generated: '2026-08-13' method: searched probe: true source: https://www.simon.ai/terms/security note: >- Simon Data publishes a named security contact but no vulnerability disclosure programme. There is no /.well-known/security.txt on any Simon host (all 404), no bug bounty, no HackerOne/Bugcrowd/Intigriti presence and no responsible-disclosure page or safe-harbour statement. What exists is a security policy page carrying a direct address for the Simon Security Team. The automated probe returned none because the security page lives at /terms/security behind a 301 from /security; it was found by following the redirect. policy: [https://www.simon.ai/terms/security] contact: [security@simondata.com] bug_bounty: null safe_harbour: false security_txt: false disclosure_page: null security_program: soc2: SOC 2 Type 2, report and bridge letter available under NDA incident_response: documented — anomalous access patterns trigger the incident response process encryption_at_rest: AES-256 with per-customer provisioned keys encryption_in_transit: TLS 1.2 and SSHv2; no unencrypted protocols used within the platform logging: AWS and Snowflake access events logged and retained per SOC 2, read-only to prevent tampering policy_review: annually by the Security Team and Simon leadership evidence: - source: https://www.simon.ai/terms/security http_status: 200 kind: security-policy-page keywords: [security team, soc 2, incident response, 'security@simondata.com'] - source: https://www.simon.ai/security http_status: 301 kind: redirect note: 301 to https://www.simon.ai/terms/security - source: https://www.simon.ai/.well-known/security.txt http_status: 404 kind: security.txt - source: https://api.simondata.com/.well-known/security.txt http_status: 404 kind: security.txt