Simple Smooth Safe
Security & compliance

Most of the risk is removed by the architecture, not managed by us.

Our products run in your tenant and we store none of your data. Here is what that means control by control — including the one place it is not true, and the certifications we do not hold.

Version 1.0Last updated 10 August 2026

The short version. Our products run inside your Microsoft tenant. We operate no service that stores your data, so most of the questions on a standard security questionnaire resolve to "not applicable, and here is why" rather than to a control we assert and you have to trust.

This page is the public summary. The full security and compliance review is available under NDA — email security@simplesmoothsafe.com.

1. Where your data actually is

ProductWhere it runsWhat reaches us
SSS DocGen A container in your Azure subscription, reading your Dataverse Nothing. Documents return to the caller; unless Attach is used they are stored nowhere.
SSS DMS Your Power Platform. Reads your Dataverse and your SharePoint in place Nothing. It does not migrate, copy or move files.
PSA Hub Your Dataverse, native tables, under your Entra ID Nothing. The app is hosted and authenticated by the Power Platform.

There is no SSS-operated database, no shared multi-tenant application, and no data-processing pipeline of ours between you and your records. Backup, retention, DLP and eDiscovery remain your tenant's, governed by policies you already run.

2. Identity and access

3. Secrets

The DocGen container reads its Entra client secret from Azure Key Vault through its own managed identity. It is never committed and never logged.

One limitation we publish rather than bury. The Dataverse plugin needs its own copy of that secret, and the out-of-the-box request it uses to read configuration — RetrieveEnvironmentVariableValue — cannot resolve Key Vault-backed environment variables. So on the Dataverse side the secret is a Text environment variable, readable by anyone who can read environment-variable values in that environment.

The compensating control is to restrict that privilege to the administrators who need it. The fix is known — have the plugin call RetrieveEnvironmentVariableSecretValue instead — and it is on the roadmap. It is stated on the product page, in the deployment runbook and here, because a security claim a product does not meet is worse than the limitation it papers over.

4. Sub-processors

Because no customer data flows to us in normal operation, the sub-processor list is short and covers only the systems that could touch material you deliberately send us — a support attachment, a log, an exported template.

Sub-processorPurposeLocation
Microsoft Ireland Operations LtdEmail, file storage, Microsoft FormsEU
Hosting providerThis website. Holds no customer data.EU

Website analytics (Plausible) is deliberately not on this list: it is cookieless, stores no personal data, and never touches customer data. It is covered by the Privacy Policy instead. Changes to this list carry 30 days' notice and a right to object — see the DPA, section 6.

5. Data protection

6. Development and change

7. What we do not claim

Stated plainly so nobody has to discover it in a questionnaire response:

8. Reporting a vulnerability

Email security@simplesmoothsafe.com, or see /.well-known/security.txt. We aim to acknowledge within two business days, tell you whether we can reproduce it within five, and agree a disclosure timeline with you rather than impose one.

Please do not test against a customer environment. If you need somewhere to test, ask and we will arrange it.

9. Questionnaires

Send it. We answer security questionnaires as part of a normal sales process, not as a favour, and we would rather answer yours than have you guess from this page. The full security and compliance review is available under NDA.