Snapshot 37896
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security and Trust Built for government. Secured for it. Agencies trust SimpliGov with sensitive data and critical processes, protected at FedRAMP High. Authorization FedRAMP High Listing FedRAMP Marketplace Independent audit SOC 2 Type II, unqualified opinion Regulated data HIPAA and PCI DSS assessed Penetration testing Quarterly, by a third party fedRAMP High Authorized at government’s highest bar. Agencies run on Microsoft Azure Government — U.S. government cloud infrastructure operated separately from Azure commercial — with per-agency data isolation and disaster recovery exercised end to end. What High means The most demanding of FedRAMP’s impact levels. Controls come from NIST SP 800-53, the impact level is set under FIPS 199, and High applies to systems holding data whose loss would cause severe or catastrophic harm.c Independently assessed Controls are examined by an accredited third-party assessment organization, not self-attested. Continuously monitored Authorization is a standing obligation — ongoing vulnerability scanning, reporting, and review of significant changes. Reusable by agencies Agencies request the authorization package from FedRAMP by submitting a signed access request and NDA, then build on assessment work already completed rather than starting from scratch. What it gives you A credential you can put to work — in renewals, in audits, and in front of your own security and procurement reviewers. Certifications and audits Regular independent assessments FedRAMP High sits alongside the attestations agencies ask for by name. Third-party assessors examine the platform’s controls against each of these standards; the FedRAMP listing is on the Marketplace and the authorization package is released to agencies through FedRAMP’s package access request process; the remaining reports come from your account team under NDA. FedRAMP High The strongest baseline available for cloud services handling unclassified federal data. Assessed by an accredited third-party assessor and monitored continuously, with the authorization package available to agencies through FedRAMP’s package access request process. Listed on the FedRAMP Marketplace SOC 2 Type II Tests whether controls operated across a full audit period. Covers security, availability, confidentiality, and processing integrity. Most recent report: unqualified opinion, no exceptions. Report available under NDA PCI DSS Assessed as a service provider by a Qualified Security Assessor, full assessment, Compliant rating. SimpliGov never stores or processes a full card number — your payment processor handles card data and we keep only a reference token. Attestation of compliance HIPAA An independent assessment of administrative, physical, technical, and organizational safeguards, plus privacy and breach-notification requirements. Every applicable control assessed effective, no risks identified, overall rating Satisfactory. Risk assessment on file Certification scope, audit periods, and assessor details are provided in the reports themselves. Security Program Security is a company-wide commitment Engineering, operations, and support work under the same documented policies — data classification, access control, change management, incident response, disaster recovery — reviewed at least annually, with disaster recovery and incident response tested on a schedule. Applications & Access Encryption keys held in a key vault under a documented key management policy. Role-based access under least-privilege and segregation-of-duties principles; SimpliGov employee remote access to the platform environment is via VPN only and requires multi-factor authentication. Web application firewall configured against OWASP 3.0 guidelines, managing points of access to the platform alongside network security groups. Third-party static code analysis against OWASP standards, plus weekly and monthly third-party internal and external vulnerability scanning. Enterprise malware protection and continuous monitoring of key applications and the network. Policies & Procedures Employee access to customer production sites requires a job-duty justification and internal approval, and is reviewed annually by the CTO to confirm the customer authorized it Background screening, signed confidentiality agreements, and security awareness training completed before platform access is granted Policies covering data classification, privacy, breach notification, and incident response, reviewed at least annually A formal data retention schedule and documented data protection guideline governing storage, maintenance, and deletion Disaster recovery tested every six months; changes that materially affect security or availability are communicated to affected customers for approval before implementation Systems & Operations Firewalls and network segmentation restricting traffic flow, with administrative access via multi-factor VPN through a jump server the CTO controls. DDoS protection and intrusion detection and prevention at the cloud network edge. Centralized security logging, intrusion detection, and alerting through a managed SIEM, backed by a third-party continuous security monitoring service. A security patch management policy covering timely patching and emergency patching during security events. Documented data destruction procedures, with data removed from the platform environment when it is no longer required. Infrastructure & Resilience The FedRAMP High authorized environment runs on Microsoft Azure Government, with per-agency data isolation; your account team can confirm the current status of your environment. Disaster recovery exercised end to end, with replication between primary and secondary cloud sites and daily, differential, weekly, and monthly backups. Physical and environmental security is Microsoft Azure Government's responsibility as hosting provider; SimpliGov reviews the data centers' own assurance reports as part of vendor oversight. Quarterly third-party internal and external penetration testing, with methodologies aligned to OWASP, OSSTMM, FISMA, NIST CSRC, and ISO standards. 98% uptime commitment with service level credits, per the published SLA. Transmission & Storage Customer access to the production portal is encrypted in transit. Encryption at rest for production databases, virtual servers, and backup storage. Assessed as a multi-tenant service provider against the PCI DSS additional requirements for multi-tenant environments, marked in place. Digital signature workflows. Monitoring & Response Continuous automated monitoring of platform availability with threshold-based alerting and notification. A documented incident response plan covering identification, mitigation, and reporting, with defined roles, staff training, and tested response drills Documented breach notification procedures, assessed against HIPAA breach-notification requirements with no findings. Change management requiring approval before promotion to production, with separate release, UAT, and staging environments. Workflow audit trails maintained as platform data, and customers can audit their own application server logs as frequently as they need. SimpliAI AI inside the same security boundary as everything else. SimpliAI runs in SimpliGov’s Azure Government environment under the same access, logging, and tenant-isolation controls as the rest of the platform. It does not send agency content to commercial models, sees only what a user gives it, and produces drafts that must be reviewed. Where processing happens All SimpliAI processing runs inside SimpliGov’s Microsoft Azure Government environment, within the same security boundary as the rest of the platform, and customer content does not leave it Customer content is never sent to Azure commercial, to a public consumer AI service, or to the open web, which is not used as a knowledge source. SimpliGov selects the best-fit model for each task and that selection may change as results improve; all processing for these features remains inside Azure Government What SimpliAI can see SimpliAI operates on content a user explicitly provides — a document uploaded in SimpliAI Forms, or text typed in SimpliAI Chat — plus approved SimpliGov documentation and form template structure. SimpliAI has no access to submitted form data, case records, or live request records, and any expansion of that scope passes security review before release. Chat uses retrieval-augmented generation: each question retrieves passages from an approved SimpliGov documentation set, and the cited answer is generated from those passages. Your data stays yours Tenant isolation is enforced server-side for all AI inputs, drafts, conversations, and outputs; no customer can access another customer’s AI data at any layer, including form generation. Customer prompts, chat content, and uploaded documents are not used to train the large language models (LLMs). SimpliAI inherits the platform’s existing access controls: portal authentication, role-based access, and the same tenant boundary as the rest of SimpliGov. People stay in control SimpliAI output is a draft: it cannot publish workflows, change production settings, or alter records on its own. Authorized users make every publish, routing, and configuration decision, and human review of AI-drafted forms remains required for layout, validation, routing, and accessibility. Logging, response, and retention Encryption in transit uses TLS 1.2 or higher, and encryption at rest is applied under the platform's existing controls AI activity is captured in centralized security logging and monitoring, supporting security monitoring, incident response, and usage metering SimpliAI is covered by the same monitored incident response and escalation procedures as the rest of the platform Retention: in Forms, source uploads and generation artifacts are retained in blob storage so the input and output of each generation stay auditable; in Chat, conversations stay active until a new chat is started, then move to tenant-isolated storage Your Security Review Available Security Resources These are the documents we provide to procurement and information security reviewers, most of them under a mutual NDA. FedRAMP authorization package The System Security Plan and supporting authorization artifacts, released to agency security teams through FedRAMP’s package access request process. Availability: Via FedRAMP package request SOC 2 Type II report The full independent service auditor’s report, including the system description, control activities, and the assessor’s tests and results. Availability: Under NDA PCI DSS Attestation of Compliance The service provider AOC signed by our Qualified Security Assessor, for agencies processing card payments through the platform. Availability: Under NDA HIPAA risk assessment Independent assessment of administrative, physical, and technical safeguards against the HIPAA Security Rule, with the accompanying risk assessment control matrix. Availability: Under NDA Penetration test summary An executive summary of the most recent third-party internal and external penetration test, with remediation status. Availability: Under NDA Terms of Service and SLA Service commitments, the 98% uptime commitment, service level credits, and support response times by priority. Availability: Published Security questionnaire responses Completed responses to standard state and local security questionnaires, prepared by the team that owns the controls. Availability: On request Give your security team a head start. Your reviewers can request our FedRAMP authorization package from FedRAMP directly, and we will send the SOC 2 Type II, PCI attestation, HIPAA assessment, and penetration test summary under NDA. Learn more about trust & security