Partners Hero BgLinear gradient Lines

Security and Trust

Secure government automation.

SimpliGov prioritizes the privacy and security of agency data. The platform ensures compliance through regular third-party audits, up-to-date certifications, and continuous assessments.

CERTIFICATIONS

Maintained certifications and audits.

The platform maintains third-party oversight to ensure compliance with strict regulatory standards.

Hipaa compliant

HIPAA Hitech

The platform protects personally identifiable health-related data (PHI). Signature processes feature ISO 27001 security certification and anti-tampering controls.

Dss Compliant

PCI-DSS 3.2

SimpliGov maintains compliance as both a service provider and merchant to ensure the secure handling of credit card holder information.

Aicpa

SSAE 18 (SOC)

SimpliGov complies with American Institute of Certified Public Accountants (AICPA) reporting requirements. The organization undergoes yearly audits across enterprise operations and data centers.

SECURITY

SimpliGov Security

At SimpliGov, security is the responsibility of our entire organization. Interdepartmental testing, auditing, and training all combine to put the SimpliGov security program at the cutting edge of security standards

Applications & Access

  • Application-level Advanced Encryption Standard (AES) 256-bit encryption.
  • Managed Virtual Private Cloud with continuous firewall monitoring.
  • Formal code reviews and automated vulnerability scanning.
  • Key management and encryption program.
  • Enterprise-grade malware protection.
  • Multiple authentication mechanisms.

Policies & Procedures

  • Customers retain complete ownership of their data.
  • Employee access to private data is strictly prohibited.
  • 24/7 monitoring, disaster recovery, and crisis recovery plans are tested periodically.
  • All application users are verified by email.

Systems & Operations

  • Physically and logically separate networks utilizing two-factor, encrypted VPN access.
  • Distributed Denial of Service (DDoS) mitigation and protection against Man in the Middle (MITM) attacks, IP spoofing, and port scanning.
  • Periodic OS and application-level patching to address the latest security threats.
  • Role-based access control granted strictly on a need-to-know basis.
  • Secure media destruction procedures compliant with NIST and DOD standards.

Hardware & Infrastructure

  • Two geo-dispersed, ISO 27001, PCI DSS, SOC1, and DIACAP Level 2 audited data centers.
  • Near real-time secure data replication and encrypted archival.
  • Annual Business Continuity Planning (BCP) and Disaster Recovery (DR) testing alongside third-party penetration testing
  • Physical access controlled by professional security staff utilizing video surveillance, intrusion detection, and multi-factor authentication.
  • Redundant electrical power systems, uninterruptible power supply (UPS) units, and automated fire detection and suppression equipment.

Transmission & Storage

  • Secure SSL 256-bit viewing sessions.
  • Customer-configurable data retention programs delivering 99.999999999 percent durability and 99.99 percent availability of objects annually.

AI Security & Compliance

  • All SimpliAI processing runs inside SimpliGov's Microsoft Azure Government environment, within the same security boundary as the rest of the platform, and customer content does not leave it
  • Customer content is never sent to Azure commercial, to a public consumer AI service, or to the open web, which is not used as a knowledge source
  • SimpliAI operates on content a user explicitly provides — a document uploaded in SimpliAI Forms, or text typed in SimpliAI Chat — plus approved SimpliGov documentation and form template structure
  • SimpliAI has no access to submitted form data, case records, or live request records, and any expansion of that scope passes security review before release
  • Tenant isolation is enforced server-side for all AI inputs, drafts, conversations, and outputs; no customer can access another customer's AI data at any layer, including form generation
  • Customer prompts, chat content, and uploaded documents are not used to train the large language models (LLMs)
  • Chat uses retrieval-augmented generation: each question retrieves passages from an approved SimpliGov documentation set, and the cited answer is generated from those passages
  • SimpliGov selects the best-fit model for each task and that selection may change as results improve; all processing for these features remains inside Azure Government
  • SimpliAI output is a draft: it cannot publish workflows, change production settings, or alter records on its own
  • Authorized users make every publish, routing, and configuration decision, and human review of AI-drafted forms remains required for layout, validation, routing, and accessibility
  • SimpliAI inherits the platform's existing access controls: portal authentication, role-based access, and the same tenant boundary as the rest of SimpliGov
  • Encryption in transit uses TLS 1.2 or higher, and encryption at rest is applied under the platform's existing controls
  • AI activity is captured in centralized security logging and monitoring, supporting security monitoring, incident response, and usage metering
  • SimpliAI is covered by the same monitored incident response and escalation procedures as the rest of the platform
  • Retention: in Forms, source uploads and generation artifacts are retained in blob storage so the input and output of each generation stay auditable; in Chat, conversations stay active until a new chat is started, then move to tenant-isolated storage
  • Current SOC 2 and related attestations are available through the certifications above or from your account team; use of SimpliAI does not change your Master Agreement, order form, or Preview Agreement

Take ownership of your program operations.

See how the workflows you're running by hand right now can run themselves.