SOC2C

Is this your company? Buyers are checking Smart Access here. Claim smartaccess.io free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Smart Access logo

Smart Access

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Smart Access is SOC 2 Type II compliant.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Smart Access is the leading platform that enhances productivity on the frontline by bridging the gap between behavior and operational standards. We empower teams with tools that drive efficiency, improve compliance, and execution of their standards. Trusted by organizations across diverse industries, Smart Access helps teams unlock their true potential through actionable insights and operational excellence.

Compliance & infrastructure

Hosting
GCP
Data handled
Customer personally identifiable informationEmployee personally identifiable informationPersonal health informationMobile app usage dataPredictive analysis dataData exchange with HRIS, WMS, LMS or other systems

Documents

2

Subprocessors

29
  • G
    Google Cloud Platform · Cloud infrastructure and data services
    United States (with multi-region support)
  • M
    Microsoft · Enterprise software, communication and productivity tools
    United States & Canada
  • G
    Google Workspace · Identity provider, communication, collaboration, and productivity
    United States & Canada
  • S
    Slack · Team communication and collaboration
    United States & Canada
  • I
    Intercom · Customer support
    United States & Canada
  • B
    Box · File storage and collaboration
    United States & Canada
  • N
    New Relic · Application performance monitoring
    United States & Canada
  • C
    Cloudflare · Content delivery and security
    United States & Canada
  • S
    Sentry · Error tracking and debugging
    United States
  • J
    Jira · Project and issue tracking
    United States & Canada
  • V
    Vanta · Security
    United States
  • Z
    Zoom · Video conferencing and virtual meetings
    United States & Canada
Show all 29 subprocessors
  • B
    Bitbucket · Source code management and version control
    United States
  • H
    HubSpot · Customer relationship management (CRM) and marketing automation
    United States
  • A
    Anthropic · AI language model services
    United States
  • F
    Fathom · Meeting recording, transcription, and summarization
    United States
  • I
    Integrate.io · Data integration and ETL (Extract, Transform, Load) automation
    United States
  • L
    Loom · Video recording and asynchronous communication
    United States
  • N
    Notion · Knowledge management and collaborative documentation
    United States
  • O
    Omni Analytics · Business intelligence and analytics
    United States
  • P
    PostHog · Product and user behavior analytics
    United States
  • P
    Pusher · Real-time messaging and event delivery
    United States
  • O
    OpenAI · AI language model services
    United States
  • O
    OneSignal · Push notification delivery and engagement
    United States
  • C
    Cloudinary · Media storage, optimization, and delivery
    United States
  • x
    xAI · Engineering
    United States
  • A
    Adobe Inc. - Developer platform · SDK & Developer tools
    United States
  • V
    Vitally · Customer Success platform
    United States
  • M
    Mailgun · Marketing
    United States

Compliance leadership

The person who leads Smart Access's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Smart Access's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Subprocessor Update: Vitally – Customer Success PlatformJan 2026

As part of our ongoing efforts to strengthen customer support and improve lifecycle management, Smart Access is updating its list of authorized subprocessors to include Vitally. Subprocessor Name: Vitally – Customer Success Platform Purpose: Vitally supports Smart Access’s Customer Success operations by enabling account health monitoring, customer engagement tracking, playbooks/workflows, task management, and customer success reporting. This improves responsiveness, customer outcomes, and internal service delivery. Processor Role: Vitally acts as a subprocessor under our Information Security program and Data Processing Addendum (DPA). Vitally is contractually obligated to adhere to applicable data protection, confidentiality, and security requirements. Data Processed: Vitally may process limited customer contact and account metadata required for Customer Success workflows, including customer names and emails, company/account identifiers, lifecycle stage, renewal-related metadata, and Customer Success activity records (e.g., notes, tasks, playbook execution). Smart Access does not store payment card data in Vitally and avoids storing sensitive information in free-text fields. Smart Access has reviewed Vitally as part of our third-party risk assessment process and confirmed that appropriate technical and organizational safeguards are in place. If you have any questions about…

Subprocessor Update: Adobe Inc. – Developer API PlatformJan 2026

As part of our ongoing efforts to improve automation and streamline structured document processing, Smart Access is updating its list of authorized subprocessors to include the Adobe Developer Platform & APIs. Subprocessor Name: Adobe Inc. – Developer API Platform Purpose: Adobe’s Developer APIs are going to be introduced into different document pipelines including, SOP (Standard Operating Procedure) imports to programmatically extract structured content from PDF documents. This functionality enhances the accuracy and speed of digitizing customer SOPs into executable workflows within the Smart Access platform. Processor Role: Adobe acts as a subprocessor under our Information Security program and Data Processing Addendum (DPA). Adobe is contractually obligated to adhere to stringent data protection, confidentiality, and security standards. Data Processed: Uploaded PDF files used in the SOP import process may contain customer-authored operational content. These documents are processed temporarily and securely through the Adobe Developer API for text and structural extraction. No persistent storage of customer data is performed by Adobe, and no personal identifiable information (PII) is intentionally included in the documents submitted for parsing. --- Smart Access has reviewed Adobe’s Developer platform as part of our third-party risk assessment process and confirmed that…

Subprocessor Update: Addition of xAIDec 2025

Subprocessor Update: Addition of xAI At Smart Access, we prioritize transparency and compliance when it comes to how data is processed. As part of this commitment, we are formally announcing the addition of xAI to our list of authorized subprocessors. Purpose: xAI will provide AI / machine‑learning infrastructure services, specifically related to advanced model hosting and processing services, which may be leveraged for code development, analytics, insight generation, or automation workflows. Processor Role: xAI functions strictly as a subprocessor under our Information Security program. They are contractually obliged to adhere to the same or stronger security, confidentiality, and data protection commitments that we hold ourselves to. Data Processed: Consistent with our data minimization and pseudonymization policies. --- If you have any questions about this change, or if you would like to raise concerns about the use of xAI as a subprocessor, please contact us at [privacy-officer@smartaccess.io](mailto:privacy-officer@smartaccess.io) or through your usual account representative. Thank you for your continued trust.

Our SOC 2 Type II Auditor Report & Attestation Letter for 2024-2025 is now availableJul 2025

Please visit the Trust Center to view and download our latest SOC 2 Type II Auditor Report and Attestation Letter for the 2024–2025 period. To stay informed about future updates, new compliance documentation, or updates related to our Information Security Program we recommend subscribing to notifications via the Trust Center.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Other certifications
    List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Smart Access SOC 2 compliant?
Smart Access is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Smart Access SOC 2 Type I or Type II?
Smart Access is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Smart Access's SOC 2 for a vendor risk assessment?
Yes. Smart Access's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Smart Access penetration tested?
Smart Access hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Smart Access secure?
Security isn't a single yes/no, but Smart Access is SOC 2 Type II compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.

Business & Industrial peers that completed SOC 2