Security
SimCenter runs on computers inside your business. That is a serious thing to ask of anyone, so this page says how to tell us when something is wrong, and what we have actually built rather than what we intend to.
Reporting a problem
Email security@simcenter.io. If that bounces for any reason, use matthew@simcenter.io — it reaches the same person.
Please include what you found, how to reproduce it, and what you think it lets someone do. A rough email beats a polished one that never gets sent.
What we promise in return
- We will acknowledge your report within 3 business days.
- We will tell you honestly whether we think it is a real problem, and why.
- We will tell you when it is fixed.
- We will credit you by name if you want it, and stay quiet about you if you don't.
SimCenter is run by one person. We have no bug bounty and cannot pay for reports — we would rather say so plainly than imply otherwise.
Safe harbour
If you are researching in good faith, we will not pursue legal action or ask anyone else to. Good faith means: only touch accounts and venues that are yours, don't run attacks that degrade the service for real venues, don't access or keep anyone else's data, and give us a reasonable chance to fix things before going public.
If you find you can reach another customer's data, please stop there and tell us. You do not need to prove the point by collecting it.
How the software is built
The honest way to judge a small vendor is to ask what a break-in would actually reach. These are the decisions that shape that answer.
The agent on your PCs
- It makes outbound connections only. It opens no listening port and needs no inbound firewall rule, so it does not widen the way into your network.
- It reports machine health — hardware, devices, running process names, network reachability. It does not capture screens, keystrokes, documents or window contents. The exact list is on the privacy page.
- It talks to one origin over HTTPS, and refuses to be redirected to another server that cannot prove it is ours.
The service
- No third-party code. SimCenter is written against the Node.js and PowerShell standard libraries with zero external packages. There is no dependency tree to be compromised, which removes the most common way small products get breached.
- Passwords are stored as scrypt hashes with a unique per-account salt, and compared in constant time. We cannot recover your password, only reset it.
- Session cookies are
HttpOnly,SameSite=LaxandSecure, so they are not readable by scripts and are not sent across sites. - Card details never reach our servers. Payments run through Stripe, and their webhooks are verified by signature with a replay window.
- Camera and outlet passwords you enter are never returned by the API — not to you, not to anyone. Responses are built from an explicit list of fields, so a credential cannot start leaking because someone added a field later.
- Your venues are isolated from each other, and that isolation is covered by automated tests that run on every change rather than being assumed.
- Traffic is HTTPS end to end. Data is backed up nightly.
Your data is yours
You can export everything SimCenter holds about your account, or delete the account outright, from inside the app. Neither requires emailing us and waiting.
What we are still improving
Listing this seems more useful than implying the work is finished:
- Signed agent updates. Stations keep themselves current automatically. We are adding cryptographic signing to that channel so a station will run only code we have signed, rather than trusting the connection alone. The signing certificate is in progress.
- Independent review. We have not had an external penetration test. We would rather say that than let the absence be assumed either way.
Things we will never do
- Email you asking for your password. We cannot read it and have no use for it.
- Ask for remote access to your PCs to "verify" something, out of the blue.
- Sell your data, or hand it to anyone without a legal obligation to.
If you get a message claiming to be from SimCenter that does any of those, it is not from us. Forward it to security@simcenter.io.