Security Philosophy
Peepaly is built on the belief that sensitive employee information deserves the same care as financial records. We keep the surface area small, default to local-first storage and only add complexity when it clearly benefits our customers.
Privacy First
We collect only what is needed to help you onboard your team. There is no advertising layer, no tracking pixels and no sale of information to third parties.
Local Storage Architecture (current prototype)
Today, Peepaly stores everything — employees, documents, welcome settings and preferences — in your own browser's local storage. Nothing leaves your device. This makes the prototype easy to explore and keeps sensitive information under your direct control.
Future Cloud Security
When Peepaly moves to hosted infrastructure, security will be treated as a first-class product. That includes hardened production environments, least-privilege access controls, background checks for staff with production access, and regular reviews of our security posture.
Encryption
Future cloud versions will use TLS 1.2+ for data in transit and industry-standard encryption at rest for stored records and uploaded documents.
Authentication
Cloud accounts will support strong passwords with modern hashing, session expiry and — as a planned enhancement — multi-factor authentication for owners and managers.
Role-based Access
Peepaly already separates Owner, Manager and Employee views. In the cloud version this will be enforced server-side so managers cannot see pay or private notes, and employees only see their own profile.
Document Security
Uploaded documents will be stored in access-controlled object storage. Only the owner and appropriately permitted managers will be able to retrieve them.
Data Ownership
Your data is yours. You can export or delete your records at any time. Peepaly acts as a custodian, not an owner, of your team information.
Responsible Disclosure
If you believe you've discovered a vulnerability, please email support@simplaful.com with details. We commit to acknowledging reports within a reasonable timeframe and to working respectfully with researchers.
Future Compliance
We are designing Peepaly with a view to industry-standard compliance frameworks as our customer base grows.
- Cloud backupPlanned
- Multi-factor authenticationPlanned
- Audit logsPlanned
- SOC 2Planned
- ISO 27001Planned
A note on shared responsibility
- Peepaly protects the application and (in future) our hosted infrastructure.
- You are responsible for how your team accesses the application, for the devices they use and for the accuracy of the information you enter.