You're on dev (v1.1 integration) - not for real elections.

Security & compliance

Built for organisations thattake trust seriously.

SimpleVote uses configured regional storage, provider-managed encryption, documented retention controls and published procurement information. Review the Trust Centre for scope and limitations.

SimpleVote Ltd is certified to Cyber Essentials and Cyber Essentials Plus (24 June 2026, issued by The IASME Consortium Ltd). Verify certificate

Cyber Essentials Plus

Independently verified UK cyber security

SimpleVote Ltd is certified to Cyber Essentials and Cyber Essentials Plus (issued 24 June 2026). The UK government-backed scheme assesses firewalls, secure configuration, access control, malware protection, and patching.

What you can rely on

  • Cyber Essentials and Cyber Essentials Plus certified by IASME
  • Verify our certificate on the Blockmark registry at any time

Cloud infrastructure

Built on independently audited providers

SimpleVote runs on cloud platforms that publish scoped assurance reports and certifications. Those provider controls do not certify SIMPLEVOTE LTD. We publish our subprocessors, TOMs and DPA for due diligence.

What you can rely on

  • Provider SOC 2 reports may be available for their scoped services
  • Provider ISO/IEC 27001 certification under a shared responsibility model
  • Documented subprocessors, retention rules, and a standard DPA for organisers

Data protection

Privacy by design for member elections

Primary database storage is in London. Transactional email is sent from Ireland. Edge delivery, support and recipient mail systems may process data elsewhere under transfer safeguards.

What you can rely on

  • Primary database region: London; transactional email region: Ireland
  • Scheduled removal of voter names and emails 30 days after an election closes
  • UK GDPR-aligned processing with data minimisation and purpose limitation
  • Registered with the UK ICO (reference ZC162594)

Data protection

Encryption by default

Voters and election managers can trust that data is protected in storage and in transit.

What you can rely on

  • Encryption at rest (AES-256) for database records and backups
  • Encryption in transit (HTTPS/TLS) for every connection to SimpleVote
  • Provider-managed edge protection against common denial-of-service attacks

Payments

Card data stays with your payment provider

When you pay for larger tiers, card details are handled by a certified payment provider. SimpleVote never stores card numbers.

What you can rely on

  • PCI DSS Level 1 payment processing via a certified provider (e.g. Stripe)
  • SimpleVote only receives payment confirmations, not card data

For IT & procurement

Technical details

A concise summary for security questionnaires. For legal terms, subprocessors, and the DPA, see our legal pages or contact info@simplevote.org.

Application hosting
Vercel (configured London compute where applicable)
Database & authentication
Supabase PostgreSQL and Auth (United Kingdom - London)
Transactional email
Resend (Ireland) for voter invitations, reminders and results
Voter personal data retention
Scheduled deletion 30 days after election close
ICO registration
ZC162594
Subprocessors & DPA
See Subprocessors and Data Processing Agreement
Certification
Cyber Essentials and Cyber Essentials Plus (IASME). Infrastructure providers may hold their own ISO 27001 / SOC 2 reports; those do not certify SIMPLEVOTE LTD.

Questions about security?

Read our privacy policy and DPA, or create a free account and run a test election before your live poll.

Security & compliance | SimpleVote | SimpleVote