The page your IT function reads before the deal proceeds.
This is not a marketing page and it does not read like one. Each row below is a statement Simcomm will be held to. Where a control is planned rather than present it says so, and where nothing is in place it says that too.
AcuityQ™ holds no security certification today. Any claim to the contrary on any page of this site is an error — please tell us at security@acuityq.ai and we will fix it.
Control by control
Where each control stands
Rows marked Confirm are being verified by Simcomm before launch and must not be relied on until the marker is gone. We would rather show you the marker than a sentence nobody has checked.
| Area | Position | State |
|---|---|---|
| Deployment model | Single-tenant database per customer, on shared application infrastructure. Confirm the deployment model actually offered, and whether a dedicated-infrastructure option exists. | Confirm |
| Where data sits | Application and database run in an Indian region. Data does not leave India in normal operation. Name the region and the hosting provider. Any exception — a processor outside India — must be listed below and in the privacy notice. | Confirm |
| Transport encryption | TLS 1.2 or above on every connection, with HSTS on all AcuityQ hosts. | In place |
| Encryption at rest | Database and backup volumes encrypted at rest. Confirm the cipher and who holds the keys, and say so here. | Confirm |
| Authentication | Username and password with configurable complexity and lockout, plus a session that expires on inactivity. | In place |
| Single sign-on | SAML / OIDC sign-on against your identity provider. State the quarter, or leave the row out. | Planned |
| Session handling | Server-side sessions with a bearer token, rotated on sign-in; a CSRF token is required on every state-changing request. | In place |
| Authorisation | Capability-based. A role is a set of named capabilities, not a tier, and records are additionally scoped by desk and customer segment. | In place |
| Audit | Every change to a governed object records who, what, from, to and when. The trail cannot be configured off and cannot be edited from the application. | In place |
| Audit retention | Audit entries are retained for the life of the record they describe. Confirm the retention period, and whether it differs from case and quote retention. | Confirm |
| Backups | Automated daily backup with a stated retention window and a tested restore. State the frequency, the retention window, the RPO and RTO you will actually commit to, and when the restore was last tested. | Confirm |
| Export | Customers can export their own data — organisations, contacts, cases, quotes, documents and audit entries — in a machine-readable format, at any time, without asking us. Confirm the formats and whether export is self-service today. | Confirm |
| Deletion on exit | On termination, a full export is provided and the tenant database is deleted within a stated window, backups included. State the window. It goes in the contract, so agree it with counsel first. | Confirm |
| Separation of duties | Simcomm staff access to a customer tenant requires a named, time-bound grant and is itself recorded in the audit trail. Confirm that support access works this way today. If it does not, say what it is instead — this is the question an IT auditor asks. | Confirm |
| Vulnerability disclosure | Reports to security@acuityq.ai. Acknowledged within two working days, with a triage outcome within ten. Someone has to own this mailbox and keep to the commitment. Agree it before it is printed. | Confirm |
| Penetration testing | Independent application penetration test, with a summary letter available under NDA. Name the quarter, or remove the row. | Planned |
| Certification | AcuityQ holds no security certification today. Where Simcomm is working towards one, it is named here with the standard and the target, and nothing more is claimed. | In place |
Sub-processors
Every third party that touches lead or customer data, named. If this list changes, customers under contract are told before the change takes effect.
The same list appears in the privacy notice, which is the version that carries legal weight.
| Processor | Purpose | Where |
|---|---|---|
| hosting provider | Application and database hosting | region |
| transactional e-mail | Acknowledgement and notification e-mail from acuityq.ai | region |
| Cloudflare | Turnstile — bot check on the website lead form | Global edge |
| analytics host | Cookie-free website analytics | region |
The website, separately
What acuityq.ai itself collects
This site is not the product. It collects less, and it is worth stating separately because the two are often confused in a security review.
One cookie, before consent
A first-party identifier so a repeat submission of the lead form can be recognised as the same person. No third party can read it. Nothing else is set until you accept.
No third-party fonts or scripts
Typefaces are served from this domain. There is no font CDN request, no tag manager and no advertising pixel — so your visit is not announced to anyone.
Lead data, 24 months
What you type into a form is held for 24 months from our last contact and then deleted. The browser never talks to the AcuityQ platform directly.
How a lead travels — no credential ever reaches the browser
The platform issues no long-lived API keys, and none could be held in a public website's JavaScript in any case. The browser only ever speaks to this site's own endpoint.
Reporting a vulnerability
Write to security@acuityq.ai with enough detail to reproduce the issue. You will get a human acknowledgement, not an auto-reply with a ticket number and nothing after it.
We will not take legal action over good-faith research that stays within the demonstration estate at demo.acuityq.ai, does not degrade the service for others, and does not access data belonging to anyone else. Please do not test against a customer's production tenant.
Security questionnaire?
Send it over. We answer in your format rather than asking you to read ours.