Authentication
In productSupabase Auth with session refresh in application middleware. Protected app routes require a signed-in user.
Trust Center
A clear view of how we protect customer workspaces — authentication, isolation, auditability, and the controls we maintain as we prepare for formal assurance. Conservative claims only.
Assurance status
SOC 2 readiness
Internal control inventory and evidence work underway. Not SOC 2 certified. No Type I or Type II attestation is claimed.
Who this is for
Prospects & customers
Security questionnaires, enterprise procurement, and diligence — grounded in product engineering, not marketing badges.
Overview
SmartPR is a Puerto Rico business permits and licensing platform. Customer filings and workspace data are confidential. We document security controls that exist in product engineering and the readiness work toward a future independent audit.
We do not publish fake ISO marks, invented SOC 2 Type II badges, or compliance scores. Where production configuration must be confirmed (IdP wiring, RLS, vendor reports), we say so explicitly.
Signals that SmartPR maintains a control inventory, security documentation, and internal evidence workflows. It is not an auditor attestation and must not be read as “SOC 2 certified” or “SOC 2 Type II.”
Status
Readiness only
Not certified
Controls
Summaries of controls present in SmartPR engineering. Labels distinguish product-implemented features, items that need production verification, and readiness-track processes.
Supabase Auth with session refresh in application middleware. Protected app routes require a signed-in user.
Workspace membership and role-based permissions enforced in server-side APIs, including enterprise admin gates.
Workspace-scoped access checks on sensitive APIs. Production RLS coverage is tracked as a verification item.
Enterprise SSO configuration and SCIM provisioning with hashed service-account credentials. Production IdP wiring requires verification per customer environment.
Time-boxed operator access: reason and duration required, read-only by default, expiry enforced, and audited.
Append-only audit events for sensitive enterprise and admin actions, with helpers to redact secrets from logs and responses.
Hash-only credential storage, show-once secrets, rotate/revoke, scoped tokens, and fingerprinting for service accounts.
Server-side AI calls only, structured metadata logging (not raw confidential content), and workspace auth on AI routes. Vendor DPA details require verification.
Documented vulnerability management process and control inventory. Ongoing scan cadence and production evidence are part of readiness work — not a completed certification.
Documents
Download the PDF overview of SmartPR security practices and SOC 2 readiness documentation. Suitable for security questionnaires and early diligence. It does not constitute a certification.
Download PDFContact
For questionnaires, NDAs, or diligence follow-ups, email darius@getsmartpr.com. We respond with facts we can stand behind — not inflated claims.