SimpleStay.ai

Security Policy

Vigente desde el 22 de julio de 2026 · Última actualización: 22 de julio de 2026

Este documento se proporciona en inglés. La traducción al español se publicará tras la revisión legal; la versión en inglés prevalece.

SimpleStay maintains safeguards designed to protect the confidentiality, integrity, and availability of information.

1. Cloud Infrastructure

The Platform is operated using reputable cloud providers, including Vercel and Supabase or comparable providers.

2. Encryption in Transit

Communications between users, the Platform, and trusted providers are protected using TLS or comparable encrypted protocols.

3. Authentication

We use modern authentication standards, including OAuth 2.0 and secure authentication providers. Administrative access is restricted according to role and business need.

4. Database Security

Application data is stored in managed cloud databases with authentication, access restrictions, logging, and provider security controls.

5. Payment Security

Stripe handles card processing, bank details, payouts, and identity verification. SimpleStay generally does not store complete payment-card or bank-account credentials.

6. Email Security

Business email is hosted through Google Workspace or comparable enterprise email services.

7. Monitoring

We monitor system health, errors, availability, suspicious activity, and security-relevant events.

8. Backups

Critical data is backed up daily where appropriate. Backups support recovery and continuity, but restoration times are not guaranteed.

9. Incident Response

SimpleStay maintains an incident-response team and procedures for detection, containment, investigation, recovery, documentation, and legally required notification.

10. Access Control

Access to production systems is limited to authorized personnel and providers using least-privilege principles.

11. Responsible Vulnerability Disclosure

Security researchers may report suspected vulnerabilities to:
[email protected]

Subject: “Security Vulnerability Report” Include:

  • a clear description;
  • affected URL, feature, or service;
  • reproducible steps;
  • potential impact;
  • supporting evidence; and
  • contact information.

Researchers must:

  • avoid accessing, changing, downloading, or deleting data that is not their own;
  • avoid service disruption, denial-of-service, spam, social engineering, physical intrusion, and privacy violations;
  • stop testing and notify us if sensitive data is encountered;
  • provide reasonable time for investigation and remediation before public disclosure; and
  • comply with applicable law.

A report does not create a right to payment. No bug bounty exists unless separately announced in writing. We will make reasonable efforts to acknowledge good-faith reports, investigate credible issues, and communicate status when appropriate.

12. No Absolute Guarantee

No technology is completely secure. This Policy describes safeguards and commitments, not an absolute warranty.

13. Contact

[email protected]
Subject: “Security Policy Inquiry”

Centro legal

Preferencias de cookies

Usamos cookies de analíticas solo después de que aceptes. Nos ayudan a entender el uso del sitio y mejorar la experiencia.

Security Policy · SimpleStay