Back to Documentation
Security & Compliance6 min readUpdated January 2026

Security Overview

SimplyTicket is built with security as a foundational principle. We understand you're trusting us with sensitive customer data, and we take that responsibility seriously.

Infrastructure Security

Data Centers

Enterprise-grade cloud infrastructure certified for:

SOC 2 Type II
ISO 27001
PCI DSS Level 1
HIPAA (with BAA)

Network Security

  • All traffic encrypted with TLS 1.3
  • DDoS protection and mitigation
  • Web Application Firewall (WAF)
  • Intrusion detection systems
  • Regular third-party penetration tests

Data Encryption

In Transit

All data transmitted between your browser and SimplyTicket uses TLS 1.3 with strong cipher suites. We enforce HTTPS and use HSTS headers.

At Rest

All stored data is encrypted using AES-256. Encryption keys are managed through a secure key management system with regular rotation.

Access Controls

🔐

Role-Based Access

RBAC for all resources

📱

MFA Support

Multi-factor authentication

🔑

SSO Integration

SAML 2.0 and OAuth

Session Management

Configurable timeouts

Audit Logging

All significant actions are logged for security and compliance:

User authentication events
Permission and role changes
Data exports and bulk operations
API key creation and usage
Settings modifications
Failed login attempts

Audit logs retained for 2 years and can be exported for compliance reporting.

Compliance

StandardDescription
SOC 2 Type IIAnnual audit of security, availability, and confidentiality controls
GDPRFull compliance for EU customers including DPAs
CCPACalifornia Consumer Privacy Act compliance
HIPAAAvailable for healthcare customers (requires BAA)

🔒 Reporting Security Issues

If you discover a security vulnerability, please report it responsibly to security@simplyticket.net. We operate a bug bounty program for qualifying security researchers.