Security
Last updated 26 September 2026
Simmer is a young product and this page says what is actually true today, including the parts that are not finished. We would rather be checkable than impressive.
Keeping venues apart
Every venue's data is kept apart by the database itself, not only by Simmer's own code. Each record carries the business it belongs to, and the database will only hand back the ones belonging to whoever is signed in (the technical name is row-level security). So if we ever wrote a search that forgot to ask "whose venue is this?", it would find nothing rather than someone else's records. This is the one thing we test hardest, because it is the one thing that must never fail.
Accounts
- Passwords are scrambled one way before they are stored (with Argon2, a method built to be slow to crack), so nobody at Simmer can read them.
- Two-factor sign-in, where a code from an app on your phone is needed as well as the password, is available to every manager, with single-use recovery codes in case the phone is lost.
- Password resets expire in an hour, work once, and sign out every existing session.
- Whether someone may change who can reach a venue is checked against the database every time they try, not against what their browser remembers from signing in — so removing someone takes effect immediately.
Where it runs
Microsoft Azure, Australia East, in Sydney. Everything is encrypted on its way between your device and Simmer, and again where it is stored. Passwords Simmer itself uses to reach its database and other services are kept in a locked store (Azure Key Vault), not written into the code.
Backups
The database is backed up automatically, and we can wind it back to any moment in the last seven days. The copies are kept in the same Australian region. We rehearse restores with a script that copies the live database, restores it somewhere else, and checks that the structure, the rules keeping venues apart and the number of records all came back.
Being straight about the gap: those backups are not yet copied to a second region, so a whole-region failure is a real risk we have not removed. It is on the list before we take on a venue that cannot afford a bad day.
Your data is yours
Every guest, booking, recipe, invoice and roster belongs to the venue, not to Simmer. An owner can export the lot at any time from Settings (a zip of spreadsheet files), and that stays true if you leave. We never sell or share guest data, and we never use it to market to your guests on anyone else's behalf.
What we do not have yet
- No SOC 2 or ISO 27001 certification (the formal security audits large companies ask their suppliers for). We are too small for it to mean much yet, and claiming otherwise would be dishonest.
- No history of past outages. The status page checks from your browser and shows how things are right now. If something is down and stays down, contact us.
- No single sign-on (signing in with your company's Microsoft or Google account). Two-factor is the strongest option today.
- Backups are not yet copied to a second region.
Telling us about a problem
If you find a security issue, email security@simmer.au and we will get back to you. We will not take legal action against anyone who reports a problem in good faith and gives us a reasonable chance to fix it before telling anyone else.