Trust & Security

Know where SmartC runs, what data it uses, and who remains in control.

SmartC begins security review with a clear deployment, data, access, AI, and approval boundary—not an implied assurance claim.

What the review must make clear
One accountable boundary for each deployment.
Where the application runs
Where customer data is processed
What AI can receive
What SmartC can access
Who approves consequential action
Choose the Data Boundary

SmartC Hosted is the default. Customer Private Cloud can be evaluated when policy requires customer-controlled hosting.

Default deployment model

SmartC Hosted

SmartC operates the application as a managed SaaS deployment, subject to the agreed security, data-processing, and contractual review.

Lower customer infrastructure effort
SmartC-managed application operations and updates
Appropriate where policy permits SaaS processing
Controls and subprocessors reviewed before production use
Enterprise evaluation option

Customer Private Cloud

A customer-controlled Azure deployment can be evaluated when policy requires the application and business data to remain within the customer environment.

Customer-controlled hosting boundary
Customer identity, network, and infrastructure responsibilities
More deployment and operational coordination
Availability confirmed through technical and commercial review

These are deployment models—not security certifications.

Define the Boundary Before Connection

The agreed scope defines the data, access, retention, and support boundary.

The security review should resolve these decisions before environment-specific data is connected.

Data scope
Agree the systems, fields, business purpose, and minimum information required for the selected use case.
Source access
Your organization grants and can revoke access to source systems under its own authority and policy.
Retention and exit
Define retention, export, deletion, and transition requirements for the selected deployment.
SmartC support access
Document whether SmartC requires support access, for what purpose, and under which agreed controls.

Material data and access boundaries belong in the main review—not in hidden caveats.

AI and Action Control

AI can assist analysis. It does not approve consequential action.

The selected deployment defines what authorized context can reach an approved AI service. Business decisions remain with accountable people.

1 · Scope
Authorized context
AI use is limited to the agreed purpose, data boundary, and approved service.
2 · Evidence
Grounded analysis
Recommendations should be reviewed against verified inventory, usage, cost, ownership, and business context.
3 · Review
Human judgment
Technology, finance, security, procurement, and business implications are considered before action.
4 · Approval
Decision owner remains in control
The designated technology owner approves consequential execution in line with company policy.

SmartC recommends. The designated technology owner approves in line with company policy before execution.

Responsibilities and Assurance

Security review should be based on evidence and responsibility—not implied certification.

SmartC is responsible for
Explaining the selected deployment and processing boundary
Documenting SmartC-managed responsibilities and dependencies
Providing available architecture, data-flow, subprocessor, and contractual information
Responding to the agreed security and technical review
Your organization remains responsible for
Approving the deployment model and permitted data sources
Managing customer identities, source permissions, and internal policy requirements
Reviewing business, legal, security, and procurement implications
Approving consequential optimization actions
Current assurance status

SmartC does not currently hold SOC 2 or ISO 27001 certification. The security evaluation is based on the available architecture, responsibility, contractual, and control evidence.

Controlled review material

Relevant architecture, data-flow, responsibility, subprocessor, questionnaire, and contractual information is shared during a qualified review as it is available for the selected deployment.

Talk to Us

Start with the policy, data, AI, hosting, or procurement question you need to resolve.

Share the requirement and the deployment context. We will review it and get back to you with the appropriate next step.

Hosting policy SaaS permitted, customer-controlled hosting required, or still under review.
Data boundary Sources, sensitivity, residency, retention, deletion, and export requirements.
AI and access Approved AI services, user access, support access, and decision controls.
Review process Questionnaire, architecture review, procurement, legal, and contractual needs.
Thank you. We’ll get back to you.
By sending this form, you agree that SmartC may use the information to respond.
{{ tErr }}

Email us instead? support@smartc.ai

Book a Demo

See SmartC before beginning a full technical review.

Use a focused Demo to understand the relevant Product, data required, AI role, approval boundary, and likely deployment questions.

Relevant Product See the SmartC capability aligned to your IT cost priority.
Data required Understand the information used for the selected workflow.
AI role See where AI assists analysis and where human review remains required.
Next step Decide whether a security review or environment-specific Assessment is appropriate.

SmartC recommends. The designated technology owner approves in line with company policy before execution.

Thank you. Choose a Demo time below.
Calendar integration placeholder

Available meeting times will appear here immediately after submission when the scheduling workflow is connected.

Book Your Demo

Complete the form to choose a Demo time.

{{ fErr }}
Request an Assessment

Define the evidence, access, and approval boundary for an environment-specific Assessment.

Agree the scope before connecting data, then establish the baseline, validate evidence, qualify opportunities, and define the next safe action.

Scope Systems, data fields, purpose, owners, and exclusions.
Access Source permissions, customer users, and any agreed SmartC support access.
Evidence Baseline, findings, confidence gaps, and affected stakeholders.
Approval Proceed, validate further, defer, or stop under company policy.

SmartC recommends. The designated technology owner approves in line with company policy before execution.

Thank you. Choose a scoping time below.
Scoping times appear here when the scheduling workflow is connected.
{{ aErr }}

IT Cost Optimization software and expert-led services across the major areas of enterprise technology spend.

Resources
BlogGuidesDocumentationEvents
Security Practices Informed By SOC 2 · ISO/IEC 27001 · GDPR Principles

We use essential cookies to run this site; analytics are optional.