トラストセンターに戻る

セキュリティ概要

Disclosure Level: Public | Version: v1.1 | Last Updated: January 2026

サービス概要

SimplyPNGは画像処理ワークフロー(背景除去など)を実行し、WebアプリケーションとAPIを通じて処理結果を提供するクラウドSaaSです。

セキュリティ原則

  • 最小権限アクセス
  • 管理アクセスの強力な認証
  • 通信の暗号化
  • データストアへのアクセス制御
  • 監視とインシデント対応体制
  • セキュアな開発プラクティスと脆弱性管理

High-Level Architecture

We use reputable, industry-standard service providers for:

  • • Web application hosting and delivery
  • • Managed database services (account metadata)
  • • Object storage (customer content where applicable)
  • • Compute/processing infrastructure (workload execution)
  • • Transactional email delivery
  • • Payments processing

A full list of subprocessors (including vendor names) is available under NDA upon request.

Access Control

Administrative Access

  • • Administrative access is restricted to authorized personnel only
  • • Multi-factor authentication (MFA) is enforced for administrative accounts

Authorization

  • • Role-based access control (RBAC) for administrative functions
  • • Four-tier hierarchy: admin → ops → content → support
  • • Organization roles: owner → admin → member → viewer
  • • Access provisioned on least-privilege basis

Encryption

In Transit: All customer connections use TLS 1.3 enforced at the edge.
At Rest: Data is protected using encryption at rest (AES-256) by our storage and database providers.
Secrets: Handled using secure environment configuration and never stored in source control.

Logging and Monitoring

  • • We monitor service health, error rates, and processing job outcomes
  • • Administrative actions and system access events are logged
  • • Application logs retained for 30 days
  • • Security logs retained for 90 days

インシデント対応

検出、封じ込め、修復、顧客通知プロトコルを含むインシデント対応手順を維持しています。

Security Contact: security@simplypng.app

Vulnerability Reporting: See Vulnerability Disclosure

Compliance and Assurance

PlannedSOC 2: Roadmap target 2027
PlannedPenetration Testing: Planned when revenue supports

We are actively implementing industry-standard security controls and can provide detailed documentation of our security practices under NDA.

Disclosure Policy Notice

This public document intentionally omits vendor names and sensitive infrastructure details. Vendor-specific due diligence information is available under NDA.