Security
Last updated August 2026.
Local-first architecture. Simulations run in your browser on your own device. Your models and parameters stay local unless you explicitly save them to your account or share them — which means most of your work never touches our servers at all.
Encryption in transit. The entire site is served over HTTPS/TLS. Traffic between your browser and our infrastructure is encrypted.
Authentication. Sign-in is handled by our identity provider (Clerk). We never see or store your password. Session tokens are managed by the provider using industry-standard practices.
Payments. All payments are processed by Stripe. Card numbers and payment credentials go directly to Stripe and are never stored on our servers — we only retain non-sensitive billing metadata (plan, status).
Hosting. The application is hosted on managed cloud infrastructure with automatic patching and DDoS protection at the edge.
Data minimization. We collect the minimum needed to run your account: email, name, and plan status. We do not sell your data.
Responsible disclosure. Found a vulnerability? Please report it to security@polysimos.com. We appreciate coordinated disclosure and will respond promptly.
Note: PolySim OS is an educational and exploratory simulation tool. It is not certified for safety-critical, clinical, or operational decision-making. See our Terms and Acceptable Use.