HIPAA & PHI

  • Our platform does not process or store PHI (Protected Health Information)
  • All data generated and stored in Simsurveys is synthetic and HCP-level only
  • Even though HIPAA does not apply, we follow security practices designed to meet or exceed HIPAA technical safeguards

Security Practices

Encryption

Encryption in transit & at rest — All data is encrypted using industry-standard protocols (TLS/HTTPS, AES-256).

Access Control

Access control — Unique accounts, role-based permissions, and multi-factor authentication protect client environments.

Monitoring & Alerting

Monitoring & alerting — System health and availability are continuously monitored.

Confidentiality

Confidentiality agreements — All employees and contractors operate under NDA and least-privilege access policies.

Data Isolation

Data isolation — Client projects are logically separated to prevent cross-access.

Data Availability & Integrity

Backups & Recovery

Backups & recovery — Automated backups are securely stored and tested for restorability.

Uptime Monitoring

Uptime monitoring — We maintain high system availability and monitor performance 24/7.

Data Validation

Data validation — Synthetic datasets are checked for completeness and accuracy before delivery.

Audit & Accountability

Login Tracking

Login tracking — User authentication events are logged for accountability.

Change Activity

Change activity — Project-level actions (e.g., question updates, report builds, quota changes) are recorded to maintain an audit trail.

Privacy & Retention

Privacy Policy

Privacy policy — A formal policy is maintained and made available to clients.

Data Retention

Data retention — Client project data is retained indefinitely by default, ensuring projects remain accessible.

Deletion on Request

Deletion on request — Clients may request deletion at any time, and data will be securely removed from active systems and backups within defined timelines.

Industry Alignment

Certification Roadmap

While Simsurveys has not yet undergone formal certification, our practices are designed to align with leading frameworks such as SOC 2 and ISO 27001. Certification is part of our roadmap, but today we already implement the core controls these standards require.

Questions About Security?

Our team is happy to discuss our security practices and compliance posture in detail.

Contact Security Team