Skip to content

Security at SimpleKPI built on trusted infrastructure, protected by design

Your KPI data runs your business decisions. Here is exactly how we keep it safe. Last updated 16 July 2026.

Infrastructure

SimpleKPI is hosted on Microsoft Azure, using Azure's managed database, storage, and security services. Application secrets and encryption keys are held in Azure Key Vault, and Cloudflare provides network security and content delivery in front of the platform. Azure data centers are certified to internationally recognized standards such as ISO 27001 and SOC 2.

Encryption

Data is encrypted in transit using TLS (HTTPS) across the entire Service, and encrypted at rest by Azure's storage and database encryption. Encryption key material for application-level data protection is managed through Azure Key Vault.

Access and authentication

  • Sign-in: accounts are verified at signup by email one-time passcode, or authenticated through Google or Microsoft single sign-on. Enterprise customers can connect their own SSO identity provider.
  • Role-based access: six roles (Owner, Admin, Manager, Contributor, Analyst, Viewer) control exactly what each user can see and do, down to which KPIs a user can access and enter data against.
  • API access: the Developer API uses scoped tokens (read or write, per resource type) that you create and revoke in Settings, with rate limiting applied.
  • Public sharing: publicly shared dashboards and reports use unguessable token links that you can regenerate or revoke at any time, with an option to restrict the data they expose.

Payments

Payments are processed by Stripe. Card details are entered directly into Stripe's secure checkout and never pass through or get stored on SimpleKPI's servers. SimpleKPI holds only a Stripe customer reference for your account.

AI and your data

SimpleKPI's AI features run on Microsoft Azure AI Foundry, so your prompts and relevant account data are processed inside the same Microsoft Azure infrastructure that hosts the rest of the Service, and are not sent directly to third-party AI providers, as described in our Privacy Notice. Your data is not used to train AI models, and any change the AI proposes to your account only takes effect after a user reviews and confirms it, so nothing is written to your data without a human decision.

Backups and continuity

Client data is backed up on Azure infrastructure, with archival backups retained for a limited period before secure deletion, as described in our Privacy Notice. You can also export your KPI data to Excel or pull it through the Developer API at any time, so your data is never locked in.

Data protection and compliance

SimpleKPI is GDPR compliant and acts as a processor for the data you bring to the platform. Details of what we collect, how long we keep it, our sub-processors, and your rights are set out in our Privacy Notice and GDPR statement. SimpleKPI Ltd is registered in England and data protection queries can be raised at privacy@simplekpi.com.

Reporting a security concern

If you believe you have found a vulnerability in SimpleKPI, or you suspect your account has been compromised, contact us at support@simplekpi.com and we will prioritize it. Please include enough detail for us to reproduce the issue, and give us a reasonable opportunity to fix it before sharing it publicly.

Get started with your KPI Software

Get started for free