Skip to content
— SECURITY & COMPLIANCE

Enterprise-grade security,
by design.

Multi-tenant isolation at the database layer, an issued SOC 2 Type II report, and a security posture built for asset-heavy industries that can't afford a breach.

SOC 2 Type I · Report IssuedSOC 2 Type II · Report IssuedData Protection · Built InAccess Controls · Active
— ARCHITECTURE

Defense in depth.
Every layer hardened.

Six independent controls that compound. We protect data the way operations teams protect uptime — with redundancy, observability, and an incident playbook that doesn't depend on a single person being awake.

01 / CONTROL

Multi-Tenant Isolation

Complete data isolation between tenants using row-level security policies. Your data never mingles with other organizations.

  • PostgreSQL row-level security
  • Tenant-scoped API endpoints
  • Isolated storage buckets
  • Cross-tenant access prevention
02 / CONTROL

Role-Based Access Control

Granular permission system with customizable roles. Control exactly who can see and do what.

  • Pre-built role templates
  • Custom role creation
  • Feature-level permissions
  • Department scoping
03 / CONTROL

Audit Logging

Comprehensive audit trails for every action. Know who did what, when, and from where.

  • Immutable audit records
  • User action tracking
  • Data change history
  • Export for compliance
04 / CONTROL

Encryption

Industry-standard encryption for data at rest and in transit. Your data is protected at every layer.

  • TLS 1.3 in transit
  • AES-256 at rest
  • Encrypted backups
  • Key rotation policies
05 / CONTROL

Authentication

Enterprise SSO support with MFA. Secure access without compromising convenience.

  • SAML 2.0 SSO (Enterprise)
  • Multi-factor authentication
  • Session management
  • Password policies
06 / CONTROL

Infrastructure

Hosted on enterprise-grade cloud infrastructure with redundancy and disaster recovery.

  • AWS / GCP infrastructure
  • Multi-region availability
  • Automated backups
  • DDoS protection
— COMPLIANCE

Frameworks
we report against.

SOC 2 Type I and Type II reports issued, Security trust services category. Every framework below maps to controls your auditors and procurement reviewers will recognize.

SOC 2 Type I

Report Issued

SOC 2 Type I examination completed by Advantage Partners under the AICPA SOC for Service Organizations framework. Security trust services category, verified at a point in time.

SOC 2 Type II

Report Issued

SOC 2 Type II report issued by Advantage Partners. Security trust services category, examined across a three-month observation window (March 12 – June 12, 2026) — controls tested for operating effectiveness over time, not just design.

Data Protection

Built In

Row-level tenant isolation, AES-256 encryption at rest, TLS 1.3 in transit, and data export capabilities.

Access Controls

Active

Role-based access control, MFA support, session management, and comprehensive audit logging.

Infrastructure Security

Active

AWS cloud hosting with WAF, automated backups, DDoS protection, and encrypted storage.

— INDEPENDENTLY EXAMINED

The attestation package.

SMMS has completed both SOC 2 Type I and SOC 2 Type II examinations, performed by Advantage Partners under the AICPA SOC for Service Organizations framework. The Type II report covers the Security trust services category across a three-month observation window, testing that our controls operated effectively over time. Report available under NDA.

AICPA SOC for Service OrganizationsSOC 2 Type I report issued — Security category, controls verified at a point in timeSOC 2 Type II report issued — Security category, observation window March 12 to June 12, 2026Advantage Partners — SOC 2 Type I examination, Security category
— RESPONSIBLE DISCLOSURE

Found something?
Tell us first.

We take security vulnerabilities seriously. If you believe you've found a security issue in SMMS, please report it responsibly. We appreciate your help in keeping SMMS and our customers safe.

Questions about security?

Our security team is happy to discuss your specific requirements and answer any questions about our practices.