Effective as of the Agreement Effective Date; updated from time to time

1. Purpose and Scope

This Data Security Policy (“Policy”) describes the administrative, physical, and technical safeguards Simplexity AI LLC (“Provider”) maintains to protect Customer Data, including Protected Health Information (“PHI”) as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (collectively, “HIPAA”). This Policy applies to all Provider Personnel, Subcontractors, and systems involved in the processing, storage, or transmission of Customer Data.

Provider is currently pursuing SOC 2 Type II certification. The controls described herein are designed to satisfy the SOC 2 Trust Services Criteria (Security, Availability, and Confidentiality) and the HIPAA Security Rule (45 C.F.R. Parts 160 and 164).

The current and up-to-date Policy is available at www.simplexitylegal.com/data-security-policy/. Provider may amend the Policy from time to time in its sole discretion. 

2. Organizational Security

2.1 Security Ownership. The General Manager is responsible for the development, implementation, and maintenance of this Policy and all related security programs.

2.2 Risk Assessment. Provider conducts a formal information security risk assessment no less than annually, or following any material change to its systems or services. Risk assessments identify threats and vulnerabilities to the confidentiality, integrity, and availability of Customer Data, and inform the prioritization of remediation activities.

2.3 Security Policies and Procedures. Provider maintains written security policies and procedures covering, at minimum: access control, incident response, change management, vendor risk, and acceptable use. Policies are reviewed and updated annually.

2.4 Security Awareness Training. All Provider Personnel with access to Customer Data complete security awareness training upon hire and annually thereafter. Training covers phishing, social engineering, password security, and HIPAA obligations.

3. Access Control

3.1 Least Privilege. Provider grants access to Customer Data and production systems on a least-privilege, need-to-know basis. Access rights are reviewed quarterly and revoked promptly upon role change or termination.

3.2 Authentication. Access to systems processing Customer Data requires multi-factor authentication (MFA). Shared or generic credentials are prohibited.

3.3 Password Standards. Where passwords are used, Provider enforces minimum complexity requirements and prohibits password reuse across systems.

3.4 Remote Access. Remote access to production environments is restricted to VPN or equivalent encrypted tunnels and requires MFA.

3.5 Privileged Access. Administrative and privileged access is documented, time-limited where practicable, and subject to enhanced logging and review.

4. Data Classification and Handling

4.1 Classification. Customer Data is classified as Confidential. PHI is further classified as Restricted and subject to the controls in this Policy and applicable HIPAA requirements.

4.2 Data Minimization. Provider collects and retains only the Customer Data necessary to perform the Services. Data minimization principles are applied at ingestion and throughout the data lifecycle.

4.3 Data Location. All Customer Data, including PHI, is processed and stored exclusively within the United States, as required by the Agreement.

4.4 Encryption at Rest. Customer Data is encrypted at rest using AES-256 or an equivalent standard.

4.5 Encryption in Transit. Customer Data is encrypted in transit using TLS 1.2 or higher. Unencrypted transmission of PHI is prohibited.

4.6 Data Retention and Disposal. Customer Data is retained for the period required to perform the Services and is securely deleted or destroyed in accordance with Provider’s then-current retention schedule and Section 14.4 of the Agreement. PHI is disposed of in a manner that renders it unreadable and unrecoverable.

5. System and Infrastructure Security

5.1 Cloud Infrastructure. Provider’s production environment is hosted on Google Cloud Platform (“GCP”). Provider leverages GCP’s native security controls, including network segmentation, identity and access management, and audit logging, as a component of its security posture.

5.2 Vulnerability Management. Provider conducts automated vulnerability scanning of production infrastructure and application code on at least a monthly basis. Critical and high-severity vulnerabilities are remediated within 60 days of identification; critical vulnerabilities affecting PHI are remediated within 15 days.

5.3 Patch Management. Operating systems, libraries, and dependencies are patched on a defined cycle. Security patches rated critical are applied on an expedited basis.

5.4 Network Security. Production systems are isolated from development and test environments. Network access is controlled via firewalls, security groups, and deny-by-default ingress policies. PHI is not present in non-production environments except as required and with equivalent controls applied.

5.5 Logging and Monitoring. Provider maintains centralized audit logs for access to and modification of systems processing Customer Data. Logs capture user identity, timestamp, action, and resource. Logs are retained for no less than 12 months and are protected against unauthorized modification.

5.6 Intrusion Detection. Provider employs automated tooling to detect anomalous access patterns and potential security events. Alerts are routed to Provider Personnel for triage.

6. Subcontractor and Vendor Security

6.1 Vendor Assessment. Before engaging any Subcontractor with access to Customer Data, Provider performs a security review commensurate with the sensitivity of the data to be accessed. PHI may only be shared with Subcontractors who have executed a Business Associate Agreement (“BAA”) with Provider as required by HIPAA.

6.2 Contractual Requirements. Subcontractors with access to Customer Data are required to maintain security controls materially equivalent to those described in this Policy and to comply with applicable Law, including HIPAA.

6.3 Ongoing Oversight. Provider reviews Subcontractor security posture periodically and reserves the right to terminate engagements where a Subcontractor fails to meet security requirements.

7. Data Breach Procedures

7.1 Incident Detection and Response. Provider maintains a written Incident Response Plan covering detection, containment, eradication, recovery, and post-incident review. The plan is tested no less than annually.

7.2 Notification — HIPAA Breach. In the event of a Breach of Unsecured PHI as defined under 45 C.F.R. § 164.402, Provider will notify Customer without unreasonable delay and in no event later than 30 calendar days after Provider discovers the Breach. Notification will include, to the extent known: (a) a description of the Breach and the PHI involved; (b) the identity of individuals whose PHI was affected, if determinable; (c) the steps affected individuals should take to protect themselves; (d) a description of Provider’s investigation and remediation steps; and (e) contact information for follow-up questions.

7.3 Notification — Other Security Incidents. For security incidents affecting Customer Data that do not constitute a HIPAA Breach, Provider will notify Customer within 72 hours of determining that Customer Data was or is reasonably likely to have been accessed, disclosed, or used in an unauthorized manner.

7.4 Cooperation. Provider will cooperate with Customer’s reasonable requests in connection with any breach investigation and will provide such information as is reasonably necessary for Customer to fulfill its own notification obligations under applicable Law.

8. Physical Security

8.1 Data Center Security. Customer Data is hosted in GCP data centers, which maintain physical security controls including 24/7 monitoring, biometric access controls, and environmental protections. Provider relies on GCP’s physical security certifications (including SOC 2 and ISO 27001) as a component of its own physical security posture.

8.2 Office and Device Security. Provider Personnel accessing Customer Data on Provider-managed devices must use encrypted storage, screen lock policies, and remote wipe capabilities. Hardcopy PHI, if any, is stored in locked facilities and disposed of via cross-cut shredding or equivalent.

9. Business Continuity and Disaster Recovery

9.1 Backup. Customer Data is backed up in accordance with Provider’s Backup Policy (Exhibit F). Backups are encrypted and stored in geographically redundant locations within the United States.

9.2 Recovery Objectives. Provider maintains documented Recovery Time Objectives (“RTO”) and Recovery Point Objectives (“RPO”) for the Services. These are available to Customer upon written request.

9.3 Testing. Provider tests its disaster recovery capabilities no less than annually and remediates gaps identified during testing.

10. Compliance and Audit

10.1 HIPAA Compliance. Provider maintains a HIPAA compliance program including designation of a Privacy Officer and Security Officer, workforce training, and documentation of policies and procedures as required by 45 C.F.R. Parts 160 and 164.

10.2 SOC 2 Certification. Provider is pursuing SOC 2 Type II certification. Upon completion, Provider will make its SOC 2 report available to Customer under NDA upon written request.

10.3 Customer Audit Rights. No more than once per calendar year, and upon 30 days’ written notice, Customer may request documentation evidencing Provider’s compliance with this Policy. Provider will respond to reasonable written security questionnaires within 30 business days. On-site audits require mutual written agreement and are subject to reasonable confidentiality and scheduling constraints.

10.4 Policy Updates. Provider may update this Policy from time to time to reflect changes in technology, applicable Law, or security best practices. Provider will notify Customer of material changes with at least 30 days’ prior written notice. Continued use of the Services following the effective date of any update constitutes acceptance.