Cargando…
Cargando…
TRUST CENTER · CENTRO DE CONFIANZA
The security, privacy, and transparency posture behind simiriki — encryption, identity and access, retention, incident response, our sub-processor registry, and where our compliance program stands. Refreshed quarterly, with file-level evidence you can verify.
SQL injection, SSRF, open redirects, CSRF, OAuth state, webhook signatures, HMAC, encryption at rest, CSP — each one audited against the code that defends it. Public, reproducible, refreshed every quarter.
Our detection catalog spans 201 rules — 155 via Microsoft Graph (the free Auditoría) and 46 via Azure Resource Manager (added with admin consent and Reader access) — organized into 8 categories.
MFA enforcement, conditional access, admin roles, stale accounts
DMARC, SPF, DKIM, forwarding rules, anti-phishing
External sharing, DLP policies, sensitivity labels
Compliance policies, managed vs unmanaged devices
Logging, retention, regulatory alignment
OAuth permissions, risky apps, consent policies
License utilization, connector health
Process automation, approval workflows
Each evaluated rule produces an observed pass or finding with CRITICAL, HIGH, MEDIUM, or LOW severity. The 0–100 posture score is calculated from those rule outcomes; a control that could not be evaluated remains pending rather than becoming a false failure.
Every report states how many rules were evaluated, which controls remained pending, and which observed findings produced each remediation action. The Audit does not infer compliance or financial return without evidence.
Your data is processed by simiriki and the third-party services below. This registry supports applicable processor/subprocessor disclosure obligations and stays in lockstep with the machine-readable schema embedded on this page.
| Service | Legal entity | Country | Purpose |
|---|---|---|---|
| Hetzner Cloud | Hetzner Online GmbH | DE | Production compute, disk, PostgreSQL, and Redis on a single-region VPS in Ashburn, Virginia (US) |
| Microsoft 365 + Azure / Graph + ARM | Microsoft Corporation | US | Customer Microsoft 365 + Azure OAuth (read-only: 155 rules via Microsoft Graph + 46 rules via Azure Resource Manager) during scans + Graph SendMail for transactional email |
| Stripe | Stripe, Inc. | US | Payment processing. Customer email + payment-intent ID (no card data — Stripe Checkout hosts the flow). PCI DSS Level 1. |
| Cloudflare | Cloudflare, Inc. | US | Authoritative DNS, TLS termination, edge protection, and Cloudflare Tunnel; processes HTTP request metadata in transit |
| Anthropic | Anthropic, PBC | US | Claude models for diagnostics, executive memos, commercial workflows, and editorial content (executive memos run under explicit client consent: generating executive memos and quarterly analyses for clients). The site assistant and posture Audit are deterministic and do not send their inputs or findings to Anthropic. Data sent to Anthropic through its commercial API is not used to train its models (Anthropic Commercial Terms) and is retained only temporarily and in a limited way to operate the service and monitor misuse. Workflows involving personal data are processed only through Anthropic’s commercial API; they are never sent to any model provider’s free tier. |
| Google Analytics 4 | Google LLC | US | Consent-gated public-site analytics; not run in the authenticated dashboard or portal. |
Full contractual terms in our Data Processing Agreement.
These are TARGETS our compliance program is built toward — not active certifications. We disclose this honestly: simiriki does not hold these certifications today. Audit dates are revenue-triggered and available on request.
Mexico's federal personal-data protection law. Mandatory for all Mexican customer data. Privacy notice published; ARCO rights honored within ≤ 20 business days (Art. 32).
In evidenceAICPA trust-services-criteria attestation. ~12-month observation period; triggered by the first enterprise contract. We do not claim a report that does not yet exist.
Committed on auditInternational information-security management standard. Controls mapped via Microsoft Compliance Manager; external Stage 1/Stage 2 audit triggered by enterprise contract.
Committed on auditMexican national standard equivalent to ISO/IEC 27001, issued by NYCE. Relevant for Mexican government and enterprise procurement that requires the national norm. Same controls as ISO 27001; local certification triggered by contract.
Committed on auditMicrosoft's security baseline for Azure workloads. simiriki's former Azure estate was deleted on 2026-08-13; there is no current production subscription on which to claim Azure Policy enforcement.
PlannedCenter for Internet Security Azure-specific baseline. It does not apply to the current Hetzner runtime and would be reassessed only if a production workload returns to Azure.
PlannedEU General Data Protection Regulation. Relevant if we serve European data subjects. Article 28 (subprocessor) disclosures are already published; full scope is triggered by the first customer with EU data.
PlannedUS Health Insurance Portability and Accountability Act. Healthcare vertical. We do not handle US PHI today; triggered only if we enter the US healthcare market.
PlannedMexican National Banking and Securities Commission rules (CUB, record retention). Mexican banking/financial vertical. Triggered by the first CNBV-regulated customer.
PlannedThe free scan requests only least-privilege, read-only configuration scopes — never the content of your mail, calendar, files, or contacts. Each permission maps to the detection rules it powers.
In the event of a security incident:
Depending on your jurisdiction, you have the right to access, rectify, cancel/delete, or object to the processing of your data — the ARCO rights under Mexico's LFPDPPP, with equivalent rights under the EU GDPR and applicable US state privacy laws. Contact us at jjdlr@simiriki.com with subject “Data Rights” and we respond within 20 business days.
simiriki operates as a 100% cloud-native, paperless service. Our infrastructure choices prioritize energy efficiency:
Every process we automate for our clients eliminates repetitive manual tasks, reduces energy consumption from desktop workstations, and replaces paper-based compliance workflows with cloud-native alternatives.
We welcome responsible disclosure of security vulnerabilities. See our Responsible Disclosure Policy for details. We acknowledge reports within 72 hours and provide safe harbor for good-faith researchers.