Security at SIMY

Your code and conversations are protected by design, not afterthought.

Infrastructure & Encryption

Encryption in Transit

All data is encrypted using TLS 1.3 during transmission between your devices, our servers, and third-party integrations.

Encryption at Rest

Data stored on our servers is encrypted using AES-256. Database backups are also encrypted.

Cloud Infrastructure

Hosted on AWS/GCP with industry-standard security controls, network isolation, and regular security patching.

Access Controls

Role-based access control (RBAC), multi-factor authentication for internal systems, and principle of least privilege.

Data Handling by Plan

Enterprise data is never used for AI training. Standard and Pro plan data may be used to improve our models. See our Privacy Policy for full details.

FeatureStandard / ProEnterprise
Data encryption (transit & rest)
AI model training opt-outBy requestDefault
Data isolation
SSO / SAML
Audit logs
Custom data retention

Compliance Roadmap

We are committed to achieving industry-standard compliance certifications. Our current status:

CertificationStatusTarget
GDPR ComplianceActive
CCPA ComplianceActive
SOC 2 Type IIPlanned2026
HIPAAPlanned2027
ISO 27001Planned2027

Responsible Disclosure

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.

Report a Vulnerability

Email with details of the vulnerability. We aim to acknowledge reports within 24 hours and provide a resolution timeline within 72 hours.