Trust Center

Security and trust at Senior Simple

How we protect the agencies, agents, and Medicare beneficiaries who rely on our platform.

Last reviewed September 2026

Compliance

Independent assessments of how we operate.

SOC 2

Report available on request

An independent examination by Capps Accounting PLLC of the Senior Simple Platform System and the design of our security and confidentiality controls, concluded with an unqualified opinion.

Criteria
Security, Confidentiality
As of
August 27, 2026
Auditor
Capps Accounting PLLC

HIPAA safeguards

Maintained continuously

We operate the platform under the HIPAA Security Rule safeguards — administrative, physical, and technical. The full list is published below.

Basis
45 CFR §164.308, §164.310, §164.312
BAA
Available to agencies on request

Security safeguards

Technical Safeguards (45 CFR §164.312)

  • Access control & unique user identification

    Every user signs in with a unique identity. Access is role-based and least-privilege, and each agency's data is isolated from every other agency's at the database level.

    In place
  • Encryption in transit

    All data is encrypted in transit using TLS.

    In place
  • Encryption at rest

    All stored data is encrypted at rest by our database platform.

    Provider-managed
  • Audit controls

    Every action that touches client data is recorded in an immutable audit trail, retained for at least ten years.

    In place
  • Authentication

    Sign-in follows current NIST guidance, including screening passwords against known breach databases.

    In place
  • Automatic logoff

    Sessions automatically time out after a period of inactivity.

    In place
  • Secrets handling & log redaction

    Secrets are redacted from logs at the write boundary, and application logs stay within our own infrastructure.

    In place

Administrative Safeguards (45 CFR §164.308)

  • Access management & least privilege

    Role-based access with per-agency isolation enforced on every request.

    In place

Physical Safeguards (45 CFR §164.310)

  • Facility access controls

    Data-center physical security, surveillance, and environmental controls are provided by our cloud platforms under their own HIPAA / SOC 2 programs.

    Provider-managed
  • Media disposal & re-use

    Secure disposal and sanitization of storage media.

    Provider-managed

Documents

  • SOC 2 Report

    Our independent auditor's report on the Senior Simple Platform System, shared under a confidentiality agreement.

How we handle client information

The Medicare brokerage workflow touches sensitive data. Here is what we do with it.

Senior Simple is built for the Medicare brokerage workflow, which routinely touches sensitive client information. We operate the platform under the safeguards listed above: encrypted transport, encrypted storage, role-based access, immutable audit logging, and a Business Associate Agreement available to any agency that needs one.

Every sub-processor that handles protected health information on our behalf operates under a Business Associate Agreement. Who they are and what they process is described in our SOC 2 report.

Client data is used to operate the service for the agency that collected it. We do not sell it, and we do not use it to train models.

Data residency

Where your data lives.

Data residency refers to the geographic location where data is stored at rest. All customer data is stored and processed in the United States — on Amazon Web Services, Supabase, and Vercel's US infrastructure — and is not replicated outside it.

Senior Simple personnel may operate these systems from multiple locations, which may include international locations. In all cases, access is granted only when necessary, limited to what the task requires, and logged.

Talk to us

Report a vulnerability

security@seniorsimple.io

We acknowledge security reports within one business day and coordinate disclosure with researchers in good faith.

Compliance and documents

compliance@seniorsimple.io

Security questionnaires, BAAs, document requests, and anything your legal team needs to review.