. Simple is a multi-tenant platform designed to keep each customer’s data separate. Authorisation is enforced server-side under a tenant-isolated security model, so a user authenticated against one customer account cannot reach another customer’s data. How that separation is implemented varies by product: Simple RetailPath provisions a separate set of database tables for each customer, while Simple Admation applies tenant isolation through the platform’s access control layer. Further detail is available on request. 

What kind of data does Simple hold? 

Simple holds marketing assets and the workflow information attached to them. The platform is not designed or intended to store personally identifiable information, and it does not store credit card details, health information or other sensitive categories of personal data. 

Is Simple protected from viruses? 

Yes. After upload, all files are scanned for viruses in a separate safe zone before being committed to the production system. Files that fail scanning are not admitted to the platform. 

If a customer terminates their subscription, can they get their files and metadata back? 

Yes. We can extract all data and files. This is typically provided as a download link for all files, each named with a unique ID that maps the file back to its metadata, so the export can be loaded into another system without losing context. 

Access Control

Does Simple support single sign-on? 

Yes, and we recommend it. Simple’s SSO framework supports enterprise protocols, with a preference for OpenID Connect (OIDC), and we have easy configuration for Microsoft Entra ID. We can also configure SSO with other identity providers, including Okta. 

How are users identified? 

Every user has a unique username, which is their email address. Login access cannot be shared between users, and each account is uniquely attributable in the audit trail. 

What password policy applies when SSO is not used? 

Where SSO is not in place, Simple enforces strong, complex passwords with enterprise-level configuration. Customers can optionally enable automatic password rotation after a set number of days, and automatic disabling of accounts that have been inactive for a set number of days. Both settings are configurable and default to 90 days when switched on. 

Does Simple support multi-factor authentication? 

Simple does not provide multi-factor authentication natively within the application. Where MFA is required, it is enforced through the customer’s own identity provider using SSO, which is the configuration we recommend for all enterprise customers. 

Does Simple have role-based security? 

Yes. Simple uses a tenant-isolated Role-Based Access Control model built on least-privilege principles. Administrators set a user’s role when creating the account, which determines the level of access and the functions available. Our solution architects map and configure the roles required to support each customer’s workflow. 

How is least privilege applied? 

By default, all users are provisioned with least-privilege access. If a user needs broader rights, a customer platform administrator can upgrade them accordingly. Administrative capabilities are restricted to authorised personnel and are logically separated from standard user access. 

How does the system respond to failed login attempts? 

For security purposes, Simple locks an account for 60 minutes after three unsuccessful login attempts. A platform administrator or our support team can restore access sooner by triggering a password reset. 

Are user sessions time-limited? 

Yes. All users time out after 60 minutes of inactivity, and this is not configurable. Session handling uses encrypted HTTPS connections, SameSite cookies, cryptographically strong session identifiers, session invalidation on logout and token regeneration following authentication, with controls in place to mitigate session fixation, CSRF and XSS attacks. 

Can an administrator disable a user account on demand? 

Yes. Platform administrators can disable selected users or all users at any time. Our support team can enforce a password reset for all users within a single customer account, or globally across the platform, if circumstances require it. 

Can we export a user list for access reviews? 

Yes. A client administrator can export the user list, including each user’s role, as an XLS file, which supports periodic user access reviews and recertification. 

Information Security and Privacy

Who at Simple can access customer data? 

Only authorised team members have access to production data. All are full-time Simple employees who have undergone police background checks, access is granted on least-privilege principles, and every action is logged. Simple does not use subcontractors, so no third-party personnel have access to customer data. Our team is based in Australia, with a small number of employees working overseas; they connect to the same Australian-hosted systems under the same controls, and no customer data is copied or stored outside Australia in the process. 

Does Simple hold insurance? 

Yes. Simple holds cyber risk insurance, professional indemnity insurance, public and products liability insurance, and workers compensation insurance. Certificates of currency can be provided on request as part of a procurement or vendor onboarding process. 

Does Simple have an Information Security Policy? 

Yes. We maintain an Information Security Policy document that is kept up to date and shared with all staff as updates occur and when new employees are inducted. Employees are encouraged to read this policy alongside other relevant company policies and documents, including: 

  • Internet, Social Media, Email & Computer Use Policy 
  • Privacy Policy 
  • Code of Conduct Policy 
  • Modern Slavery Policy 
  • Ethical Sourcing Policy 

Simple’s Information Security Policy covers: 

  • Physical Security 
  • Network Security 
  • Data Classification and Segregation 
  • Logical Security / Access Controls 
  • Risk Management 
  • Data Encryption 
  • Authentication Mechanisms 
  • Data Backup and Recovery 
  • Data Retention, Return and Destruction 
  • Logging and Monitoring 
  • Web Application Security Assessment 
  • Vulnerability Management 
  • Patch Management 
  • Secure Coding Practices 
  • Secure Remote Access for Employees 
  • Bring Your Own Device Policy (BYOD) 
  • Secure Software Development 
  • Business Continuity Management and Disaster Recovery 
  • Incident Management and Response 
  • Third Party Risk Management 

Does Simple have a privacy policy? 

Yes. Our privacy policy can be accessed here (https://www.simple.io/privacy-policy/). 

Does Simple require access to our IT systems? 

No. Simple does not require access to customer IT systems or customer premises to deliver or support the platform. 

Software Development and Release Management

How do you manage and test your new releases? 

We use an Agile Scrum methodology and DevOps to manage our development and product backlog. Once development is complete, updates are uploaded to a staging environment for testing. 

On staging, the test team unit test new changes and report back to development with any issues. The developers fix issues before re-uploading to staging, and this cycle continues until all unit tests pass. 

Once all unit tests pass, the test team perform an integration test, which ensures that all new functionality works within the existing system without causing issues elsewhere. Again, this is a cycle between testers and developers until all reported issues are resolved. 

Once the integration test has passed, the test team seek approval for the release from the Product Management team. Once approved, deployment to production is scheduled inside our next designated change window. 

General Queries

Does Simple provide an audit trail that logs activity? 

Yes. Simple maintains an extensive audit trail that logs user workflow decisions, including uploads, feedback, approvals and rejections, each recorded with a user and a date and time stamp. The application also logs security events, such as incorrect login attempts. 

Does Simple track who has downloaded assets? 

Yes. Each time an asset is downloaded it is recorded with a user, date and time stamp, and an IP address. All downloads for an asset can be viewed in the Download History tab, and this information can be provided as a monthly extract or on demand. 

What file sizes and types can users upload to Simple? 

File uploads are limited to a file size of 2GB. Users can upload any file type, and we automatically create thumbnail previews for most file types. 

Do I need to install any software to use Simple? 

No. All you need is a supported internet browser and a reasonable internet connection. Supported browsers include: 

  • Microsoft Edge 
  • Safari (latest 2 versions) 
  • Chrome (latest 2 versions) 
  • Firefox (latest 2 versions)