How Cymulate protects its platform, its people, and its customers' data — from certified governance and encryption to continuous threat detection and resilient operations.
Security at Cymulate starts at the top. A defined governance structure,
annual risk assessments, and a documented control environment hold the
program accountable and keep it improving.
Board & Management Oversight
The Board of Directors governs trust principles and challenges management decisions; steering and audit committees meet periodically. Day-to-day security is led by a dedicated CISO with executive support.
Annual Risk Assessment
An Internal Audit function performs a yearly risk assessment across employees, assets, development, and customer operations.
Policies & Code of Conduct
An Information Security Policy is reviewed and updated at least annually by the CISO. Every employee reads and accepts the Code of Conduct, with probation, suspension, or termination as consequences for misconduct.
Endpoint Security (AV/EDR)
EDR is deployed across all Cymulate endpoints and servers, extending beyond traditional antivirus. A centralized console continuously detects and notifies on malicious or suspicious activity, and lets the Security Team remotely manage affected machines and initiate remediation when needed.
02Assurance
Compliance & Certifications
Cymulate undergoes continuous, independent audits to verify that its controls meet recognized international standards for security, privacy, and cloud assurance.
SOC 2 Type II & SOC 3
Independent attestation by an independent external auditor across Security, Availability, Confidentiality, and Privacy Trust Services Criteria. The public SOC 3 report covers May 2024–Apr 2025.
ISO/IEC 27001
Information Security Management System certification governing how Cymulate manages and protects information assets.
ISO/IEC 27701
Privacy Information Management extension to ISO 27001, governing the handling of personal data.
ISO/IEC 27017
Code of practice for information security controls specific to cloud services.
Compliance backed by a Data Protection Officer, a published Privacy Policy, and a Data Processing Addendum (DPA).
Continuous, not point-in-time
Audits and assessments recur on defined cycles rather than as one-off events, so controls are validated against industry standards on an ongoing basis. Cymulate did not identify any reportable system incidents during the SOC 2 examination period.
03Infrastructure
Cloud & Infrastructure Security
Cymulate platform runs on a private AWS tenant engineered for isolation, high availability, and redundancy across multiple regions.
Private AWS Tenant
Infrastructure is deployed in a private AWS tenant across multiple regions for maximum stability and availability.
Virtual Private Cloud (VPC)
Servers are isolated in Cymulate’s own VPC, protected by restricted security groups that allow only the minimum communication required to and between servers.
Physical Security (AWS)
Server hosting is entrusted to AWS data centers (ISO 27001, PCI DSS Level 1, SOC 2/3) with on-site guards, intrusion detection, fire suppression, backup power, and environmental controls.
Availability & Redundancy
Fully redundant, scalable, high-availability design across applications, network connectivity, switches/routers, firewalls, load balancers, and data storage — with replication across availability zones.
Network firewalls & segmentation protecting servers, monitored by the Security Team.
Advanced WAF and DDoS protection at the network edge.
Key Management Service (KMS) in place to ensure regular key rotation.
04Data Protection
Encryption & Data Protection
Customer data is encrypted everywhere it lives and everywhere it travels, with managed keys and additional protection for sensitive fields.
Encryption in Transit
All traffic is protected with HTTPS / TLS 1.2 or higher, securing data as it moves between users, the platform, and the agent.
Encryption at Rest
Data stored in databases and AWS is encrypted with AES-256. Sensitive values are further protected using salted hashes.
Managed Keys & Rotation
Key Management Service (KMS) is deployed, governing encryption keys and ensures keys are rotated on a regular basis
No PII / PCI Stored
Cymulate does not collect or store sensitive Personal Identifying Information or PCI-DSS cardholder data. Processed data is largely aggregated test results plus basic contact details.
05Build & Product
Application & Product Security
Security is built into the development lifecycle and exposed to customers as configurable product controls — validated by continuous testing and independent assessments.
Secure Development Lifecycle
Changes are managed end-to-end in a dedicated system; requests are reviewed by a forum of R&D, Product, and the CTO.
Two-reviewer peer code review and rigorous QA are required before any code is committed.
Logically separate development, testing, staging, and production environments.
Periodic secure-code training for engineers; every version is tested before customer release.
Vulnerability Management & Testing
OWASP Top 10
The platform is tested for OWASP Top 10 vulnerabilities on a periodic basis by qualified third parties.
Periodic Vulnerability Scanning
Network and Zero-Day vulnerability scanning is performed on a weekly cadence.
Periodic Penetration Test
Independent penetration testing and risk assessment at least annually, or after significant changes; critical findings are addressed promptly.
Application Security and Software Supply Chain Protection
We use OX Security to continuously identify, prioritize, and remediate application and software supply chain risks throughout the development lifecycle. Its unified, risk-based approach improves visibility, reduces alert noise, and enables our teams to focus on vulnerabilities that pose the greatest real-world risk.
Customer-Facing Authentication & Access
Two-Factor Authentication (2FA) enforced for the platform.
Single Sign-On (SSO) available as an optional integration.
Role-Based Access Control with three distinct permission levels.
IP address restrictions available to limit account access.
Strong password policy enforced for all accounts.
Tenant isolation ensures each customer sees only their own data.
06Access Control
Identity & Access Management
Internal access follows least-privilege and need-to-know principles, is granted through a controlled workflow, and is reviewed every month.
Least Privilege & RBAC
Access is granted only to resources needed for a role, using least-privilege and need-to-know. A Role-Based Access Control model is applied to every group an employee belongs to.
Per-application, per-asset
Roles with unique credentials for every employee.
VPN, firewalls, 2FA, and access control lists
Govern all remote access to assets.
07People
People & HR Security
Security culture is established from day one — through agreements, structured onboarding and offboarding, and continuous awareness training.
NDA & confidentiality agreements signed by every employee and critical supplier.
Workstation protection via centralized remote management and monitoring.
Code of Conduct covering conflict of interest, anti-fraud, anti-bribery, privacy, and duty to report.
08Detect & Respond
Threat Detection, Monitoring & Incident Response
Production is monitored continuously, suspicious activity is surfaced to the Security Team, and a structured incident-management process drives investigation through to root-cause analysis.
Endpoint Detection & Response
EDR is deployed across endpoints and servers to detect and respond to malicious activity, augmenting traditional antivirus.
Continuous Production Monitoring
Infrastructure, servers, and databases are monitored for resource consumption, availability, and anomalies; threshold breaches alert relevant stakeholders for timely resolution.
Firewall & Intrusion Monitoring
Firewalls and rule configurations defend servers against external threats; the Security Team monitors firewall consoles and investigates unusual activity until resolved.
Incident Management & RCA
A documented process covers detection, quarantine, resolution, recovery, and stakeholder reporting. High-severity incidents undergo formal Root Cause Analysis to improve resilience.
09Resilience
Business Continuity & Disaster Recovery
Preventing and mitigating disruption matters as much as recovering from it. Cymulate combines redundant infrastructure with frequent, tested backups and a documented recovery plan.
Frequent Encrypted Backups
Database backups are performed in accordance with the applicable backup and retention policies and are stored in a separate availability zone.
Tested Restores
Periodic test restores validate backup reliability and data integrity, with results reviewed and acted on by relevant stakeholders.
Redundant, High-Availability IaaS
AWS IaaS keeps Development, Testing, and Production continuously available with redundant applications, networking, load balancing, and storage.
10Platform
The Cymulate Agent
The lightweight agent that runs simulations is designed to communicate securely, authenticate uniquely per customer, and keep every action auditable by the client.
Secure Communication
Maintains a stable, encrypted channel to the Cymulate Cloud throughout simulations, running scheduled tests per the user’s dashboard actions.
Per-Customer Token
Every action performed by the agent requires a token that is generated uniquely for each customer.
Encrypted Credentials
Any passwords kept on the client’s agent are stored encrypted, never in clear text.
Full, client-accessible activity logging
All agent activity is recorded, and the resulting logs can be accessed directly by the client for transparency and audit.