From b5d9f8253a82aa1099a1b90ab685aed2b0f5153f Mon Sep 17 00:00:00 2001 From: Sim Pi Agent Date: Sat, 19 Sep 2026 02:05:59 +0000 Subject: [PATCH 1/3] docs(blog): update enterprise --- apps/sim/content/blog/enterprise/index.mdx | 36 +++++++++++----------- 1 file changed, 18 insertions(+), 18 deletions(-) diff --git a/apps/sim/content/blog/enterprise/index.mdx b/apps/sim/content/blog/enterprise/index.mdx index 137a79fe142..366fe69f784 100644 --- a/apps/sim/content/blog/enterprise/index.mdx +++ b/apps/sim/content/blog/enterprise/index.mdx @@ -3,11 +3,11 @@ slug: enterprise title: 'Sim for Enterprise' description: 'Access control, BYOK, self-hosted deployments, on-prem Copilot, SSO & SAML, whitelabeling, Admin API, and flexible data retention—enterprise features for teams with strict security and compliance requirements.' date: 2026-02-11 -updated: 2026-08-31 +updated: 2026-09-19 authors: - - vik -readingTime: 10 -tags: [Enterprise, Security, Self-Hosted, SSO, SAML, Compliance, BYOK, Access Control, Copilot, Whitelabel, API, Import, Export] + - andrew +readingTime: 6 +tags: [Enterprise, Security, Compliance, AI Agents, Sim] ogImage: /blog/enterprise/cover.jpg ogAlt: 'Sim Enterprise features overview' about: ['Enterprise Software', 'Security', 'Compliance', 'Self-Hosting'] @@ -16,29 +16,29 @@ canonical: https://www.sim.ai/blog/enterprise featured: true draft: false faq: - - q: "Is Sim SOC 2 certified, and can we get a copy of the report for vendor review?" - a: "Sim maintains SOC 2 Type II certification with annual audits covering security, availability, and confidentiality controls, and shares the report directly with prospective customers under NDA. Sim also provides penetration test reports, architecture documentation, and completed security questionnaires (SIG, CAIQ, and custom formats) for vendor review." - - q: "Can we restrict which model providers or integrations are available to certain teams?" - a: "Yes, through permission groups that are enforced at the execution layer, not just hidden in the UI. Administrators can allowlist approved model providers so unapproved ones fail to execute, disable specific workflow blocks like HTTP calls, and block integrations that haven't cleared security review — while users outside any permission group keep full access by default." - - q: "Does Sim offer SLAs and dedicated support?" - a: "SLA terms and dedicated support are established through direct engagement with Sim during the enterprise sales and deployment process rather than through a published self-service SLA. Enterprise customers also work directly with Sim on requirements such as data retention policies, while self-hosted deployments provide full control over the underlying infrastructure." + - q: "Does Sim have a SOC 2 Type II report, and can we get a copy for vendor review?" + a: "Yes. Sim maintains a SOC 2 Type II report based on annual examinations of security, availability, and confidentiality controls. Sim shares the report directly with prospective customers under NDA and also provides penetration test reports, architecture documentation, and completed security questionnaires in SIG, CAIQ, and custom formats." + - q: "What does Sim provide for an enterprise security review?" + a: "Sim provides its SOC 2 Type II report under NDA, penetration test reports, architecture documentation, and completed security questionnaires for enterprise security reviews. Reviewers can also evaluate SSO through SAML 2.0 or OIDC, permission groups enforced at the execution layer, configurable data-retention policies for execution traces, BYOK with customer-managed model credentials, and self-hosted deployment on customer infrastructure." + - q: "How are SLAs and dedicated support handled?" + a: "Sim sets SLA terms and dedicated support arrangements during the enterprise evaluation. Contact Sim to confirm response times, availability commitments, escalation paths, and support coverage for your deployment." - q: "Does Sim support VPC or on-premises deployment?" a: "Yes, Sim can run entirely within your own network or infrastructure using Docker Compose or Helm charts for Kubernetes. Deployment options include single-node, high-availability, and air-gapped configurations, with the application, WebSocket server, and PostgreSQL database remaining inside your environment." - q: "Does Sim support data residency across regions?" - a: "Sim supports regional data handling through self-hosting in your chosen region or BYOK routing to your own model provider, rather than through a built-in multi-region hosting guarantee. Self-hosting keeps the application, WebSocket server, and database within your network, while BYOK can route model traffic directly to providers such as Azure OpenAI or AWS Bedrock." + a: "Self-hosting lets you deploy Sim in infrastructure located in your chosen region. BYOK lets you select a model provider and account configuration that meet your residency requirements. Confirm hosted-service region availability directly with Sim. Self-hosting keeps the application, WebSocket server, and database within your network, while BYOK can route model traffic directly to providers such as Azure OpenAI or AWS Bedrock." - q: "Can teams roll back a deployed agent to a previous version?" - a: "Yes, teams can roll back to a previous version because each workflow deployment creates a version snapshot. The Admin API also exposes version history for integration with change management processes." + a: "Yes. Each workflow deployment creates a version snapshot that administrators can use to restore an earlier version. The Admin API also exposes version history for integration with change management processes." - q: "Can admins set budget caps or track spend per team?" - a: "Sim does not describe numeric per-team budget caps or a per-team spend dashboard; its documented cost-control mechanism is provider and feature allowlisting through permission groups. Admins can restrict model providers, integrations, and platform capabilities by team, while BYOK lets teams use their own provider's billing dashboards and spend controls." + a: "The capabilities described here do not include numeric per-team budget caps or a per-team spending dashboard. Administrators can restrict model providers, integrations, and platform features by permission group. With BYOK, spending controls and usage reporting depend on the configured model provider." - q: "Does using our own LLM API keys (BYOK) keep our data from passing through Sim's servers?" - a: "Yes. When you configure your own API keys for providers like OpenAI, Anthropic, Google, Azure OpenAI, or AWS Bedrock, prompts and completions route directly between Sim and that provider without passing through Sim's infrastructure. BYOK is available to everyone, not just enterprise plans, and is the default with no Sim-managed keys involved in self-hosted deployments." + a: "BYOK makes Sim use your credentials for providers such as OpenAI, Anthropic, Google, Azure OpenAI, or AWS Bedrock. In Sim's hosted service, confirm the request path and processing boundaries during your security review. In a self-hosted deployment, Sim runs in your infrastructure and sends requests to the model provider you configure. BYOK is available to everyone, not just enterprise plans, and is the default with no Sim-managed keys involved in self-hosted deployments." - q: "Can Copilot be used without sending workflow data to an external AI service?" - a: "Yes. Copilot can run entirely within a self-hosted deployment using your own LLM keys, so prompts containing context from your workflows, execution logs, and workspace configuration route directly to your chosen provider and never leave your network." + a: "Yes, if Copilot uses a model endpoint hosted within your network. Customer-owned API keys alone do not keep data on-premises when the selected provider runs externally. Copilot requests may include workflow context, execution logs, and workspace configuration." - q: "What identity providers does Sim support for SSO, and what happens when an employee is deprovisioned?" - a: "Sim integrates with Okta, Azure AD (Entra ID), Google Workspace, OneLogin, Auth0, JumpCloud, Ping Identity, ADFS, and any SAML 2.0 or OIDC compliant identity provider. IdP deprovisioning blocks future SSO authentication but does not currently remove Sim membership or revoke active Sim sessions, so offboarding must also remove or suspend access in Sim." + a: "Sim integrates with Okta, Microsoft Entra ID (formerly Azure AD), Google Workspace, OneLogin, Auth0, JumpCloud, Ping Identity, ADFS, and other identity providers that support SAML 2.0 or OIDC. Sim uses your IdP configuration for authentication and account access. Logout behavior and deprovisioning timing can depend on session settings, so verify both during implementation." --- -We've been working with security teams at larger organizations to bring Sim into environments with strict compliance and data handling requirements. This post covers the enterprise capabilities we've built: granular access control, bring-your-own-keys, self-hosted deployments, on-prem Copilot, SSO & SAML, whitelabeling, compliance, and programmatic management via the Admin API. +Sim supports enterprise deployments with access controls, customer-managed model credentials, self-hosting, SSO, compliance documentation, and programmatic administration. These capabilities help larger organizations deploy Sim under strict security, compliance, and data-handling requirements. This guide explains how each control works and which deployment requirements it addresses. ## Access Control @@ -189,7 +189,7 @@ For teams practicing GitOps, export workflows to your repository and use the Adm ## Get Started -Enterprise features are available now. Check out our [self-hosting](https://docs.sim.ai/platform/self-hosting) and [enterprise](https://docs.sim.ai/platform/enterprise) docs to get started. +Enterprise features are available now. Check out our [self-hosting](https://docs.sim.ai/platform/self-hosting) and [enterprise](https://docs.sim.ai/platform/enterprise) docs to get started. Teams comparing deployment options can also use our guides to [enterprise AI agent platforms](https://www.sim.ai/library/best-ai-agent-platforms-for-enterprise-teams-2026), the [AI workflow automation buyer's checklist](https://www.sim.ai/library/ai-workflow-automation-platform-buyers-checklist), and [AI agents in procurement](https://www.sim.ai/library/ai-agents-in-procurement). *Questions about enterprise deployments?* From b7a70899d8c818576f3000b10a3526019774a4fa Mon Sep 17 00:00:00 2001 From: Sim Pi Agent Date: Sat, 19 Sep 2026 02:12:33 +0000 Subject: [PATCH 2/3] Pi Babysit: address PR #8002 feedback --- apps/sim/content/blog/enterprise/index.mdx | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/apps/sim/content/blog/enterprise/index.mdx b/apps/sim/content/blog/enterprise/index.mdx index 366fe69f784..8e2f1e9507f 100644 --- a/apps/sim/content/blog/enterprise/index.mdx +++ b/apps/sim/content/blog/enterprise/index.mdx @@ -11,7 +11,7 @@ tags: [Enterprise, Security, Compliance, AI Agents, Sim] ogImage: /blog/enterprise/cover.jpg ogAlt: 'Sim Enterprise features overview' about: ['Enterprise Software', 'Security', 'Compliance', 'Self-Hosting'] -timeRequired: PT10M +timeRequired: PT6M canonical: https://www.sim.ai/blog/enterprise featured: true draft: false @@ -35,7 +35,7 @@ faq: - q: "Can Copilot be used without sending workflow data to an external AI service?" a: "Yes, if Copilot uses a model endpoint hosted within your network. Customer-owned API keys alone do not keep data on-premises when the selected provider runs externally. Copilot requests may include workflow context, execution logs, and workspace configuration." - q: "What identity providers does Sim support for SSO, and what happens when an employee is deprovisioned?" - a: "Sim integrates with Okta, Microsoft Entra ID (formerly Azure AD), Google Workspace, OneLogin, Auth0, JumpCloud, Ping Identity, ADFS, and other identity providers that support SAML 2.0 or OIDC. Sim uses your IdP configuration for authentication and account access. Logout behavior and deprovisioning timing can depend on session settings, so verify both during implementation." + a: "Sim integrates with Okta, Microsoft Entra ID (formerly Azure AD), Google Workspace, OneLogin, Auth0, JumpCloud, Ping Identity, ADFS, and other identity providers that support SAML 2.0 or OIDC. With SSO alone, IdP deprovisioning blocks future SSO authentication but does not remove Sim membership or revoke active Sim sessions, so offboarding must also remove or suspend access in Sim." --- Sim supports enterprise deployments with access controls, customer-managed model credentials, self-hosting, SSO, compliance documentation, and programmatic administration. These capabilities help larger organizations deploy Sim under strict security, compliance, and data-handling requirements. This guide explains how each control works and which deployment requirements it addresses. From 9b7fe49a2d231e2d225f8fca849fe752bf56dd89 Mon Sep 17 00:00:00 2001 From: Waleed Date: Fri, 18 Sep 2026 22:24:52 -0700 Subject: [PATCH 3/3] Change author in enterprise blog index Updated author name from 'andrew' to 'vik'. --- apps/sim/content/blog/enterprise/index.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/sim/content/blog/enterprise/index.mdx b/apps/sim/content/blog/enterprise/index.mdx index 8e2f1e9507f..d9a1869ba0b 100644 --- a/apps/sim/content/blog/enterprise/index.mdx +++ b/apps/sim/content/blog/enterprise/index.mdx @@ -5,7 +5,7 @@ description: 'Access control, BYOK, self-hosted deployments, on-prem Copilot, SS date: 2026-02-11 updated: 2026-09-19 authors: - - andrew + - vik readingTime: 6 tags: [Enterprise, Security, Compliance, AI Agents, Sim] ogImage: /blog/enterprise/cover.jpg