Trust Center

Security built into how SmartPR runs

A clear view of how we protect customer workspaces — authentication, isolation, auditability, and the controls we maintain as we prepare for formal assurance. Conservative claims only.

Assurance status

SOC 2 readiness

Internal control inventory and evidence work underway. Not SOC 2 certified. No Type I or Type II attestation is claimed.

Who this is for

Prospects & customers

Security questionnaires, enterprise procurement, and diligence — grounded in product engineering, not marketing badges.

Overview

What we will say — and what we will not

SmartPR is a Puerto Rico business permits and licensing platform. Customer filings and workspace data are confidential. We document security controls that exist in product engineering and the readiness work toward a future independent audit.

We do not publish fake ISO marks, invented SOC 2 Type II badges, or compliance scores. Where production configuration must be confirmed (IdP wiring, RLS, vendor reports), we say so explicitly.

SOC 2 readiness badge

Signals that SmartPR maintains a control inventory, security documentation, and internal evidence workflows. It is not an auditor attestation and must not be read as “SOC 2 certified” or “SOC 2 Type II.”

Status

Readiness only

Not certified

Controls

Security control overview

Summaries of controls present in SmartPR engineering. Labels distinguish product-implemented features, items that need production verification, and readiness-track processes.

Authentication

In product

Supabase Auth with session refresh in application middleware. Protected app routes require a signed-in user.

RBAC & enterprise roles

In product

Workspace membership and role-based permissions enforced in server-side APIs, including enterprise admin gates.

Tenant isolation

In product

Workspace-scoped access checks on sensitive APIs. Production RLS coverage is tracked as a verification item.

SSO & SCIM

Verify in prod

Enterprise SSO configuration and SCIM provisioning with hashed service-account credentials. Production IdP wiring requires verification per customer environment.

Support access

In product

Time-boxed operator access: reason and duration required, read-only by default, expiry enforced, and audited.

Audit logging

In product

Append-only audit events for sensitive enterprise and admin actions, with helpers to redact secrets from logs and responses.

Secrets & service accounts

In product

Hash-only credential storage, show-once secrets, rotate/revoke, scoped tokens, and fingerprinting for service accounts.

AI governance

In product

Server-side AI calls only, structured metadata logging (not raw confidential content), and workspace auth on AI routes. Vendor DPA details require verification.

Vulnerability readiness

Readiness

Documented vulnerability management process and control inventory. Ongoing scan cadence and production evidence are part of readiness work — not a completed certification.

Documents

Security & Trust Package

Download the PDF overview of SmartPR security practices and SOC 2 readiness documentation. Suitable for security questionnaires and early diligence. It does not constitute a certification.

Download PDF
File
SmartPR-Security-Trust-Package.pdf
Contents
Control overview, readiness posture, and security practices for customer diligence.

Contact

Security & trust inquiries

For questionnaires, NDAs, or diligence follow-ups, email darius@getsmartpr.com. We respond with facts we can stand behind — not inflated claims.