SimpleStay.ai

Security Policy

Effective July 22, 2026 · Last updated July 22, 2026

SimpleStay maintains safeguards designed to protect the confidentiality, integrity, and availability of information.

1. Cloud Infrastructure

The Platform is operated using reputable cloud providers, including Vercel and Supabase or comparable providers.

2. Encryption in Transit

Communications between users, the Platform, and trusted providers are protected using TLS or comparable encrypted protocols.

3. Authentication

We use modern authentication standards, including OAuth 2.0 and secure authentication providers. Administrative access is restricted according to role and business need.

4. Database Security

Application data is stored in managed cloud databases with authentication, access restrictions, logging, and provider security controls.

5. Payment Security

Stripe handles card processing, bank details, payouts, and identity verification. SimpleStay generally does not store complete payment-card or bank-account credentials.

6. Email Security

Business email is hosted through Google Workspace or comparable enterprise email services.

7. Monitoring

We monitor system health, errors, availability, suspicious activity, and security-relevant events.

8. Backups

Critical data is backed up daily where appropriate. Backups support recovery and continuity, but restoration times are not guaranteed.

9. Incident Response

SimpleStay maintains an incident-response team and procedures for detection, containment, investigation, recovery, documentation, and legally required notification.

10. Access Control

Access to production systems is limited to authorized personnel and providers using least-privilege principles.

11. Responsible Vulnerability Disclosure

Security researchers may report suspected vulnerabilities to:
[email protected]

Subject: “Security Vulnerability Report” Include:

  • a clear description;
  • affected URL, feature, or service;
  • reproducible steps;
  • potential impact;
  • supporting evidence; and
  • contact information.

Researchers must:

  • avoid accessing, changing, downloading, or deleting data that is not their own;
  • avoid service disruption, denial-of-service, spam, social engineering, physical intrusion, and privacy violations;
  • stop testing and notify us if sensitive data is encountered;
  • provide reasonable time for investigation and remediation before public disclosure; and
  • comply with applicable law.

A report does not create a right to payment. No bug bounty exists unless separately announced in writing. We will make reasonable efforts to acknowledge good-faith reports, investigate credible issues, and communicate status when appropriate.

12. No Absolute Guarantee

No technology is completely secure. This Policy describes safeguards and commitments, not an absolute warranty.

13. Contact

[email protected]
Subject: “Security Policy Inquiry”

Legal Center

Cookie preferences

We use analytics cookies only after you agree. They help us understand site usage and improve the experience.

Security Policy · SimpleStay