SECURITY

Sparkling Logic is committed to the security of your data and business operations. SMARTS™ was designed with security at the forefront and we maintain compliance with the latest best practices.

SMARTS™ Security - Built-in features to protect your data and operations

Compliance Certifications and Examinations

We comply with the highest industry standards for security.

ISO/IEC 27001 - Certified by Accorp

ISO/IEC 27001

The leading international standard for information security management systems. Certification demonstrates that our people, policies, and technology align to best practices for risk management, cyber-resilience, and operational excellence.

AICPA SOC
SOC 2®

The leading US standard for service organizations. Examination completion demonstrates that our systems and controls effectively achieve security, availability, processing integrity, confidentiality, and privacy.

SMARTS™ Built-in Security Features

We designed SMARTS™ to protect all operations carried out in the platform. 

Authentication

Valid authentication is necessary to perform any interaction within SMARTS™. Setup can be done through the built-in authentication provider or delegated to an external one. Supported protocols include LDAP, WS-Federation, and OAuth2.

Access Control

All SMARTS™ users are assigned roles which define what operations they are allowed to perform. SMARTS™ includes predefined roles which may be customized such as Workspace Admin, Release Manager, and User roles. In addition, organizations can create their own roles, specifying permissions at a granular level.

Securing Programmatic Interactions

All service programmatic interactions are implemented through HTTPS with certificates that can be set up by the organization. All API invocations are protected by a hash and a secret key. An ISO format timestamp is also used to protect against replay attacks.

Securing Data Storage

All interactions with the database are internal to SMARTS™ and implemented through HTTPS. Organizations can specify an encryption key to encrypt the database content at rest so that with unauthorized access, the contents are unreadable.