Security
Trust Center — Security, privacy, and compliance at Smartta
1. Our Commitment
At Smartplace Pty Ltd ("Smartta"), security is fundamental to everything we build. Our workforce governance platform handles sensitive employee data, compliance records, credential evidence, and payroll information. We take this responsibility seriously and have built our platform with security at every layer.
This page provides an overview of our security practices, compliance programme, and the measures we take to protect your data. If you have specific security questions or require a detailed security assessment, please contact security@smartplace.ai.
2. Compliance
We maintain a rigorous compliance programme aligned with industry standards and regulatory requirements.
SOC 2 Type II
Smartta is working towards SOC 2 Type II: readiness work is under way and no audit has been engaged.
ISO 27001
Smartta is preparing for certification to ISO/IEC 27001:2022; the certification audit is scheduled for October 2026.
Penetration Testing
Smartta’s first independent penetration test was commissioned in October 2026.
Smartta runs on Amazon Web Services. AWS’s ISO/IEC 27001 certificate and SOC 2 report cover the AWS services and Regions Smartta uses.
3. Privacy and Data Processing
We provide comprehensive data protection documentation and contractual safeguards:
- Data Processing Agreement (DPA): Available for all enterprise customers. Includes Standard Contractual Clauses (SCCs) for international transfers and a UK International Data Transfer Addendum where applicable.
- Data Usage Framework: Clear policies governing how customer data is used, stored, and protected.
For full details on our data handling practices, see our Privacy Policy.
4. Product Security
Our platform is designed with defence-in-depth security at every layer.
Authentication
- Customer users can sign in with multi-factor authentication (authenticator app or passkey)
- OAuth 2.0 for API authentication
- Scoped JWT tokens with configurable expiry
- Brute-force protection and account lockout policies
Authorization
- Role-Based Access Control (RBAC) with granular permissions
- Each customer’s data is held in its own database
- Identity-Aware Proxy (IAP) for scoped external access
Auditing
- Immutable evidence chain for compliance-critical operations
- Tamper-evident records with cryptographic integrity checks
API Security
- All APIs served over TLS 1.2+ exclusively
- Rate limiting and throttling on all endpoints
- Input validation and output encoding
- CORS policies and CSRF protection
5. Infrastructure
Our platform is hosted on enterprise-grade cloud infrastructure with multiple layers of protection.
Cloud Hosting
Customer workforce data is stored in AWS Sydney (ap-southeast-2). Some supporting services — sign-in, email and SMS delivery, payments, bot checks and AI features — are provided by sub-processors outside Australia.
Network Security
Virtual Private Cloud (VPC) with private subnets, security groups, and network ACLs. No direct public internet access to data stores.
Web Application Firewall
AWS WAF is deployed in front of the production application in monitoring mode, and AWS Shield Standard applies.
6. Application Security
All code changes undergo peer review, with security considerations part of the review criteria.
7. Encryption
In Transit
All data transmitted between clients and our services is encrypted using TLS 1.2 or higher. We enforce HTTPS across all endpoints and HSTS headers are set on all responses.
At Rest
Production data volumes, snapshots and object storage are encrypted with AWS KMS (AES-256).
8. Identity and Access Management
Access to our production systems is tightly controlled:
- Multi-factor authentication is enforced for staff sign-in to company systems (Google Workspace, GitHub and the company network)
- Privileged access is time-bound, logged, and reviewed regularly
- Access reviews are conducted quarterly to ensure appropriate access levels
- Employee offboarding includes immediate revocation of all system access
9. Business Continuity
Our business continuity and disaster recovery plans ensure service availability and data durability.
Maximum targeted duration for restoring services following a major disruption.
Maximum acceptable data loss window. Regular encrypted snapshots limit data loss in a disaster scenario.
- Production data volumes are snapshotted hourly and daily in AWS Sydney, encrypted, and kept for no more than 90 days
- Restore is tested; the last test was on 30 September 2026
10. Incident Response
We maintain a formal incident response plan that covers identification, containment, eradication, recovery, and lessons learned. Key elements include:
- Production is scanned for vulnerabilities continuously (AWS Inspector), with external scans at least quarterly
- Defined severity levels with corresponding response timelines
- Dedicated incident response team with clear roles and responsibilities
- We notify affected customers without undue delay, and within 72 hours of confirming a breach affecting their data, and notify the OAIC where the Notifiable Data Breaches scheme requires it
- Post-incident review and root cause analysis for all significant incidents
- Regular incident response drills and tabletop exercises
11. Third-Party Services
Third-party services that have access to customer data are assessed for security before they are onboarded.
12. AI/ML Transparency
Where our Services use artificial intelligence or machine learning capabilities, we are committed to transparency:
- Deterministic rule engines: Core compliance features (award interpretation, credential validation, care minutes calculations) use deterministic rule engines, not probabilistic AI models. That makes outcomes predictable, auditable and repeatable.
- AI-assisted features: Where AI-assisted features are available (such as natural language queries or document extraction), they are clearly labelled as such.
- Human oversight: Automated outputs are recommendations; Customers retain full control over acting on them.
13. Shared Responsibility Model
Security is a shared responsibility. While we secure the platform, infrastructure, and application layers, our customers play an important role in securing their own use of the Services:
Smartta is responsible for:
- Securing the platform infrastructure and network
- Maintaining encryption at rest and in transit
- Patching and updating platform software
- Monitoring for and responding to security threats
- Maintaining its information security management system and the controls described on this page
- Providing multi-factor authentication for customer users
Customers are responsible for:
- Managing user accounts and access permissions within their tenant
- Enabling and enforcing MFA for their users
- Protecting their own API keys and credentials
- Ensuring their authorised users comply with acceptable use policies
- Reporting suspected security incidents promptly
14. Contact Us
For security questions, to report a vulnerability, or to request a security assessment:
- Security team: security@smartplace.ai
- Privacy team: privacy@smartplace.ai
- Responsible disclosure: If you discover a security vulnerability, please report it to security@smartplace.ai. We appreciate coordinated disclosure and will acknowledge your report within 2 business days.
Smartplace Pty Ltd (ACN 639 781 678)
C/- Margetson & Associates, Unit 21, 598-602 Forest Road, Penshurst, NSW 2222, Australia
Trust Center
Security documentation for due-diligence review is published at our Trust Center. Material not published there can be requested at hello@smartta.ai.
trust.smartta.ai