Trust Centre
Technical and organisational measures
SIMPLEVOTE LTD applies technical and organisational measures appropriate to the risk of processing election and account data. Infrastructure providers publish their own certifications under a shared-responsibility model; those do not certify SIMPLEVOTE LTD as ISO 27001 or SOC 2. SimpleVote holds Cyber Essentials and Cyber Essentials Plus.
Access and authentication
- Named accounts and role-based access for organisation users.
- Multi-factor authentication available for dashboard users; sensitive actions can require a fresh authenticator code.
- Voter access uses single-use email links; voter identity is stored separately from ballot rankings.
Encryption and application security
- HTTPS/TLS in transit and provider-managed encryption at rest.
- Server-side authorisation checks for tenant-scoped actions.
- Signed checks on transactional email delivery events.
Data minimisation and retention
- Voter invitee personal data is scheduled for deletion after election close under the published retention schedule.
- Email open and click analytics are retained only as de-identified aggregates, not as named recipient records.
- Security audit records are retained for a defined maximum period.
Staff, suppliers and continuity
- Access to production systems is limited to authorised personnel on secured devices.
- Subprocessors are listed publicly; customers may request change notices.
- Backup and recovery arrangements are maintained with our infrastructure providers. Current recovery evidence is available on request for procurement.
Incidents
Personal-data incidents affecting Controller data are notified under the Data Processing Agreement, including written notice to the Controller within 24 hours of awareness where that commitment applies.
For security questionnaires or a detailed control pack, contact info@simplevote.org.
