Skip to main content

Security

How we build, run, and operate Smoov to protect your data.

Security infrastructure

  • Encryption at rest for all stored data; encryption in transit via TLS 1.2+ on every external endpoint.
  • Least-privilege access by default. Production credentials are scoped per-service; no shared admin keys.
  • Secure SDLC: dependency review, type-checking gates, secret scanning, and pre-merge automated checks on every change.

Operational security

  • Continuous error monitoring with PII scrubbing; structured request logs retained on a defined schedule.
  • Documented incident response with on-call coverage.
  • 72-hour breach notification commitment from confirmed incident to affected-customer notice. See breach notification.

Product security

  • Admin controls scoped to founder-level accounts only; all admin actions are append-only audit-logged.
  • Account deletion is self serve. From the privacy section of your settings, two taps delete your account and the data it holds across the tables our deletion manifest derives from the live schema. It runs immediately and we confirm by email.
  • Records we must keep by law, such as billing and tax records, are retained on the schedule published in our privacy policy.
  • See /privacy for our full data-handling policy.

Privacy

Detailed policies and processor disclosures: privacy policy, data processing agreement, subprocessors.

Compliance

See our compliance posture for active certifications, in-progress audits, and out-of-scope frameworks.

AI governance

See AI security and governance and trust & safety methodology.