Legal & trust center

Security Overview

A transparent description of the safeguards currently built into TrainerSim.

Effective · Version 1.0

This public document explains our standard operating terms and practices. A signed order, enterprise agreement, or negotiated DPA may contain additional terms.

Security approach

TrainerSim applies layered controls across the browser, application, database, provider boundary, and operational workflow. This page describes implemented practices; it does not claim SOC 2, ISO 27001, or another independent certification.

Identity and tenant access

  • Authenticated accounts and role-based authorization for platform, organization, manager, and learner functions.
  • Row-level and application-level controls designed to separate organization data.
  • Administrative creation and editing separated from learner practice surfaces.
  • Server-side service credentials that are not exposed to the browser.

Data and media protection

  • TLS in transit and provider-managed encryption at rest.
  • Private recording storage with owner-aware authorization and short-lived signed replay URLs.
  • Bounded upload types and sizes, URL validation, and privacy filtering for website context.
  • Billing through Stripe so full card numbers are not stored by TrainerSim.
  • Sensitive values and URL query secrets excluded or redacted from support-page context and operational events.

Application and provider controls

  • Content Security Policy, HSTS, Permissions Policy, Referrer Policy, and MIME-sniffing protection on the production application.
  • Signed webhook verification, idempotency controls, authenticated Edge Functions, and rate limiting for exposed services.
  • Consent-gated microphone, camera, screen sharing, recording, and co-browsing interactions.
  • Validated element highlighting for embedded guidance; support agents cannot arbitrarily operate hidden page controls.

Operations and shared responsibility

We test core learner, administrator, billing, provider, and support workflows before releases and monitor production health. Customers remain responsible for role assignments, lawful content, user consent, endpoint security, configured retention, and human review of consequential outputs.

Report a concern

Send suspected vulnerabilities or security incidents to support@trainersim.com with enough detail to reproduce the issue. Do not access, alter, retain, or disclose data beyond what is necessary to demonstrate a good-faith finding.

Questions about this document?

Contact Pacific Wave Digital at support@trainersim.com. We are based in Port Vila, Vanuatu.