SOC2C

Is this your company? Buyers are checking Smaply here. Claim smaply.app free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Smaply logo

Smaply

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Smaply is SOC 2 Type II compliant. Smaply also holds ISO 27001, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Welcome to the Trust Center for Smaply GmbH (formerly More than Metrics GmbH). Our commitment to security, reliability, and transparency is demonstrated through our ISO 27001-aligned practices and service level agreements (SLAs). To access our resources, including policies and SLAs, users must request access and agree to our NDA. The Trust Center also features live compliance control checks and a transparent overview of our subprocessors, including where data is stored. Discover how we ensure the security and reliability of Smaply, making it a trustworthy partner for your success.

Compliance & infrastructure

Hosting
GCP
Data handled
Credit card informationPersonal health informationCustomer PII (Name, Email, IP Address, Device Information)

Documents

18

Subprocessors

8
  • G
    Google Cloud Platform · Cloud provider
    EU, US, Asia, Australia – depending on version and set-up
  • V
    Vercel · Web app hosting
    EU/US – depending on version and set-up
  • U
    Usersnap GmbH · Customer Feedback & Bug Reporting
    EU
  • F
    Freshdesk · Customer support
    EU
  • A
    ActiveCampaign · Marketing automation
    EU
  • W
    WorkOS · Authentication Provider
    US
  • S
    Sentry · Application performance monitoring & error tracking
    EU/US – depending on version and set-up
  • P
    Paddle · Finance and payments
    US

Compliance leadership

The person who leads Smaply's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Smaply's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Smaply SOC 2 compliant?
Smaply is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Smaply ISO 27001 certified?
According to Smaply's public trust center, Smaply is ISO 27001 certified. On SOC2C this listing is Listed.
Is Smaply GDPR compliant?
According to Smaply's public trust center, Smaply is GDPR compliant. On SOC2C this listing is Listed.
Is Smaply SOC 2 Type I or Type II?
Smaply is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Smaply's SOC 2 for a vendor risk assessment?
Yes. Smaply's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by Smaply

Reproduced from Smaply's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Do you support Single Sign-On (SSO) or Multi-Factor Authentication (MFA)?
Yes. Single Sign-On (SSO) is free of charge for 10 users onwards. You can still use SSO fewer than 10 users, with additional cost. MFA can be enforced via the connected identity provider (IdP). However, please not that you cannot use both SSO and MFA at the same time.
Do you encrypt data in transit and rest?
Encryption is applied to protect data at rest and in transit using strong cryptography and industry-standard protocols, including AES-256 and TLS 1.3, with cryptographic protection of passwords.
Who is able to access our data?
Our access to customer data is strictly limited, role-based and governed by our ISO 27001-aligned Information Security Management System. Only authorised personnel (specifically, selected engineering or operations staff) may access customer data, and only when necessary for support, maintenance or legal obligations. Such access is granted on a least-privilege basis, logged and monitored, and subject to defined security policies, confidentiality obligations and contractual data protection agreements. No Smaply personnel have routine or standing access to customer content. Access is event-driven, auditable and governed by our internal access control policies.
Do you use my data to train your AI models?
No. Smaply uses ephemeral processing via Google's Generative AI API. Your data is: 1. Not Stored: Customer data is processed transiently in-memory only and never persisted by Google or Smaply. 2. Not Used for Training: Per Google's API terms of service, data sent via the Generative AI API is not used to train, fine-tune, or improve models. 3. Not Shared: Your data is never shared with third parties or used for any purpose beyond generating the specific response you requested. Verification: This guarantee is contractually enforced through our Google Cloud AI Platform agreement. Enterprise customers can request a copy of our Data Processing Addendum (DPA) for legal review.
Where are your servers located?
We operate on a hybrid cloud infrastructure powered by Google Cloud Platform (GCP) within the European region. - Primary data center: Frankfurt am Main, Germany - Backup data center: Belgium This setup ensures high availability, redundancy, and compliance with European data protection standards. Additionally, we offer single-tenant hosting options tailored to your preferred location and tenancy requirements. (Additional costs may apply depending on your subscription level.)