Back to Trust Center

Security Overview

Disclosure Level: Public | Version: v1.1 | Last Updated: January 2026

Service Summary

SimplyPNG is a cloud SaaS that performs image processing workflows (e.g., background removal) and delivers output assets to users via the SimplyPNG web application and API.

Security Principles

  • Least privilege access
  • Strong authentication for administrative access
  • Encryption in transit
  • Controlled access to data stores
  • Monitoring and incident response readiness
  • Secure development practices and vulnerability management

High-Level Architecture

We use reputable, industry-standard service providers for:

  • • Web application hosting and delivery
  • • Managed database services (account metadata)
  • • Object storage (customer content where applicable)
  • • Compute/processing infrastructure (workload execution)
  • • Transactional email delivery
  • • Payments processing

A full list of subprocessors (including vendor names) is available under NDA upon request.

Access Control

Administrative Access

  • • Administrative access is restricted to authorized personnel only
  • • Multi-factor authentication (MFA) is enforced for administrative accounts

Authorization

  • • Role-based access control (RBAC) for administrative functions
  • • Four-tier hierarchy: admin → ops → content → support
  • • Organization roles: owner → admin → member → viewer
  • • Access provisioned on least-privilege basis

Encryption

In Transit: All customer connections use TLS 1.3 enforced at the edge.
At Rest: Data is protected using encryption at rest (AES-256) by our storage and database providers.
Secrets: Handled using secure environment configuration and never stored in source control.

Logging and Monitoring

  • • We monitor service health, error rates, and processing job outcomes
  • • Administrative actions and system access events are logged
  • • Application logs retained for 30 days
  • • Security logs retained for 90 days

Incident Response

We maintain incident response procedures including detection, containment, remediation, and customer notification protocols.

Security Contact: security@simplypng.app

Vulnerability Reporting: See Vulnerability Disclosure

Compliance and Assurance

PlannedSOC 2: Roadmap target 2027
PlannedPenetration Testing: Planned when revenue supports

We are actively implementing industry-standard security controls and can provide detailed documentation of our security practices under NDA.

Disclosure Policy Notice

This public document intentionally omits vendor names and sensitive infrastructure details. Vendor-specific due diligence information is available under NDA.