Security at SimFusion
Your data, models, and intellectual property are protected by enterprise-grade security infrastructure and practices.
Type II Certified
AES Encryption
Uptime SLA
Compliant
Data Protection
Encryption at rest and in transit with industry-leading algorithms.
Access Control
Multi-factor authentication and role-based permissions.
Monitoring
24/7 security monitoring and automated threat detection.
Our Security Commitment
At SimFusion, security is not an afterthought—it's foundational to everything we build. We understand that you trust us with your proprietary models, sensitive data, and intellectual property. We take that responsibility seriously.
Our security program is built on three core principles: Confidentiality (your data is accessible only to authorized parties), Integrity (your data cannot be altered without authorization), and Availability (your data is accessible when you need it).
Data Encryption
Encryption in Transit
All data transmitted between your browser and our servers is protected using TLS 1.3, the latest and most secure version of the Transport Layer Security protocol. This ensures that your data cannot be intercepted or tampered with during transmission.
- TLS 1.3 for all connections
- Perfect Forward Secrecy (PFS) enabled
- HSTS (HTTP Strict Transport Security) enforced
- Regular SSL Labs A+ rating
Encryption at Rest
All stored data is encrypted using AES-256, the same encryption standard used by governments and financial institutions worldwide. This includes:
- User account information and credentials
- Model configurations and simulation data
- Uploaded datasets and files
- Custom block code and metadata
- Backups and archived data
Infrastructure Security
Cloud Infrastructure
SimFusion runs on Amazon Web Services (AWS) and Google Cloud Platform (GCP), benefiting from their world-class security infrastructure:
- SOC 2 Type II and ISO 27001 certified data centers
- Physical security with biometric access controls
- Redundant power, cooling, and networking
- DDoS protection and mitigation
- Network segmentation and VPC isolation
Network Security
- Web Application Firewall (WAF) for threat filtering
- Intrusion Detection and Prevention Systems (IDS/IPS)
- Automated vulnerability scanning
- Rate limiting and abuse prevention
- IP allowlisting for Enterprise customers
Access Control and Authentication
Multi-Factor Authentication (MFA)
We strongly recommend and support MFA for all accounts. You can enable:
- Time-based One-Time Passwords (TOTP) via authenticator apps
- Hardware security keys (WebAuthn/FIDO2)
- SMS-based verification (less secure, not recommended)
Role-Based Access Control (RBAC)
Enterprise customers can define granular permissions:
- Project-level access controls
- Read-only, editor, and admin roles
- Custom permission sets
- Team and organization management
Single Sign-On (SSO)
Enterprise plans support SSO integration with:
- SAML 2.0 (Okta, OneLogin, Azure AD, etc.)
- OIDC / OAuth 2.0
- Just-in-Time (JIT) provisioning
- SCIM for automated user provisioning
Data Privacy and Compliance
Compliance Certifications
Data Residency
Enterprise customers can choose where their data is stored:
- United States (US-East, US-West)
- European Union (Frankfurt, Ireland)
- United Kingdom (London)
- Asia Pacific (Singapore, Tokyo, Sydney)
Data Processing Agreements
We offer Data Processing Agreements (DPAs) for Enterprise customers to ensure compliance with GDPR, CCPA, and other privacy regulations. Contact our sales team for more information.
Application Security
Secure Development Lifecycle
Security is integrated into every phase of our development process:
- Threat modeling for new features
- Automated static code analysis (SAST)
- Dependency vulnerability scanning (SCA)
- Dynamic application security testing (DAST)
- Regular penetration testing by third-party firms
- Bug bounty program for responsible disclosure
Code Security
- All code changes require peer review
- No production secrets in source code
- Automated secrets scanning
- Signed commits and build artifacts
- Immutable infrastructure deployments
Operational Security
Security Monitoring
Our Security Operations Center (SOC) monitors our infrastructure 24/7:
- Real-time log analysis and correlation
- Automated anomaly detection
- Threat intelligence integration
- Incident response playbooks
- Mean time to detect (MTTD): <5 minutes
Backup and Recovery
- Automated daily backups with 30-day retention
- Point-in-time recovery for up to 7 days
- Geo-redundant backup storage
- Quarterly disaster recovery drills
- RTO (Recovery Time Objective): 4 hours
- RPO (Recovery Point Objective): 1 hour
Incident Response
Despite our best efforts, security incidents can occur. We have a comprehensive incident response plan:
- Detection: Automated monitoring and user reports
- Containment: Immediate isolation of affected systems
- Investigation: Root cause analysis and impact assessment
- Notification: Affected users notified within 72 hours as required by law
- Remediation: Fix vulnerabilities and prevent recurrence
- Post-Incident: Lessons learned and process improvements
Your Security Responsibilities
Security is a shared responsibility. To keep your account secure:
- Use a strong, unique password (we recommend a password manager)
- Enable multi-factor authentication (MFA)
- Regularly review account activity and access logs
- Keep your email account secure (it's used for password resets)
- Report suspicious activity immediately to security@simfusion.io
- Ensure your team members follow security best practices
Security Reporting
Report a Security Issue
If you discover a security vulnerability, please report it responsibly. We have a bug bounty program for qualifying reports.
We commit to:
- Acknowledging receipt of your report within 24 hours
- Providing an initial assessment within 72 hours
- Keeping you informed of our progress
- Not taking legal action against researchers who follow responsible disclosure
- Recognizing contributors in our Security Hall of Fame (with permission)
Security Updates
We continuously improve our security posture. For the latest security updates and advisories, subscribe to our security newsletter or follow our status page.
This Security Overview is updated regularly. Last reviewed: March 18, 2026.
Trusted By Industry Leaders
Security certifications and audit reports available to Enterprise customers under NDA.