Enterprise-grade security,
by design.
Multi-tenant isolation at the database layer, an issued SOC 2 Type II report, and a security posture built for asset-heavy industries that can't afford a breach.
Defense in depth.
Every layer hardened.
Six independent controls that compound. We protect data the way operations teams protect uptime — with redundancy, observability, and an incident playbook that doesn't depend on a single person being awake.
Multi-Tenant Isolation
Complete data isolation between tenants using row-level security policies. Your data never mingles with other organizations.
- PostgreSQL row-level security
- Tenant-scoped API endpoints
- Isolated storage buckets
- Cross-tenant access prevention
Role-Based Access Control
Granular permission system with customizable roles. Control exactly who can see and do what.
- Pre-built role templates
- Custom role creation
- Feature-level permissions
- Department scoping
Audit Logging
Comprehensive audit trails for every action. Know who did what, when, and from where.
- Immutable audit records
- User action tracking
- Data change history
- Export for compliance
Encryption
Industry-standard encryption for data at rest and in transit. Your data is protected at every layer.
- TLS 1.3 in transit
- AES-256 at rest
- Encrypted backups
- Key rotation policies
Authentication
Enterprise SSO support with MFA. Secure access without compromising convenience.
- SAML 2.0 SSO (Enterprise)
- Multi-factor authentication
- Session management
- Password policies
Infrastructure
Hosted on enterprise-grade cloud infrastructure with redundancy and disaster recovery.
- AWS / GCP infrastructure
- Multi-region availability
- Automated backups
- DDoS protection
Frameworks
we report against.
SOC 2 Type I and Type II reports issued, Security trust services category. Every framework below maps to controls your auditors and procurement reviewers will recognize.
SOC 2 Type I
Report IssuedSOC 2 Type I examination completed by Advantage Partners under the AICPA SOC for Service Organizations framework. Security trust services category, verified at a point in time.
SOC 2 Type II
Report IssuedSOC 2 Type II report issued by Advantage Partners. Security trust services category, examined across a three-month observation window (March 12 – June 12, 2026) — controls tested for operating effectiveness over time, not just design.
Data Protection
Built InRow-level tenant isolation, AES-256 encryption at rest, TLS 1.3 in transit, and data export capabilities.
Access Controls
ActiveRole-based access control, MFA support, session management, and comprehensive audit logging.
Infrastructure Security
ActiveAWS cloud hosting with WAF, automated backups, DDoS protection, and encrypted storage.
The attestation package.
SMMS has completed both SOC 2 Type I and SOC 2 Type II examinations, performed by Advantage Partners under the AICPA SOC for Service Organizations framework. The Type II report covers the Security trust services category across a three-month observation window, testing that our controls operated effectively over time. Report available under NDA.




Found something?
Tell us first.
We take security vulnerabilities seriously. If you believe you've found a security issue in SMMS, please report it responsibly. We appreciate your help in keeping SMMS and our customers safe.
Questions about security?
Our security team is happy to discuss your specific requirements and answer any questions about our practices.