Trust

Product security capabilities designed for scoped access, protected data flows, and safer simulation handling.

This page describes product security capabilities and architectural controls. It does not claim formal certification unless a separate certification record exists and has been publicly disclosed.

Security statement

This page describes product security capabilities, deployment expectations, and architectural safeguards. It does not claim a formal certification, attestation, or audit result unless that record is separately documented and publicly provided.

Authentication

The platform includes authenticated role-based access patterns and is structured to support stronger authentication workflows over time, including MFA-ready extension points.

RBAC

Role-based access control separates super admin, organization admin, manager, and employee experiences so users land inside the correct workflow boundary.

Tenant isolation

Organization scoping is treated as a core architectural rule across dashboards, records, exports, simulations, and AI-assisted workflows.

Encryption in transit

Deployments are expected to use HTTPS in production so browser-to-application traffic is protected in transit.

Encryption at rest

Sensitive settings such as provider credentials are designed for encrypted storage, and private file handling is used for protected assets where appropriate.

Audit logging

The platform includes audit-oriented logging patterns for sensitive or operationally important actions such as exports, generation workflows, and access-related events.

Secure file handling

Protected downloads, simulation assets, and voice-related files are intended to stay in controlled storage paths with signed access where needed.

Backups

Operational deployments should include backup and recovery procedures appropriate to the hosting environment and organizational requirements.

Incident response

Organizations should pair the platform with their own incident response processes. The product is designed to preserve evidence, logs, and scoped reporting that can support those workflows.

Data retention

Retention expectations should be set according to organizational policy, legal review, and deployment requirements rather than assumed by default.

AI data handling

AI-related requests should remain scoped, logged, and configurable. Platform capabilities should not be interpreted as claims about an external provider’s contractual or certification posture unless separately documented.

Responsible simulation safety

The platform is designed around controlled training environments. Product capabilities emphasize safe simulated interactions rather than real credential capture, real malware, or uncontrolled external attack reproduction.

Key safeguards

Signed interaction routes for simulations and protected downloads.

Scoped access rules, structured logging, and protected storage patterns.

Simulation safety controls that distinguish training from real-world attack execution.

Review the platform with your security or trust stakeholders.

Request a demo if you want to walk through access controls, reporting workflows, simulation safety, and deployment expectations in more detail.