Trust & Security

An honest account of how we protect your plans.

Here is what is actually in place today, who processes data on our behalf, and what is still on the roadmap. We tell you what we can prove — and mark what's planned as planned.

Our posture, stated plainly. SimplyCount is a bootstrapped company and an early-stage product. We do not currently hold SOC 2, ISO 27001, HIPAA, or any other third-party security or compliance certification, and we do not claim to. This page describes the concrete measures we have actually implemented and, separately, the ones we have planned. If a control isn't listed here as in place, assume it isn't yet.

Where your plans live

SimplyCount is a desktop application: your plan sets are processed on your own device, inside your own network, and are never uploaded to us. SimplyCount checks its license once, when the app launches, over HTTPS to our licensing provider (Keygen; every vendor we share data with is listed in our Privacy Policy) — that launch-time check needs an internet connection and carries license data, not your drawings; after launch, counting runs fully offline. A fully offline build with no license check is available at negotiated pricing for air-gapped environments. For firms that want one shared install, SimplyCount can also run on a server inside your own firewall — estimators connect on your network, plan sets stay in your building, same engine, same sign-off, same encrypted local database. The measures on this page describe our web properties; deployments inside your network are governed by your own environment's security.

No third-party AI model touches your plans

SimplyCount's counting is done by our own purpose-built, self-learning machine-learning models — there is no large language model (LLM) in the loop, and your plan sets are never sent to one. On your own machine, inference runs locally: no plan data needs to leave your network for a count to happen. For a security review, that removes whole categories of questions — there is no third-party model to vet, no prompt logs, and no per-query telemetry. (On an on-prem server deployment, that same purpose-built engine runs on a server inside your own firewall — still no third-party LLM, and your plans still never leave your building.)

Where your plans go On-premise, your plans stay inside your network; a typical LLM-based tool sends them to a third-party model outside it. inside your network outside SimplyCount, on-prem your plans your machine counts here Nothing crosses the line. A typical LLM-based tool your plans third-party AI model your drawings leave

If you later want to layer your own AI on top — a bid summary, a scope writeup — you export the structured counts and route them to whatever model your firm already runs (open-source, on-premise, or your chosen provider). SimplyCount does the counting without sending your drawings to a frontier model; what you do with the exported result, and on which AI, stays your decision.

Security measures in place today

These are implemented and running now, not aspirational:

Encryption in transit In place

All traffic to our services is served over TLS, with HTTP Strict Transport Security (HSTS) enforced.

Secret management In place

Application secrets (admin and integration keys) are stored in a managed cloud secret vault and mounted at deploy — never committed to code or kept as plaintext config.

Least-privilege service accounts In place

Each service runs under its own dedicated service account with only the permissions it needs. The marketing site has no access to CRM or secret material.

Real, revocable sessions In place

Admin access uses opaque, server-side session identifiers with short idle and bounded absolute timeouts, plus per-session revocation. Raw tokens are never used as cookie values.

CSRF protection In place

State-changing admin actions are protected against cross-site request forgery.

Rate limiting In place

Public write endpoints are rate-limited per client to bound abuse and fabricated traffic.

Salted-hash PII crosswalk In place

Where we correlate records internally, identifiers are matched through a salted hash rather than by storing raw personal identifiers in the join.

Hardened HTTP headers In place

Responses set a Content-Security-Policy, X-Frame-Options (deny framing), X-Content-Type-Options, and a strict referrer policy.

Attributed audit logging In place

Administrative actions are recorded in an append-only audit log; actions taken via verified Google sign-in are attributed to a specific person.

Access-scoped admin auth In place

The product-owner console is gated behind verified sign-in restricted to authorized people, with revocable access — not an open endpoint.

CI with secret scanning In place added 2026-08-11

Every code change runs an automated test suite plus a full-history credential scan before it can merge. The repository's entire history was scanned before it ever left our machines: zero secrets found.

Reviewed-change-only deploys In place added 2026-08-11

Production deploys are mechanically refused unless the exact code being shipped has passed review and merged — the deploy tooling checks provenance before it will run, and every deploy is recorded in an append-only log.

Published privacy policy In place added 2026-08-11

Our Privacy Policy is live and describes our data collection exactly as implemented — including what our desktop app does not send.

Planned and in progress

We are honest about the gap between where we are and where we're going. These are not yet in place:

Automated data-retention purge Planned

Today our retention policy is applied as a read-time filter — older records are excluded from views. A background purge job that actually deletes past-retention data is planned but not yet built. See the retention section below.

Per-collection data isolation Planned

Finer-grained internal data isolation between services is planned.

Full least-privilege migration In progress

Our primary services run under dedicated least-privilege service accounts; the remaining services are being brought under the same model.

Formal compliance program Planned

We do not hold SOC 2 / ISO 27001 today. A formal program and third-party assessment are goals for the future, not current status.

Data handling & retention

You own your Customer Data (your plan sets and the counts produced from them). We process it only to provide the Service, and we do not sell it or use it to train shared or third-party models.

Retention, stated honestly: our retention policy is currently enforced as a read-time filter — records past the retention window are excluded from views and reporting. An automated purge job that permanently deletes past-retention data is planned but not yet implemented. We do not claim automated deletion we haven't built. If you need data deleted now, email us and we will handle it manually.

Uploaded samples (pilot counts)

The product never uploads your plans — counting runs on your machine. Separately, when you request early access you can choose to attach a sample sheet for a pilot count; that file does come to us. Stated plainly:

Retention. Sample blueprints you upload during early access are kept to improve symbol detection unless you ask us to delete them. Email sales@simplycount.com and they're removed.

Handling. While we run the pilot count and check the results, SimplyCount team members can see the file. No third-party model ever does. Deletion is performed manually — the read-time-filter / no-automated-purge posture described above applies to these files too.

On-prem server deployment

For firms that want one shared install, SimplyCount can run on a server inside your own firewall. Estimators connect on your network; plan sets stay in your building. Same engine, same sign-off, same encrypted local database — nothing is uploaded to us. Because the deployment lives entirely inside your network, it is governed by your own environment's security controls; contact sales@simplycount.com to set one up.

Report a vulnerability

We welcome responsible disclosure. If you believe you've found a security vulnerability in SimplyCount, please tell us before disclosing it publicly, and give us a reasonable window to investigate and fix it.

Email sales@simplycount.com with steps to reproduce, the affected URL or component, and its impact. We will acknowledge your report, keep you updated, and credit you if you'd like.

Please do: test only against your own account and data, and avoid privacy violations, data destruction, or service disruption. Please don't: run automated scanning at scale or access other customers' data. We currently run an informal program; a formal policy and, in time, a coordinated-disclosure page are planned.

Questions

Security or privacy questions or a data request: sales@simplycount.com. See also our Privacy Policy and legal documents (all drafts pending counsel review).

A number you can defend — and a company that levels with you.

Run your own plans and see exactly what SimplyCount marks — on your own machine.

Want to pilot on your own plans? Say so in your request.