> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://docs.simplebooklet.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Simplebooklet Data Encryption Overview

# Simplebooklet Data Encryption Overview

Simplebooklet Marketing Inc. | Effective December 1, 2024

[View & Download](https://simplebooklet.com/simplebookletdataencryptionoverview)

|| To download: Click the link above to open the document. Once it's open, click the **Download** button in the navbar at the bottom of the page to save a copy.

---

## Purpose

This document outlines how **Simplebooklet** encrypts and protects customer data across all layers of its platform — including transport encryption (SSL/TLS), custom domain certificate management, and storage encryption within our hosting infrastructure.

Our goal is to ensure data confidentiality, integrity, and authenticity throughout the lifecycle of every booklet and user interaction.

## 1. Encryption in Transit

### 1.1 Standard SSL/TLS Encryption

All data transmitted between users, readers, and Simplebooklet's servers is protected using **TLS 1.2 or higher** encryption protocols.

This includes:

* Data uploaded through the Simplebooklet web app (e.g., PDFs, images, designs)
* Reader sessions viewing published booklets
* Administrative dashboard traffic
* API communication between services (Customer.io, Paddle, ProfitWell, etc.)

Every Simplebooklet URL is automatically served over HTTPS, ensuring that no data — including authentication tokens, analytics events, or media — is ever sent in plaintext.

### 1.2 Wildcard Certificates for Custom Domains

For customers using **custom branded domains** (e.g., brochure.yourcompany.com), Simplebooklet issues and manages **Wildcard SSL Certificates** through a trusted Certificate Authority.

* Certificates are generated, renewed, and validated automatically using **Let's Encrypt Wildcard SSL** (via DNS-based verification).
* This ensures every custom domain benefits from **end-to-end HTTPS** coverage without requiring manual certificate installation.
* Wildcard certificates are stored in encrypted form within our secure infrastructure and rotated regularly.

**Example:**
```
https://marketing.acmebrochure.com
→ protected via *.acmebrochure.com wildcard certificate
→ handled through Simplebooklet's secure SSL termination and CDN edge servers
```

## 2. Encryption at Rest

### 2.1 File and Data Storage

All data stored within Simplebooklet's hosting environment (Liquid Web) is **encrypted at rest using AES-256** industry-standard encryption algorithms.

This includes:

* Uploaded documents, images, and assets
* Generated previews and metadata
* Reader engagement logs and analytics data
* Account credentials and configuration data (hashed and salted)

### 2.2 Backup and Redundancy

Nightly backups of data and configuration are:

* Encrypted using **AES-256 before replication**
* Stored in separate secure environments within Liquid Web
* Retained only as long as necessary for operational recovery (max 30 days)

Encryption keys are securely managed by Liquid Web's key management systems and are never exposed to Simplebooklet employees or third parties.

## 3. Certificate and Key Management

* SSL/TLS certificates (both standard and wildcard) are renewed automatically every **90 days**.
* Private keys are stored in restricted-access directories within encrypted Liquid Web storage volumes.
* Administrative access to certificate systems is restricted to authorized DevOps personnel only, using **MFA** and **RBAC** policies.
* Key rotation and decommissioning procedures are logged and reviewed quarterly.

## 4. Compliance and Best Practices

Simplebooklet's encryption practices align with recognized security standards including:

* **NIST SP 800-57** (Key Management Best Practices)
* **ISO/IEC 27001:2022** (Information Security Management)
* **GDPR & PIPEDA** encryption expectations for protecting personal data

All encryption protocols and certificate management workflows are reviewed annually as part of our security and privacy policy updates.

## Summary

Through the use of **Wildcard SSL certificates**, **TLS-encrypted transport**, and **AES-256 encrypted storage**, Simplebooklet ensures that every customer asset — from uploaded documents to reader sessions — remains secure, authenticated, and private throughout its lifecycle.