Simyl
simylflow

Built on AWS, encrypted throughout

Your team's retrospectives and insights deserve serious protection. Simyl runs entirely on AWS: data encrypted at rest with AES-256 and in transit with TLS 1.3, with security controls aligned with SOC 2 and ISO 27001 frameworks.

Security posturestatus
InfrastructureAWS
Encryption at restAES-256
Encryption in transitTLS 1.3
SOC 2 / ISO 27001aligned, not certified
GDPRcompliant
Source code storednever

Every claim on this page is one we can stand behind. Where we are not certified, we say so.

The AWS foundation

8 AWS compliance programs

Simyl is built entirely on Amazon Web Services, inheriting the security posture and compliance certifications that enterprises trust worldwide.

AWS programscope
Service Organization ControlsSOC 1/2/3
Information Security ManagementISO 27001
Cloud Security ControlsISO 27017
Cloud PrivacyISO 27018
Payment Card IndustryPCI DSS Level 1
Healthcare Data ProtectionHIPAA Eligible
US Government CloudFedRAMP
EU Data ProtectionGDPR Ready

These certifications apply to the AWS infrastructure services Simyl runs on. They are AWS's certifications, not ours: what they mean for you is that the hardware, networking, and managed services underneath your data are independently audited.

View AWS Compliance Programs

How we protect your data

6 application-level controls

Beyond AWS's infrastructure security, we implement additional controls at the application level to keep your data safe.

  • Encryption everywhere

    All data encrypted at rest using AES-256 and in transit using TLS 1.3. Your retrospective discussions and team insights are always protected.
  • Secure authentication

    Passwordless authentication via one-time codes. No passwords to steal, no credentials to leak. Enterprise SSO/SAML integration available.
  • Data segregation

    All data access is scoped by organization ID at the application layer. Enterprise customers can opt for dedicated single-tenant infrastructure.
  • Privacy by design

    Developer effectiveness metrics are private by default. Individual coaching notes visible only to the developer. You control what's shared.
  • Automatic backups

    Continuous backups with point-in-time recovery. Your data is replicated across multiple availability zones for durability.
  • Regional data residency

    Data stored in AWS US-East-1 (N. Virginia) by default. Enterprise customers can request specific regional deployment.

Our security stack

6 AWS managed services

Every component of Simyl runs on AWS managed services, minimizing our attack surface and maximizing your protection.

  • Amazon Cognito

    Identity & Access Management
    Managed authentication with MFA support
  • Amazon DynamoDB

    Primary Database
    Fully managed, encrypted, with automatic scaling
  • Amazon S3

    Data Storage
    99.999999999% durability, server-side encryption
  • AWS Lambda

    Application Compute
    Serverless, no persistent attack surface
  • Amazon CloudFront

    Content Delivery
    DDoS protection via AWS Shield
  • AWS WAF

    Web Application Firewall
    Protection against common web exploits

Our security practices

build · operate · respond

Infrastructure is only part of the equation. Here's how we build and operate Simyl securely.

Access controls

  • Role-based access control (RBAC) throughout the application
  • Principle of least privilege for all internal systems
  • Regular access reviews and audit logging
  • Separate environments for development and production

Application security

  • Input validation and sanitization on all user inputs
  • Protection against OWASP Top 10 vulnerabilities
  • Dependency scanning for known vulnerabilities
  • Secure software development lifecycle (SDLC)

Incident response

  • 24/7 infrastructure monitoring via AWS CloudWatch
  • Automated alerting for security anomalies
  • Documented incident response procedures
  • Customer notification within 72 hours for data breaches

Your data, your control

0 bytes of source code stored

Your retrospective data belongs to you. We don't sell it, we don't use it for advertising, and we don't train AI models on your content.

We never store your source code. Our GitHub, GitLab, and Bitbucket integrations only fetch commit metadata and PR statistics, not code content. Your intellectual property stays in your repositories.

Our AI features use Amazon Bedrock with your data processed in-region and never retained by the AI service. You can export your data anytime, and we honor deletion requests promptly.

  • No source code storage, ever
  • No data selling or advertising
  • AI processing with no data retention
  • Full data export available
  • Account deletion within 30 days

Need a DPA or security questionnaire?

We're happy to sign Data Processing Agreements and complete security questionnaires for enterprise customers.

Request Documentation

Need more? Let's talk.

For organizations with specific compliance requirements, we offer SSO/SAML integration, custom deployment options, dedicated support, audit logs, and custom data retention policies.