Trust and safety

Security and data protection

Keep account access, customer data, AI logs, billing and communication channels protected when using SIMCOAI.

Protect accounts and customer recordsUnderstand legal and policy acceptance gatesUse AI safely with human review
Security works best when account, billing and operational controls are used together.
Security works best when account, billing and operational controls are used together.
Account security

Protect dashboard access

Use strong passwords, OAuth from trusted providers, authenticator app MFA where available, and role-based access for team members.

  • Remove users who no longer work for the business
  • Use business email accounts where possible
  • Do not share one login across a team
  • Review billing and account changes regularly
Customer data

Handle customer information carefully

SIMCOAI should only receive data needed to answer, route or log the customer task. Sensitive information, especially card numbers, should not be requested or stored in AI chat or voice logs.

Escalate payment details to secure payment flows.

Avoid uploading unnecessary personal data.

Use legal pages and your own business policies to explain customer handling.

Sign-in

Ways you and your team sign in

Sign‑in runs through a hosted login page rather than a form embedded in the dashboard. You are sent to it from the SIMCOAI login screen, you sign in there, and you are returned to your dashboard. Your password is never typed into a SIMCOAI page, and SIMCOAI never stores it.

These methods are available depending on what is enabled for your account:

  • Password with a secure reset link.
  • Passkeys and passwordless sign‑in (Windows Hello, Touch/Face ID, 1Password, iCloud Keychain, Android) — nothing to phish.
  • Google and Microsoft accounts, where those connections are enabled for your account.
  • Email sign‑in link & 6‑digit code — one email gives both.
  • Multi‑factor authentication with an authenticator app, and Remember me for trusted browsers.
  • Verified email — an address has to be confirmed before it can reach account data.

Signing out ends your SIMCOAI session and the hosted login session, so the next sign‑in starts fresh rather than silently reusing the last identity.

Which methods you see depends on your account. Turning on multi‑factor authentication and passkeys reduces risk; no sign‑in method removes it entirely, and you are still responsible for who you invite and what they can reach.
Integrations

API keys and webhook secrets

Create scoped API keys for server‑to‑server work; the secret is shown once, so store it safely and rotate it when staff or suppliers change. Webhook signing secrets are also shown once. Never handle secret keys or signing secrets from a browser.

Policies

Legal acceptance gates

The dashboard can block feature access until required policy versions are accepted. This keeps business-use confirmation, privacy, cookies, AI, billing and telecoms terms tied to backend records.

Terms and policies

Required for new accounts and paid feature use.

Audit logs

Important security and compliance events are recorded.

The public voice demo

The demo on the SIMCOAI homepage is a real AI turn, not a recording. If you use the microphone, the short clip is sent to SIMCOAI, transcribed, answered, and the reply is returned as audio in the SIMCOAI voice. It is a demonstration on sample data: it is not connected to any customer account, it cannot read or change real orders, refunds, bookings or escalations, and it is capped at a small number of turns per session. Do not type or say anything into it that you would not want handled as demo input — real customer details, card numbers or passwords do not belong there.

Where your data lives

Login and account‑security details — your email address, sign‑in events, multi‑factor and passkey enrolments, and the identifier from any Google or Microsoft account you sign in with — are handled by the hosted login service. Your business operational data (business profile, customer records, call and conversation logs, workflow history) is stored separately on SIMCOAI‑controlled infrastructure and is not sent to the login service.

Account data separation

Your business data is separated from every other account, and writes are restricted to the service itself rather than being open to client applications.