belsimple Just right.

Security policy

Version 1.3 | Effective date: 2026-06-10

Overview

belsimple is operated by Maarnyka BV and hosted entirely in Belgium on managed cloud infrastructure. This document describes the security measures in place to protect your data.

Infrastructure

belsimple is hosted entirely in Belgium (europe-west1) on managed cloud infrastructure. By running on managed cloud services, belsimple benefits from the provider’s infrastructure security, including physical data centre security, network isolation, and DDoS protection. Our infrastructure provider holds ISO 27001 and SOC 2/3 certifications.

Data encryption

  • In transit: All connections use TLS. HTTP traffic is automatically redirected to HTTPS.
  • At rest: Database storage and backups are encrypted at rest using provider-managed encryption keys.

Authentication and access control

  • Password hashing: User passwords are hashed using a modern, memory-hard algorithm resistant to brute-force and GPU-based attacks.
  • Session management: Sessions expire after 1 hour of inactivity. All sessions are invalidated on password reset or account deactivation.
  • SSO support: Tenants can configure OpenID Connect (OIDC) single sign-on, delegating authentication to their identity provider.
  • Role-based access: Three roles (platform admin, manager, employee) with enforced permissions at the API level. Role checks cannot be bypassed from the frontend.
  • Rate limiting: Login and password reset endpoints are rate-limited to prevent brute-force attacks.

Multi-tenancy and data isolation

Each tenant’s data is logically isolated at the database level. Every query is scoped to the authenticated user’s tenant. There is no mechanism — by design — for one tenant to access another tenant’s data through the application.

Backups and disaster recovery

  • Automated backups: Our managed database service performs daily automated backups with point-in-time recovery (PITR).
  • Retention: Backups are retained according to our managed database service’s configured retention policy.

Incident response

In the event of a security incident affecting customer data:

  1. We will contain and investigate the incident immediately.
  2. Affected tenants will be notified without undue delay.
  3. The Belgian Data Protection Authority (GBA) will be notified if required under GDPR.
  4. A post-incident report will be provided to affected tenants, describing the nature of the incident, the data affected, and the measures taken to prevent recurrence.

Responsible disclosure

If you discover a security vulnerability in belsimple, please report it to legal@belsimple.be. We ask that you:

  • Provide a description of the vulnerability and steps to reproduce it
  • Allow us a reasonable period to address the issue before disclosing it publicly
  • Do not access or modify other tenants’ data during your research

We appreciate responsible disclosure and will acknowledge your contribution.

What we do not do

  • We do not store passwords in plaintext or reversible encryption.
  • We do not store or process your data outside of Belgium.
  • We do not use your data for purposes other than delivering the service.
  • We do not use analytics, tracking, or advertising services.

Maarnyka BV — Ganzeplas 23, 9880 Aalter, Belgium — KBO 0783.288.064

Contact: legal@belsimple.be