Skip to content

Security at SimpleKPI built on trusted infrastructure, protected by design

Your KPI data runs your business decisions. Here is exactly how we keep it safe. Last updated 6 August 2026.

Infrastructure

SimpleKPI is hosted on Microsoft Azure, using Azure's managed database, storage, and security services. Application secrets and encryption keys are held in Azure Key Vault, and Cloudflare provides network security and content delivery in front of the platform. Azure data centers are certified to internationally recognized standards such as ISO 27001 and SOC 2.

Encryption

Data is encrypted in transit using TLS (HTTPS) across the entire Service, and encrypted at rest by Azure's storage and database encryption. Encryption key material for application-level data protection is managed through Azure Key Vault.

Access and authentication

  • Sign-in: the current application is passwordless: passkeys, email one-time passcodes, or Google and Microsoft single sign-on, with enterprise customers able to connect their own SSO identity provider. Accounts still on the previous generation of SimpleKPI sign in with a password until they migrate.
  • Role-based access: six roles (Owner, Admin, Manager, Contributor, Analyst, Viewer) control exactly what each user can see and do, down to which KPIs a user can access and enter data against.
  • API access: the Developer API uses scoped tokens (read or write, per resource type) that you create and revoke in Settings, with rate limiting applied.
  • Public sharing: publicly shared dashboards and reports use unguessable token links that you can regenerate or revoke at any time, with an option to restrict the data they expose.

Payments

Payments are processed by Stripe. Card details are entered directly into Stripe's secure checkout and never pass through or get stored on SimpleKPI's servers. SimpleKPI holds only a Stripe customer reference for your account.

AI and your data

SimpleKPI's AI features run on Microsoft Azure AI Foundry, so your prompts and relevant account data are processed within Microsoft Azure under Microsoft's data protection commitments, rather than being sent to a model provider's own servers. Data at rest stays in our European Union region; inference itself uses a Global Standard deployment, which means a prompt may be processed in any Azure region worldwide, so we do not claim a regional guarantee for it. Two tools on this marketing website use OpenAI instead: the free KPI Generator, and the spam check on the contact form. Neither sends anything that identifies you, and neither touches your account or Client Data, as set out in our Privacy Notice. Your data is not used to train AI models, and any change the AI proposes to your account only takes effect after a user reviews and confirms it, so nothing is written to your data without a human decision.

Backups and continuity

Client data is backed up on Azure infrastructure, with archival backups retained for a limited period before secure deletion, as described in our Privacy Notice. You can also export your KPI data to Excel or pull it through the Developer API at any time, so your data is never locked in.

Data protection and compliance

SimpleKPI is GDPR compliant and acts as a processor for the data you bring to the platform. Details of what we collect, how long we keep it, our sub-processors, and your rights are set out in our Privacy Notice and GDPR statement. The processor terms themselves, including the full sub-processor list with processing locations and transfer safeguards, are in our Data Processing Agreement. SimpleKPI Ltd is registered in England and data protection queries can be raised at privacy@simplekpi.com.

Reporting a security concern

If you believe you have found a vulnerability in SimpleKPI, contact us at support@simplekpi.com and we will prioritize it. If you suspect your account has been compromised, or that any interaction with us is no longer secure, contact privacy@simplekpi.com so we can treat it as a possible data incident. Please include enough detail for us to reproduce the issue, and give us a reasonable opportunity to fix it before sharing it publicly.

Get started with your KPI Software

Get started for free