Trust & Security

Security at SimFusion

Your data, models, and intellectual property are protected by enterprise-grade security infrastructure and practices.

SOC 2

Type II Certified

256-bit

AES Encryption

99.99%

Uptime SLA

GDPR

Compliant

Data Protection

Encryption at rest and in transit with industry-leading algorithms.

Access Control

Multi-factor authentication and role-based permissions.

Monitoring

24/7 security monitoring and automated threat detection.

Our Security Commitment

At SimFusion, security is not an afterthought—it's foundational to everything we build. We understand that you trust us with your proprietary models, sensitive data, and intellectual property. We take that responsibility seriously.

Our security program is built on three core principles: Confidentiality (your data is accessible only to authorized parties), Integrity (your data cannot be altered without authorization), and Availability (your data is accessible when you need it).

Data Encryption

Encryption in Transit

All data transmitted between your browser and our servers is protected using TLS 1.3, the latest and most secure version of the Transport Layer Security protocol. This ensures that your data cannot be intercepted or tampered with during transmission.

  • TLS 1.3 for all connections
  • Perfect Forward Secrecy (PFS) enabled
  • HSTS (HTTP Strict Transport Security) enforced
  • Regular SSL Labs A+ rating

Encryption at Rest

All stored data is encrypted using AES-256, the same encryption standard used by governments and financial institutions worldwide. This includes:

  • User account information and credentials
  • Model configurations and simulation data
  • Uploaded datasets and files
  • Custom block code and metadata
  • Backups and archived data

Infrastructure Security

Cloud Infrastructure

SimFusion runs on Amazon Web Services (AWS) and Google Cloud Platform (GCP), benefiting from their world-class security infrastructure:

  • SOC 2 Type II and ISO 27001 certified data centers
  • Physical security with biometric access controls
  • Redundant power, cooling, and networking
  • DDoS protection and mitigation
  • Network segmentation and VPC isolation

Network Security

  • Web Application Firewall (WAF) for threat filtering
  • Intrusion Detection and Prevention Systems (IDS/IPS)
  • Automated vulnerability scanning
  • Rate limiting and abuse prevention
  • IP allowlisting for Enterprise customers

Access Control and Authentication

Multi-Factor Authentication (MFA)

We strongly recommend and support MFA for all accounts. You can enable:

  • Time-based One-Time Passwords (TOTP) via authenticator apps
  • Hardware security keys (WebAuthn/FIDO2)
  • SMS-based verification (less secure, not recommended)

Role-Based Access Control (RBAC)

Enterprise customers can define granular permissions:

  • Project-level access controls
  • Read-only, editor, and admin roles
  • Custom permission sets
  • Team and organization management

Single Sign-On (SSO)

Enterprise plans support SSO integration with:

  • SAML 2.0 (Okta, OneLogin, Azure AD, etc.)
  • OIDC / OAuth 2.0
  • Just-in-Time (JIT) provisioning
  • SCIM for automated user provisioning

Data Privacy and Compliance

Compliance Certifications

SOC 2 Type II
GDPR Compliant
CCPA Compliant
ISO 27001 Ready

Data Residency

Enterprise customers can choose where their data is stored:

  • United States (US-East, US-West)
  • European Union (Frankfurt, Ireland)
  • United Kingdom (London)
  • Asia Pacific (Singapore, Tokyo, Sydney)

Data Processing Agreements

We offer Data Processing Agreements (DPAs) for Enterprise customers to ensure compliance with GDPR, CCPA, and other privacy regulations. Contact our sales team for more information.

Application Security

Secure Development Lifecycle

Security is integrated into every phase of our development process:

  • Threat modeling for new features
  • Automated static code analysis (SAST)
  • Dependency vulnerability scanning (SCA)
  • Dynamic application security testing (DAST)
  • Regular penetration testing by third-party firms
  • Bug bounty program for responsible disclosure

Code Security

  • All code changes require peer review
  • No production secrets in source code
  • Automated secrets scanning
  • Signed commits and build artifacts
  • Immutable infrastructure deployments

Operational Security

Security Monitoring

Our Security Operations Center (SOC) monitors our infrastructure 24/7:

  • Real-time log analysis and correlation
  • Automated anomaly detection
  • Threat intelligence integration
  • Incident response playbooks
  • Mean time to detect (MTTD): <5 minutes

Backup and Recovery

  • Automated daily backups with 30-day retention
  • Point-in-time recovery for up to 7 days
  • Geo-redundant backup storage
  • Quarterly disaster recovery drills
  • RTO (Recovery Time Objective): 4 hours
  • RPO (Recovery Point Objective): 1 hour

Incident Response

Despite our best efforts, security incidents can occur. We have a comprehensive incident response plan:

  1. Detection: Automated monitoring and user reports
  2. Containment: Immediate isolation of affected systems
  3. Investigation: Root cause analysis and impact assessment
  4. Notification: Affected users notified within 72 hours as required by law
  5. Remediation: Fix vulnerabilities and prevent recurrence
  6. Post-Incident: Lessons learned and process improvements

Your Security Responsibilities

Security is a shared responsibility. To keep your account secure:

  • Use a strong, unique password (we recommend a password manager)
  • Enable multi-factor authentication (MFA)
  • Regularly review account activity and access logs
  • Keep your email account secure (it's used for password resets)
  • Report suspicious activity immediately to security@simfusion.io
  • Ensure your team members follow security best practices

Security Reporting

Report a Security Issue

If you discover a security vulnerability, please report it responsibly. We have a bug bounty program for qualifying reports.

We commit to:

  • Acknowledging receipt of your report within 24 hours
  • Providing an initial assessment within 72 hours
  • Keeping you informed of our progress
  • Not taking legal action against researchers who follow responsible disclosure
  • Recognizing contributors in our Security Hall of Fame (with permission)

Security Updates

We continuously improve our security posture. For the latest security updates and advisories, subscribe to our security newsletter or follow our status page.

This Security Overview is updated regularly. Last reviewed: March 18, 2026.

Trusted By Industry Leaders

Security certifications and audit reports available to Enterprise customers under NDA.