Third Party Index

Snapshot 37896

Document
Trust center
URL
https://simpligov.com/security-and-trust
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
157838 bytes
SHA-256 (raw)
3fdcd6b75352d64d8ab147093be336ae1ae475e83f06398028bca6dc344abc59
SHA-256 (normalized text)
bfcdab65e1800c512938b873e95df5331307e827bebcf0594748fe19dbc1fc9e

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security and Trust
Built for government. Secured for it.
Agencies trust SimpliGov with sensitive data and critical processes, protected at FedRAMP High.
Authorization
FedRAMP High
Listing
FedRAMP Marketplace
Independent audit
SOC 2 Type II, unqualified opinion
Regulated data
HIPAA and PCI DSS assessed
Penetration testing
Quarterly, by a third party
fedRAMP High
Authorized at government’s highest bar.
Agencies run on Microsoft Azure Government — U.S. government cloud infrastructure operated separately from Azure commercial — with per-agency data isolation and disaster recovery exercised end to end.
What High means
The most demanding of FedRAMP’s impact levels. Controls come from NIST SP 800-53, the impact level is set under FIPS 199, and High applies to systems holding data whose loss would cause severe or catastrophic harm.c
Independently assessed
Controls are examined by an accredited third-party assessment organization, not self-attested.
Continuously monitored
Authorization is a standing obligation — ongoing vulnerability scanning, reporting, and review of significant changes.
Reusable by agencies
Agencies request the authorization package from FedRAMP by submitting a signed access request and NDA, then build on assessment work already completed rather than starting from scratch.
What it gives you
A credential you can put to work — in renewals, in audits, and in front of your own security and procurement reviewers.
Certifications and audits
Regular independent assessments
FedRAMP High sits alongside the attestations agencies ask for by name. Third-party assessors examine the platform’s controls against each of these standards; the FedRAMP listing is on the Marketplace and the authorization package is released to agencies through FedRAMP’s package access request process; the remaining reports come from your account team under NDA.
FedRAMP High
The strongest baseline available for cloud services handling unclassified federal data. Assessed by an accredited third-party assessor and monitored continuously, with the authorization package available to agencies through FedRAMP’s package access request process.
Listed on the FedRAMP Marketplace
SOC 2 Type II
Tests whether controls operated across a full audit period. Covers security, availability, confidentiality, and processing integrity. Most recent report: unqualified opinion, no exceptions.
Report available under NDA
PCI DSS
Assessed as a service provider by a Qualified Security Assessor, full assessment, Compliant rating. SimpliGov never stores or processes a full card number — your payment processor handles card data and we keep only a reference token.
Attestation of compliance
HIPAA
An independent assessment of administrative, physical, technical, and organizational safeguards, plus privacy and breach-notification requirements. Every applicable control assessed effective, no risks identified, overall rating Satisfactory.
Risk assessment on file
Certification scope, audit periods, and assessor details are provided in the reports themselves.
Security Program
Security is a company-wide commitment
Engineering, operations, and support work under the same documented policies — data classification, access control, change management, incident response, disaster recovery — reviewed at least annually, with disaster recovery and incident response tested on a schedule.
Applications & Access
Encryption keys held in a key vault under a documented key management policy.
Role-based access under least-privilege and segregation-of-duties principles; SimpliGov employee remote access to the platform environment is via VPN only and requires multi-factor authentication.
Web application firewall configured against OWASP 3.0 guidelines, managing points of access to the platform alongside network security groups.
Third-party static code analysis against OWASP standards, plus weekly and monthly third-party internal and external vulnerability scanning.
Enterprise malware protection and continuous monitoring of key applications and the network.
Policies & Procedures
Employee access to customer production sites requires a job-duty justification and internal approval, and is reviewed annually by the CTO to confirm the customer authorized it
Background screening, signed confidentiality agreements, and security awareness training completed before platform access is granted
Policies covering data classification, privacy, breach notification, and incident response, reviewed at least annually
A formal data retention schedule and documented data protection guideline governing storage, maintenance, and deletion
Disaster recovery tested every six months; changes that materially affect security or availability are communicated to affected customers for approval before implementation
Systems & Operations
Firewalls and network segmentation restricting traffic flow, with administrative access via multi-factor VPN through a jump server the CTO controls.
DDoS protection and intrusion detection and prevention at the cloud network edge.
Centralized security logging, intrusion detection, and alerting through a managed SIEM, backed by a third-party continuous security monitoring service.
A security patch management policy covering timely patching and emergency patching during security events.
Documented data destruction procedures, with data removed from the platform environment when it is no longer required.
Infrastructure & Resilience
The FedRAMP High authorized environment runs on Microsoft Azure Government, with per-agency data isolation; your account team can confirm the current status of your environment.
Disaster recovery exercised end to end, with replication between primary and secondary cloud sites and daily, differential, weekly, and monthly backups.
Physical and environmental security is Microsoft Azure Government's responsibility as hosting provider; SimpliGov reviews the data centers' own assurance reports as part of vendor oversight.
Quarterly third-party internal and external penetration testing, with methodologies aligned to OWASP, OSSTMM, FISMA, NIST CSRC, and ISO standards.
98% uptime commitment with service level credits, per the published SLA.
Transmission & Storage
Customer access to the production portal is encrypted in transit.
Encryption at rest for production databases, virtual servers, and backup storage.
Assessed as a multi-tenant service provider against the PCI DSS additional requirements for multi-tenant environments, marked in place.
Digital signature workflows.
Monitoring & Response
Continuous automated monitoring of platform availability with threshold-based alerting and notification.
A documented incident response plan covering identification, mitigation, and reporting, with defined roles, staff training, and tested response drills
Documented breach notification procedures, assessed against HIPAA breach-notification requirements with no findings.
Change management requiring approval before promotion to production, with separate release, UAT, and staging environments.
Workflow audit trails maintained as platform data, and customers can audit their own application server logs as frequently as they need.
SimpliAI
AI inside the same security boundary as everything else.
SimpliAI runs in SimpliGov’s Azure Government environment under the same access, logging, and tenant-isolation controls as the rest of the platform. It does not send agency content to commercial models, sees only what a user gives it, and produces drafts that must be reviewed.
Where processing happens
All SimpliAI processing runs inside SimpliGov’s Microsoft Azure Government environment, within the same security boundary as the rest of the platform, and customer content does not leave it
Customer content is never sent to Azure commercial, to a public consumer AI service, or to the open web, which is not used as a knowledge source.
SimpliGov selects the best-fit model for each task and that selection may change as results improve; all processing for these features remains inside Azure Government
What SimpliAI can see
SimpliAI operates on content a user explicitly provides — a document uploaded in SimpliAI Forms, or text typed in SimpliAI Chat — plus approved SimpliGov documentation and form template structure.
SimpliAI has no access to submitted form data, case records, or live request records, and any expansion of that scope passes security review before release.
Chat uses retrieval-augmented generation: each question retrieves passages from an approved SimpliGov documentation set, and the cited answer is generated from those passages.
Your data stays yours
Tenant isolation is enforced server-side for all AI inputs, drafts, conversations, and outputs; no customer can access another customer’s AI data at any layer, including form generation.
Customer prompts, chat content, and uploaded documents are not used to train the large language models (LLMs).
SimpliAI inherits the platform’s existing access controls: portal authentication, role-based access, and the same tenant boundary as the rest of SimpliGov.
People stay in control
SimpliAI output is a draft: it cannot publish workflows, change production settings, or alter records on its own.
Authorized users make every publish, routing, and configuration decision, and human review of AI-drafted forms remains required for layout, validation, routing, and accessibility.
Logging, response, and retention
Encryption in transit uses TLS 1.2 or higher, and encryption at rest is applied under the platform's existing controls
AI activity is captured in centralized security logging and monitoring, supporting security monitoring, incident response, and usage metering
SimpliAI is covered by the same monitored incident response and escalation procedures as the rest of the platform
Retention: in Forms, source uploads and generation artifacts are retained in blob storage so the input and output of each generation stay auditable; in Chat, conversations stay active until a new chat is started, then move to tenant-isolated storage
Your Security Review
Available Security Resources
These are the documents we provide to procurement and information security reviewers, most of them under a mutual NDA.
FedRAMP authorization package
The System Security Plan and supporting authorization artifacts, released to agency security teams through FedRAMP’s package access request process.
Availability: Via FedRAMP package request
SOC 2 Type II report
The full independent service auditor’s report, including the system description, control activities, and the assessor’s tests and results.
Availability: Under NDA
PCI DSS Attestation of Compliance
The service provider AOC signed by our Qualified Security Assessor, for agencies processing card payments through the platform.
Availability: Under NDA
HIPAA risk assessment
Independent assessment of administrative, physical, and technical safeguards against the HIPAA Security Rule, with the accompanying risk assessment control matrix.
Availability: Under NDA
Penetration test summary
An executive summary of the most recent third-party internal and external penetration test, with remediation status.
Availability: Under NDA
Terms of Service and SLA
Service commitments, the 98% uptime commitment, service level credits, and support response times by priority.
Availability: Published
Security questionnaire responses
Completed responses to standard state and local security questionnaires, prepared by the team that owns the controls.
Availability: On request
Give your security team
a head start.
Your reviewers can request our FedRAMP authorization package from FedRAMP directly, and we will send the SOC 2 Type II, PCI attestation, HIPAA assessment, and penetration test summary under NDA.
Learn more about trust & security