Simpplr
simpplr.com · Retail operations · checked 2026-09-05
Rank 4 of 34 in Retail operations, where the median is 28.
- 7 found
- 5 not found
- 0 not measured
We measured 12 of 12 criteria for Simpplr on 2026-09-05. We found 7 with a source and did not find 5 at the addresses we checked. That is a transparency score of 61 out of 100, band C.
Overview
Transparency labelsaas-ranking.com
Simpplr
- A
- B
- C
- D
- E
- F
Published commitments5 of 9 found
- foundData processing agreement×3
- not foundSubprocessor list×3
- foundData location stated×3
- foundStatus page with history×2
- not foundPublic pricing×2
- foundNotice before subprocessors change×2
- foundCertifications named×1
- not foundUptime SLA with a figure×1
- not foundNamed privacy contact×1
Measured behaviour2 of 3 found
- foundHTTPS enforced with HSTS×2
- not foundNo third-party tracking before consent×2
- foundsecurity.txt (RFC 9116)×1
Checked 2026-09-05. Every line links the page we found it on. A cross means we found nothing at the addresses we checked, not that the vendor has no such document. A transparency score, not a product rating.
The evidence pack carries every criterion with its source, the addresses we checked, the date and the data snapshot id – the four things a procurement file needs and a screenshot loses. We do not issue badges: a badge is the first step towards a paid placement, and there is none here.
The label is the whole measurement in one object: every criterion with its weight, the band, and the date. Public transparency score, not a product or security rating.
Every line in it links the page we found the result on, or lists the addresses we checked. A cross means we found nothing there, not that Simpplr has no such document.
What they state
The exact figures and names we read off the pages linked below, with the sentence they stand in. This is what they publish, not what we verified about their systems.
- Named on that page HIPAA (named without a certification claim), ISO/IEC 27001, PCI DSS (named without a certification claim), SOC 2 (unclear from the sentence), SOC 2 Type II.
Show the 5 exact wordings
HIPAA Simpplr complies with HIPAA standards, securing communication and collaboration with all key stakeh
Read at https://www.simpplr.com/security-compliance/Compliance Trust in Simpplr for industry compliance across the board ISO 27001 Simpplr is ISO 27001:2022 certified annually.
Read at https://www.simpplr.com/security-compliance/11 (US, Life Sciences/Pharmaceutical) GXP (US, Life Sciences/Pharmaceutical) FERPA (US, Education) PCI DSS (Global, Ecommerce) This is a partial list.
Read at https://www.simpplr.com/security-compliance/Note that a SOC 2 audit of a software vendor itself, in addition to audits of any subprocessor or cloud platform on w
Read at https://www.simpplr.com/security-compliance/SOC 2 Simpplr annually undergoes a SOC 2 Type 2 audit.
Read at https://www.simpplr.com/security-compliance/ - Locations named next to the hosting wording United States.
Show the exact wording
and agree that such Personal Data may be transferred from your current location to the offices and servers of Simpplr and the authorized third parties referred to herein located in the United States (...
Read at https://www.simpplr.com/privacy/ - Third-party hosts we saw on the first load 1 googletagmanager.com.
Show the exact wording
www.googletagmanager.com
Read at https://simpplr.com/ - HSTS max-age 31536000 seconds (365 days).
Show the exact wording
max-age=31536000; includeSubDomains; preload
Read at https://simpplr.com/ - HSTS options includeSubDomains, preload.
Show the 2 exact wordings
max-age=31536000; includeSubDomains; preload
Read at https://simpplr.com/max-age=31536000; includeSubDomains; preload
Read at https://simpplr.com/ - The file expires 2027-03-31. It was still valid when we checked on 2026-09-05.
Show the exact wording
Expires: 2027-03-31T19:00:00.000Z
Read at https://www.simpplr.com/.well-known/security.txt
Gaps, heaviest first
Subprocessor list
weight 3 of 3No subprocessor list found.
Checked 7 addresses on 2026-09-05.
Show the 7 addresses we checked
https://simpplr.com/legal/subprocessors– reached, no match (HTTP 404)https://simpplr.com/subprocessors– reached, no match (HTTP 404)https://simpplr.com/sub-processors– reached, no match (HTTP 404)https://simpplr.com/legal/sub-processors– reached, no match (HTTP 404)https://simpplr.com/trust/subprocessors– reached, no match (HTTP 404)https://simpplr.com/privacy/subprocessors– reached, no match (HTTP 404)https://simpplr.com/legal/subprocessor-list– reached, no match (HTTP 404)
Public pricing
weight 2 of 3No public pricing with figures found.
Checked 5 addresses on 2026-09-05.
Show the 5 addresses we checked
https://simpplr.com/pricing– reached and rendered, no matchhttps://simpplr.com/pricing/– reached, no match (HTTP 200)https://simpplr.com/plans– reached, no match (HTTP 404)https://simpplr.com/en/pricing– reached, no match (HTTP 200)https://simpplr.com/pricing-plans– reached, no match (HTTP 404)
No third-party tracking before consent
weight 2 of 3No consent-free first load found.
- Third-party hosts we saw on the first load 1 googletagmanager.com.
Show the exact wording
www.googletagmanager.com
Read at https://simpplr.com/
Checked 1 address on 2026-09-05.
Show the 1 address we checked
https://simpplr.com/– third-party requests before any interaction: www.googletagmanager.com
Uptime SLA with a figure
weight 1 of 3No uptime figure found.
Checked 6 addresses on 2026-09-05.
Show the 6 addresses we checked
https://simpplr.com/legal/sla– reached, no match (HTTP 404)https://simpplr.com/sla– reached, no match (HTTP 200)https://simpplr.com/legal/service-level-agreement– reached, no match (HTTP 404)https://simpplr.com/trust/sla– reached, no match (HTTP 200)https://simpplr.com/uptime– reached, no match (HTTP 404)https://simpplr.com/legal/uptime-sla– reached, no match (HTTP 404)
Named privacy contact
weight 1 of 3No named privacy contact found.
Checked 7 addresses on 2026-09-05.
Show the 7 addresses we checked
https://simpplr.com/legal/privacy– reached, no match (HTTP 404)https://simpplr.com/privacy– reached, no match (HTTP 200)https://simpplr.com/privacy-policy– reached, no match (HTTP 404)https://simpplr.com/legal/privacy-policy– reached, no match (HTTP 404)https://simpplr.com/legal/privacy-notice– reached, no match (HTTP 404)https://simpplr.com/trust/privacy– reached, no match (HTTP 200)https://simpplr.com/datenschutz– reached, no match (HTTP 404)
Evidence
The full source lists sit behind these two groups, so that the answer above stays readable.
Published, with a source 7
Data processing agreement
weight 3 of 3Published and readable without a login.
Source: https://www.simpplr.com/security-compliance/dpa/ · checked 2026-09-05
Data location stated
weight 3 of 3The hosting location is stated on a public page.
- Locations named next to the hosting wording United States.
Show the exact wording
and agree that such Personal Data may be transferred from your current location to the offices and servers of Simpplr and the authorized third parties referred to herein located in the United States (...
Read at https://www.simpplr.com/privacy/
Source: https://www.simpplr.com/privacy/ · checked 2026-09-05
Status page with history
weight 2 of 3A public status page with incident history.
Source: https://status.simpplr.com/ · checked 2026-09-05
HTTPS enforced with HSTS
weight 2 of 3HTTP redirects to HTTPS and the HSTS header is set.
- HSTS max-age 31536000 seconds (365 days).
Show the exact wording
max-age=31536000; includeSubDomains; preload
Read at https://simpplr.com/ - HSTS options includeSubDomains, preload.
Show the 2 exact wordings
max-age=31536000; includeSubDomains; preload
Read at https://simpplr.com/max-age=31536000; includeSubDomains; preload
Read at https://simpplr.com/
Source: https://simpplr.com/ · checked 2026-09-05
Notice before subprocessors change
weight 2 of 3The vendor commits publicly to giving notice before the list changes.
Source: https://www.simpplr.com/security-compliance/dpa/ · checked 2026-09-05
Certifications named
weight 1 of 3SOC 2 or ISO 27001 named on a public page.
- Named on that page HIPAA (named without a certification claim), ISO/IEC 27001, PCI DSS (named without a certification claim), SOC 2 (unclear from the sentence), SOC 2 Type II.
Show the 5 exact wordings
HIPAA Simpplr complies with HIPAA standards, securing communication and collaboration with all key stakeh
Read at https://www.simpplr.com/security-compliance/Compliance Trust in Simpplr for industry compliance across the board ISO 27001 Simpplr is ISO 27001:2022 certified annually.
Read at https://www.simpplr.com/security-compliance/11 (US, Life Sciences/Pharmaceutical) GXP (US, Life Sciences/Pharmaceutical) FERPA (US, Education) PCI DSS (Global, Ecommerce) This is a partial list.
Read at https://www.simpplr.com/security-compliance/Note that a SOC 2 audit of a software vendor itself, in addition to audits of any subprocessor or cloud platform on w
Read at https://www.simpplr.com/security-compliance/SOC 2 Simpplr annually undergoes a SOC 2 Type 2 audit.
Read at https://www.simpplr.com/security-compliance/
Source: https://www.simpplr.com/security-compliance/ · checked 2026-09-05
security.txt (RFC 9116)
weight 1 of 3Served at /.well-known/security.txt.
- The file expires 2027-03-31. It was still valid when we checked on 2026-09-05.
Show the exact wording
Expires: 2027-03-31T19:00:00.000Z
Read at https://www.simpplr.com/.well-known/security.txt
Source: https://www.simpplr.com/.well-known/security.txt · checked 2026-09-05
History
Not enough completed runs yet to draw a line. The next runs fill this in.
Compare
A shortlist holds up to six vendors across categories and lives entirely in the address of its page: share the link, bookmark it, put it in a ticket. Nothing is stored, so we do not know it exists.