Security

Version: v1.0 Effective Date: 1 September 2025 Last Updated: 9 October 2026

Trust Center — Security, privacy, and compliance at Smartta

1. Our Commitment

At Smartplace Pty Ltd ("Smartta"), security is fundamental to everything we build. Our workforce governance platform handles sensitive employee data, compliance records, credential evidence, and payroll information. We take this responsibility seriously and have built our platform with security at every layer.

This page provides an overview of our security practices, compliance programme, and the measures we take to protect your data. If you have specific security questions or require a detailed security assessment, please contact security@smartplace.ai.

2. Compliance

We maintain a rigorous compliance programme aligned with industry standards and regulatory requirements.

SOC 2 Type II

Smartta is working towards SOC 2 Type II: readiness work is under way and no audit has been engaged.

ISO 27001

Smartta is preparing for certification to ISO/IEC 27001:2022; the certification audit is scheduled for October 2026.

Penetration Testing

Smartta’s first independent penetration test was commissioned in October 2026.

Smartta runs on Amazon Web Services. AWS’s ISO/IEC 27001 certificate and SOC 2 report cover the AWS services and Regions Smartta uses.

3. Privacy and Data Processing

We provide comprehensive data protection documentation and contractual safeguards:

  • Data Processing Agreement (DPA): Available for all enterprise customers. Includes Standard Contractual Clauses (SCCs) for international transfers and a UK International Data Transfer Addendum where applicable.
  • Data Usage Framework: Clear policies governing how customer data is used, stored, and protected.

For full details on our data handling practices, see our Privacy Policy.

4. Product Security

Our platform is designed with defence-in-depth security at every layer.

Authentication

  • Customer users can sign in with multi-factor authentication (authenticator app or passkey)
  • OAuth 2.0 for API authentication
  • Scoped JWT tokens with configurable expiry
  • Brute-force protection and account lockout policies

Authorization

  • Role-Based Access Control (RBAC) with granular permissions
  • Each customer’s data is held in its own database
  • Identity-Aware Proxy (IAP) for scoped external access

Auditing

  • Immutable evidence chain for compliance-critical operations
  • Tamper-evident records with cryptographic integrity checks

API Security

  • All APIs served over TLS 1.2+ exclusively
  • Rate limiting and throttling on all endpoints
  • Input validation and output encoding
  • CORS policies and CSRF protection

5. Infrastructure

Our platform is hosted on enterprise-grade cloud infrastructure with multiple layers of protection.

Cloud Hosting

Customer workforce data is stored in AWS Sydney (ap-southeast-2). Some supporting services — sign-in, email and SMS delivery, payments, bot checks and AI features — are provided by sub-processors outside Australia.

Network Security

Virtual Private Cloud (VPC) with private subnets, security groups, and network ACLs. No direct public internet access to data stores.

Web Application Firewall

AWS WAF is deployed in front of the production application in monitoring mode, and AWS Shield Standard applies.

6. Application Security

All code changes undergo peer review, with security considerations part of the review criteria.

7. Encryption

In Transit

All data transmitted between clients and our services is encrypted using TLS 1.2 or higher. We enforce HTTPS across all endpoints and HSTS headers are set on all responses.

At Rest

Production data volumes, snapshots and object storage are encrypted with AWS KMS (AES-256).

8. Identity and Access Management

Access to our production systems is tightly controlled:

  • Multi-factor authentication is enforced for staff sign-in to company systems (Google Workspace, GitHub and the company network)
  • Privileged access is time-bound, logged, and reviewed regularly
  • Access reviews are conducted quarterly to ensure appropriate access levels
  • Employee offboarding includes immediate revocation of all system access

9. Business Continuity

Our business continuity and disaster recovery plans ensure service availability and data durability.

24h Recovery Time Objective (RTO)

Maximum targeted duration for restoring services following a major disruption.

1h Recovery Point Objective (RPO)

Maximum acceptable data loss window. Regular encrypted snapshots limit data loss in a disaster scenario.

  • Production data volumes are snapshotted hourly and daily in AWS Sydney, encrypted, and kept for no more than 90 days
  • Restore is tested; the last test was on 30 September 2026

10. Incident Response

We maintain a formal incident response plan that covers identification, containment, eradication, recovery, and lessons learned. Key elements include:

  • Production is scanned for vulnerabilities continuously (AWS Inspector), with external scans at least quarterly
  • Defined severity levels with corresponding response timelines
  • Dedicated incident response team with clear roles and responsibilities
  • We notify affected customers without undue delay, and within 72 hours of confirming a breach affecting their data, and notify the OAIC where the Notifiable Data Breaches scheme requires it
  • Post-incident review and root cause analysis for all significant incidents
  • Regular incident response drills and tabletop exercises

11. Third-Party Services

Third-party services that have access to customer data are assessed for security before they are onboarded.

12. AI/ML Transparency

Where our Services use artificial intelligence or machine learning capabilities, we are committed to transparency:

  • Deterministic rule engines: Core compliance features (award interpretation, credential validation, care minutes calculations) use deterministic rule engines, not probabilistic AI models. That makes outcomes predictable, auditable and repeatable.
  • AI-assisted features: Where AI-assisted features are available (such as natural language queries or document extraction), they are clearly labelled as such.
  • Human oversight: Automated outputs are recommendations; Customers retain full control over acting on them.

13. Shared Responsibility Model

Security is a shared responsibility. While we secure the platform, infrastructure, and application layers, our customers play an important role in securing their own use of the Services:

Smartta is responsible for:

  • Securing the platform infrastructure and network
  • Maintaining encryption at rest and in transit
  • Patching and updating platform software
  • Monitoring for and responding to security threats
  • Maintaining its information security management system and the controls described on this page
  • Providing multi-factor authentication for customer users

Customers are responsible for:

  • Managing user accounts and access permissions within their tenant
  • Enabling and enforcing MFA for their users
  • Protecting their own API keys and credentials
  • Ensuring their authorised users comply with acceptable use policies
  • Reporting suspected security incidents promptly

14. Contact Us

For security questions, to report a vulnerability, or to request a security assessment:

Smartplace Pty Ltd (ACN 639 781 678)

C/- Margetson & Associates, Unit 21, 598-602 Forest Road, Penshurst, NSW 2222, Australia

Trust Center

Security documentation for due-diligence review is published at our Trust Center. Material not published there can be requested at hello@smartta.ai.

trust.smartta.ai

Related Legal Documents