Is this your company?Buyers are checking Smaply here. Claim smaply.app free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Welcome to the Trust Center for Smaply GmbH (formerly More than Metrics GmbH). Our commitment to security, reliability, and transparency is demonstrated through our ISO 27001-aligned practices and service level agreements (SLAs). To access our resources, including policies and SLAs, users must request access and agree to our NDA. The Trust Center also features live compliance control checks and a transparent overview of our subprocessors, including where data is stored. Discover how we ensure the security and reliability of Smaply, making it a trustworthy partner for your success.
SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Smaply SOC 2 compliant?
Smaply is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Smaply ISO 27001 certified?
According to Smaply's public trust center, Smaply is ISO 27001 certified. On SOC2C this listing is Listed.
Is Smaply GDPR compliant?
According to Smaply's public trust center, Smaply is GDPR compliant. On SOC2C this listing is Listed.
Is Smaply SOC 2 Type I or Type II?
Smaply is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Smaply's SOC 2 for a vendor risk assessment?
Yes. Smaply's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Smaply penetration tested?
Smaply hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Smaply secure?
Security isn't a single yes/no, but Smaply is SOC 2 Type II compliant and holds ISO 27001, SOC 2 Type II, GDPR. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Smaply have a bug bounty or vulnerability disclosure program?
Smaply hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@smaply.app or via a /security page.
Who are Smaply's subprocessors?
Smaply lists 8 subprocessors on its trust center, including Google Cloud Platform, Vercel, Usersnap GmbH, Freshdesk, ActiveCampaign. Buyers use this for fourth-party risk review.
Where does Smaply host or store data?
Smaply hosts on GCP, and handles Credit card information, Personal health information, Customer PII (Name, Email, IP Address, Device Information). Data residency details are on its trust center.
Where is Smaply's trust center or security page?
Smaply's trust center is at https://trust.smaply.app. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Do you support Single Sign-On (SSO) or Multi-Factor Authentication (MFA)?
Yes. Single Sign-On (SSO) is free of charge for 10 users onwards. You can still use SSO fewer than 10 users, with additional cost. MFA can be enforced via the connected identity provider (IdP). However, please not that you cannot use both SSO and MFA at the same time.
Do you encrypt data in transit and rest?
Encryption is applied to protect data at rest and in transit using strong cryptography and industry-standard protocols, including AES-256 and TLS 1.3, with cryptographic protection of passwords.
Who is able to access our data?
Our access to customer data is strictly limited, role-based and governed by our ISO 27001-aligned Information Security Management System. Only authorised personnel (specifically, selected engineering or operations staff) may access customer data, and only when necessary for support, maintenance or legal obligations. Such access is granted on a least-privilege basis, logged and monitored, and subject to defined security policies, confidentiality obligations and contractual data protection agreements. No Smaply personnel have routine or standing access to customer content. Access is event-driven, auditable and governed by our internal access control policies.
Do you use my data to train your AI models?
No. Smaply uses ephemeral processing via Google's Generative AI API. Your data is: 1. Not Stored: Customer data is processed transiently in-memory only and never persisted by Google or Smaply. 2. Not Used for Training: Per Google's API terms of service, data sent via the Generative AI API is not used to train, fine-tune, or improve models. 3. Not Shared: Your data is never shared with third parties or used for any purpose beyond generating the specific response you requested. Verification: This guarantee is contractually enforced through our Google Cloud AI Platform agreement. Enterprise customers can request a copy of our Data Processing Addendum (DPA) for legal review.
Where are your servers located?
We operate on a hybrid cloud infrastructure powered by Google Cloud Platform (GCP) within the European region. - Primary data center: Frankfurt am Main, Germany - Backup data center: Belgium This setup ensures high availability, redundancy, and compliance with European data protection standards. Additionally, we offer single-tenant hosting options tailored to your preferred location and tenancy requirements. (Additional costs may apply depending on your subscription level.)
Is there an SLA for resolving identified security issues?
Yes. Security issues and other software incidents are handled according to our internal Service Level Agreement (SLA), where each reported issue is assigned a severity level (S1–S4) based on its impact on the system and customers. Our team prioritizes investigation and resolution depending on this severity classification. Typical resolution targets are: - S1 – Critical issues (e.g., service unavailable, data loss): Resolution within 3 business days for standard plans and 1 business day for Enterprise plans. - S2 – Major issues (significant feature impact): Resolution within 14 days (standard) or 7 days (Enterprise). - S3 – Minor issues (limited impact): Resolution within 90 days (standard) or 30 days (Enterprise). - S4 – Low-priority improvements or minor problems: Resolution timelines are determined in mutual agreement. For critical incidents (S1 and S2), our team begins working on the issue immediately after it is reported. Our primary objective is to restore normal service operation as quickly as possible. When an immediate fix is not feasible, we prioritize providing a workaround to restore business operations, followed by a permanent solution.
Want to report a potential security issue?
If you believe you’ve discovered a potential security issue, please report it to [privacy@smaply.com](mailto:privacy@smaply.com) with as much detail as possible so our team can investigate. We review all submissions carefully. If your report highlights something we were not previously aware of, we will follow up with you. In cases where the issue is already known or does not require further action, we may not respond individually, but we still appreciate you taking the time to share your findings.
I found a security bug. Do you have an established bug bounty program?
We are currently preparing a formal bug bounty program, which we expect to launch soon. In the meantime, we welcome responsible disclosure. If you believe you have identified a security vulnerability, please send your findings to [privacy@smaply.com](mailto:privacy@smaply.com). Our team will review the report and may grant a discretionary reward based on factors such as: - The potential impact and severity of the vulnerability - How well the issue is documented and reproducible - Whether the finding represents a previously unknown vulnerability - The difficulty of exploiting the issue and the required attack conditions At this stage, we only consider rewards for high-severity security vulnerabilities. Reports related to the following topics are out of scope and not eligible for rewards: - Service disruption attempts such as denial-of-service testing - Minor configuration issues (e.g., DNS records or general infrastructure hygiene) - Social engineering, phishing, or spam-related techniques - Attacks that target employees through physical or social manipulation - Security issues in third-party tools or services that we do not operate or maintain - Vulnerabilities that depend on physical access to a user’s device