Privacy Policy

Last updated: 10 September 2026

SOCsimple respects your privacy. This Privacy Policy explains what information we collect, why we collect it, how we use it, and the choices available to you when you visit our website, request access to SOCsimple, or use the SOCsimple service.

1. Who we are

SOCsimple is a detection content management platform for Wazuh environments.

For purposes of this Privacy Policy, "SOCsimple," "we," "us," and "our" refer to the operator of the SOCsimple service, reachable at hello@socsimple.com.

2. Information we collect

We may collect information you provide directly to us, including:

When you use the service, SOCsimple may also process technical and operational information necessary to provide the product, such as:

The exact information processed may depend on the SOCsimple features you use and the Wazuh services you choose to connect.

Your security events

SOCsimple does not store your security events. When you connect a Wazuh indexer, SOCsimple reads events from it to measure how your detection content behaves, and keeps only the results of those measurements per rule: counts, rates, and how many distinct sources the events came from. Raw log lines and alert bodies are never written to SOCsimple's database or to its logs.

Two bounded exceptions exist, and we name them so the sentence above can be believed. When a rule's volume concentrates on one source, the name of that busiest source, usually a host name, is kept on the resulting finding for as long as the finding exists. When you paste a log sample to validate a change before deploying it, a one-line preview of that sample, at most 120 characters, is kept with the change record as evidence of the check. If the sample itself is shorter than that, the preview is the whole sample.

3. Wazuh credentials and connected environments

SOCsimple may require credentials or connection information in order to communicate with Wazuh components that you choose to connect.

We use this information only as necessary to provide the requested SOCsimple functionality, maintain the connection, and protect the service.

Wazuh credentials are encrypted at rest (AES-256-GCM) and are never returned to your browser: the connection settings show the address and username only. They are used solely to reach the Wazuh components you configured. Rotating the API user on your Wazuh manager withdraws SOCsimple's access at any time.

You are responsible for ensuring that you are authorized to connect SOCsimple to the Wazuh environments, infrastructure, and data you configure within the service.

4. How we use information

We may use information we collect to:

We may also use feedback you provide to improve SOCsimple.

5. Private beta

SOCsimple may be offered as a private or limited-access beta.

When you request access, we store the details you enter, send a confirmation to the email address you give, and check whether that address's domain can receive mail. A member of the SOCsimple team reviews every request by hand.

During the beta period, we may collect additional product feedback, diagnostic information, and usage information to understand how the service performs and where it can be improved.

Beta access does not mean that your information will be used for advertising or sold to advertisers.

6. How we share information

We do not sell your personal information.

We share information only with the service providers that operate parts of SOCsimple for us, and only what each needs:

No analytics, advertising or tracking provider receives anything: neither the website nor the application loads one, and both serve their own fonts rather than fetching them from a third party. When the application hits an interface error it sends a short report to SOCsimple itself, not to a third party: the kind of error, the page and environment, the time and the application build. It does not include your unsaved content. These providers may process information only as necessary to provide services to us and are subject to their own contractual and legal obligations. If we add a provider that handles your information, we will update this list.

We may also disclose information where reasonably necessary to:

7. Customer detection content

Detection content and configuration that you provide to SOCsimple remains yours or your organization's, subject to any rights held by third parties.

We use customer content only as necessary to provide, secure, support, and improve the service in accordance with these terms and any separate agreement with you.

We do not claim ownership of your Wazuh rules, decoders, CDB lists, or other detection content merely because they are processed by SOCsimple.

We do not use your content to train machine-learning models, and no SOCsimple feature sends your content to a third-party AI service. If that ever changes, this Policy will say so before it does.

8. Data retention

Today SOCsimple keeps what it stores for as long as your account exists. Your detection content, its history, findings, drafts, deployments and the activity record are kept in full, because the product's value is an honest record of what changed and when; findings, change records and the activity record are append-only and are never rewritten. Nothing is deleted on a time basis, with one exception: a sign-in session expires on its own after a period of inactivity.

Application logs go to our hosting provider's log system. By written policy they carry identifiers and outcomes only: never credentials, rule content, sample logs or alert bodies.

Archiving an account is an administrative state: outstanding invitations are invalidated and no new members can be invited, but it does not by itself end existing members' access or stop connected processing. Closing an account is handled on request to hello@socsimple.com and includes removing member access and stopping connected processing. Deletion of an account's data is likewise available on request, subject to legal, security and backup retention; there is no self-service closure or deletion yet. As the service matures we intend to add automatic retention limits, and we will update this Policy when we do.

9. Security

We use reasonable administrative, technical, and organizational measures designed to protect information processed by SOCsimple.

However, no internet service, software platform, or storage system can be guaranteed to be completely secure.

You are responsible for protecting your account credentials and for using appropriate credentials and permissions when connecting SOCsimple to your environments.

10. International processing

SOCsimple's application and its database are hosted in the United States: the application by our hosting provider, Replit, and the database by Replit's database service, Neon, in the AWS us-east-2 (Ohio) region. Email delivery through Resend is also processed in the United States. If you are located elsewhere, your information is transferred to and processed there. If we move hosting to another region or add a provider that processes information elsewhere, we will update this section before we do.

Where required, we will take appropriate measures relating to international transfers of personal information.

11. Your choices and rights

Depending on where you live and the applicable law, you may have rights regarding your personal information, including rights to request access, correction, deletion, or other restrictions on processing.

You may contact us at hello@socsimple.com to make a privacy-related request.

We may need to verify your identity before completing certain requests.

12. Cookies and similar technologies

SOCsimple sets one cookie: the sign-in session cookie, which is essential to operate the service (HttpOnly, SameSite=Lax, and Secure in production). The application also uses your browser's local storage for interface preferences and for Log test: your last five test inputs, and up to three samples per environment that you set aside to retest against a draft, are kept in full in your browser so you can reuse them. They are stored only in that browser, are not sent to SOCsimple until you run them again, and are removed when you clear the site's data. Neither the website nor the application sets analytics, advertising or tracking cookies.

If we ever introduce non-essential analytics or similar technologies, we will update this Policy and provide notice or choices where appropriate.

13. Third-party services

SOCsimple may integrate with or link to third-party services, including Wazuh and infrastructure or identity providers.

Their privacy practices are governed by their own terms and privacy policies. SOCsimple is not responsible for independent third-party services that you choose to use.

14. Changes to this Policy

We may update this Privacy Policy as SOCsimple develops.

If we make material changes, we may update the date above and provide additional notice where appropriate.

15. Contact

Questions about this Privacy Policy can be sent to: hello@socsimple.com