Draft for legal review. This page is not a finished legal document and has not been reviewed by counsel. Simtelligence Technology Inc., incorporated in Alberta, operates this service.
Security overview
Draft for legal review. This is a description of the controls on the Simtelligence pilot, not a certification and not a penetration-test report. Simtelligence Technology Inc., incorporated in Alberta, operates the service.
Sign-in
The web app is an OpenID Connect client for Microsoft Entra, with PKCE. `ENTRA_ALLOWED_TENANTS` can limit which tenant ids are accepted. Password sign-in can stay on as a break-glass or be turned off. Sessions are httpOnly cookies. Workspace tokens for MCP are stored as a SHA-256 hash and shown once.
Isolation
Each user belongs to an organization. Models, runs, tokens, and the audit log are scoped to that organization. A request that names another organization's workspace is rejected. Viewers can read, validate, compare, and export. They cannot edit, run, chat, or create tokens.
Encryption
The public site is served over HTTPS. In production the web app sends HSTS. Azure encrypts PostgreSQL, Blob Storage, and Key Vault at rest with the platform default. Postgres, blobs, and Key Vault do not accept public data-plane traffic. The apps reach them through the virtual network.
Backups
PostgreSQL Flexible Server keeps automated backups, 7 days unless that is changed, with the geo-redundant copy in Canada East by default. A restore creates a new server. A logical dump procedure is in `docs/backup-restore.md`. Blob objects are not part of the database backup.
Logging
The audit log records sign-ins, membership changes, tokens, model edits, runs, and exports. Container stdout goes to Log Analytics in Canada Central and is kept for 30 days. Job workers log the queue depth as `queue_backlog=` so an alert can watch the backlog.
Rate limits and quotas
The web app, the API, and MCP each limit requests per minute per IP and per user or token. The default is 120 per minute on the web and API, and 60 on MCP when it is unset. Separately, each organization has quotas for runs per day, replications, simulated duration, concurrent jobs, assistant messages, and storage. Defaults come from the environment. A platform admin can override them. Zero means that quota is off.
Vulnerability scanning
GitHub Actions runs Ruff, dependency review via `pip-audit`, Gitleaks, Trivy on the built images for high and critical unfixed issues, and a workflow shell syntax check. It runs on pull requests to `main`, on pushes to `main`, and when someone starts it manually. A feature-branch push does not start a second run. CI does not call a real language model or Entra. CI does not deploy.
Contact
Use the contact form on the home page for a security question. Do not include a live secret in the message.