Security Architecture
How we protect customer identity and isolate sandbox simulation execution.
1. Zero-Trust Sandbox Isolation
Every incident drill runs inside an ephemeral, hardware-isolated microVM or WebAssembly sandbox. Sandboxes are provisioned on-demand with restricted memory and CPU quotas, and destroyed immediately upon simulation completion. No state persists across different user sessions.
2. Zero Production Access to Client Infrastructure
It Works In Prod never requests API keys, cloud credentials, SSH keys, or read/write access to your company’s internal infrastructure (AWS, GCP, Azure, Kubernetes clusters). All incident simulations are 100% self-contained synthetic topology environments generated in our isolated runtime.
3. Data Encryption Standards
In Transit: All web traffic and terminal WebSockets are enforced over HTTPS / WSS using TLS 1.3 with strict HSTS policies.
At Rest: Subscriber data and telemetry records are encrypted using AES-256 with automatically rotated encryption keys.
4. Responsible Disclosure Policy
We take security vulnerabilities seriously. If you believe you have discovered a security vulnerability in our infrastructure or simulation sandboxes, please report it immediately to our security response team. We will acknowledge receipt within 24 hours.