simler

Security & Trust

We sell incident readiness. Ours included.

You trust simler with your policies, your plans, and how your team responds under pressure. Here is exactly how we protect that, without marketing gloss.

Encryption everywhere

All data is encrypted in transit (TLS) and at rest. Uploaded documents live in private storage buckets; downloads use short-lived signed URLs.

Hard tenant isolation

Every organization's data is isolated at the database level with row-level security. Isolation is enforced by the database itself, not just application code.

Passwordless authentication

Sign-in uses signed magic links: no passwords to phish, leak, or reuse. Role-based access separates admins from participants inside each organization.

AI data handling

Exercise generation sends your organization profile, selected documents, and session transcripts to the Anthropic API. API data is not used to train models, and we never train models on your data ourselves.

Auditable by design

Sessions are fully logged: transcripts, response times, and debrief reports give you the evidence trail NIS2 audits ask for, and us a clear record of what the platform did.

Responsible disclosure

Found a vulnerability? Tell us at info@simler.ai and we'll respond fast, fix it, and credit you if you want. We won't take legal action against good-faith research.

The connector security model

Exercises get sharper when they know your real organization — so simler can connect, read-only, to sources you already keep, via MCP (the open standard for connecting AI to existing software). That access is engineered to be grantable by a security team:

Read-only by design
Connectors can never write to or change your systems — there is no write path in the platform.
Scoped per source, per use case
Your admin picks exactly which sources simler may read, and which capability may use each one (scenario grounding, simulation agents, Ask).
Every query logged
Each read lands in an access log your admins can audit: which capability asked, on which source, with which outcome.
Revocable in one click
Withdraw a single source or the whole connection at any time; credentials are encrypted at rest and never leave our servers.

Compliance, honestly

We are an early-stage company and we won't pretend otherwise: SOC 2 and ISO 27001 certifications are on our roadmap, not on our wall. What we can say today: the platform is built GDPR-first (EU data residency for the primary database, documented subprocessors, data processing agreements available on request via info@simler.ai), it is designed to produce the exercise evidence NIS2 Article 21 asks of our customers, and we run our own incident tabletops on simler itself.

Questions our security page doesn't answer?

Security reviews and DPA requests welcome. We answer vendor-assessment questionnaires faster than most.