Compliance Certifications

Compliance Certifications — Independently Audited, Openly Documented

SmartSuite holds SOC 2 Type II, ISO 27001, ISO 27701, GDPR, and HIPAA certifications and attestations—published through its security page and Trust Center, so vendor due diligence starts with evidence, not questionnaires.

What Is Compliance Certifications?

Compliance Certifications are SmartSuite's independently audited security and privacy certifications and attestations—SOC 2 Type II, ISO 27001, ISO 27701, GDPR, and HIPAA—covering information-security management, service-organization controls, and healthcare and EU privacy frameworks. They help security, procurement, and compliance evaluators complete vendor due diligence with audited evidence rather than self-attestation. Reports and documentation are published on SmartSuite's Trust Center.

Independent Audits

Verify SOC 2 Type II, ISO 27001, GDPR, and HIPAA Credentials

SmartSuite's information security management system is certified to ISO/IEC 27001:2022 with annual recertification, and an annual SOC 2 Type II audit covers security, availability, and confidentiality. Formal third-party HIPAA and GDPR audits were conducted by Prescient Assurance, with a GDPR Letter of Attestation available.

These are audits of SmartSuite as your vendor—recurring, independent, and documented—not one-time self-assessments.

Trust Center

Review Security Documentation in the SmartSuite Trust Center

The SmartSuite Trust Center at trust.smartsuite.com publishes the artifacts security reviews ask for: the current SOC 2 Type II report, a penetration-test executive summary, the disaster recovery plan, cyber insurance documentation, a VPAT 2.5 accessibility report, and the full subprocessor list—with a DPA available on request.

Procurement and security teams get their evidence directly, without waiting on an email thread.

Platform Safeguards

Build on Encrypted, Enterprise-Grade Infrastructure

Certifications sit on hardened foundations: SmartSuite runs on AWS infrastructure that supports PCI-DSS, HIPAA/HITECH, FedRAMP, FIPS 140-2, NIST 800-171, and GDPR at the infrastructure level, with data encrypted in transit over HTTPS/TLS and at rest with AES-256.

One distinction matters: these certifications cover SmartSuite as a vendor. The frameworks your own organization manages—SOX, NIST CSF, FFIEC, and others—live in your GRC workflows on the platform, and remain your program to run.

Platform Context
How GRC Teams Use

Compliance Certifications

Every enterprise evaluation runs through a security gate. SmartSuite's certifications and Trust Center give evaluators audited answers--so GRC initiatives clear procurement and vendor review faster.

Vendor Due Diligence

A prospective customer's security team requests SmartSuite's SOC 2 Type II report and ISO 27001 certificate during vendor review—and pulls both from the Trust Center the same day.

Third-Party Risk Questionnaires

A GRC team assessing SmartSuite as a vendor completes its questionnaire using the Trust Center's penetration-test summary, disaster recovery plan, and subprocessor list—closing the review without a custom evidence request.

Healthcare Workflow Assurance

A healthcare organization confirms SmartSuite's third-party HIPAA audit before building PHI-adjacent workflows on the Enterprise plan, where HIPAA compliance features are available.

Certified Vendor, In-Region Data

An EU customer pairs SmartSuite's GDPR audit and attestation with European Data Residency—audited privacy practices plus workspace data hosted in AWS Ireland.

Works Better Together
Related Features

Every enterprise evaluation runs through a security gate. SmartSuite's certifications and Trust Center give evaluators audited answers--so GRC initiatives clear procurement and vendor review faster.

Features FAQ’s
Frequently Asked Questions About
Compliance Certifications
What compliance certifications does SmartSuite hold?

SmartSuite is certified and audited for SOC 2 Type II, ISO 27001, ISO 27701, GDPR, and HIPAA. ISO 27001:2022 certification is renewed annually, the SOC 2 Type II audit recurs annually, and the HIPAA and GDPR audits were performed by Prescient Assurance.

Does using SmartSuite make my organization SOC 2 or GDPR compliant?

No. SmartSuite's certifications cover SmartSuite as your vendor—they don't transfer compliance to your organization. SmartSuite's GRC products help your team manage its own frameworks and stay audit-ready, but your controls and processes determine your compliance.

Where can I get SmartSuite's SOC 2 report and other security documents?

From the SmartSuite Trust Center at trust.smartsuite.com. It publishes the current SOC 2 Type II report, a penetration-test executive summary, the disaster recovery plan, cyber insurance documentation, a VPAT 2.5 report, and the subprocessor list, with a DPA available on request.

Is SmartSuite HIPAA compliant?

SmartSuite has completed a formal third-party HIPAA compliance audit conducted by Prescient Assurance. On the pricing page, HIPAA compliance features are listed under the Enterprise plan—healthcare organizations should evaluate on Enterprise.

How is data encrypted in SmartSuite?

Data is encrypted in transit using HTTPS/TLS and at rest using AES-256, on AWS infrastructure that supports standards including PCI-DSS, HIPAA/HITECH, FedRAMP, FIPS 140-2, NIST 800-171, and GDPR at the infrastructure level.

Do certifications vary by plan?

SOC 2 Type II and ISO 27001 apply across Team, Professional, and Enterprise plans, per the pricing page. HIPAA compliance features are Enterprise-only, and GDPR-related capabilities such as European Data Residency and the DPA are arranged on Enterprise.

Who are SmartSuite's subprocessors?

The Trust Center lists SmartSuite's subprocessors—including AWS, MongoDB, Google Workspace, OpenAI, Stripe, and Zoom—so privacy teams can complete transfer and vendor-chain assessments with current information.

Clear Security Review in Days, Not Quarters

Audited certifications, a public Trust Center, and enterprise-grade infrastructure—the evidence your evaluators need is already published.