Simplytics

Security

No certifications to show you, so here is the thing underneath them: what Simplytics actually does, what it deliberately never holds, and what is still wrong with it.

The part that matters most: what is not here

Most analytics breaches are bad because of what the tool was keeping. Simplytics keeps almost none of it, which is a design decision rather than a security control — but it is the one that limits the damage of everything else.

How the account itself is protected

Transport and headers

Where the data is, and what happens if it is lost

What is still wrong

A security page that lists only good news is an advertisement. These are the open items, in the order we would fix them:

Reporting something

Email nikhil@simplytics.dev. There is no bug bounty and no payout — saying so plainly is fairer than letting you spend a weekend assuming otherwise. Reports are read and answered, and /.well-known/security.txt lists what is already known and therefore not worth your time.

Please do not test against other people's accounts or send traffic that would distort a customer's numbers. A free trial takes no card and gives you a real account of your own to test against.