# Smart Access Trust Center

Smart Access is the leading platform that enhances productivity on the frontline by bridging the gap between behavior and operational standards. Trusted by organizations across diverse industries, Smart Access helps teams unlock their true potential through actionable insights and operational excellence.

## FAQ

### Frequently Asked Questions

### How does Smart Access leverage AI within our product?

Smart Access currently uses AI to import, generate, or translate content on the platform. Use of these AI tools require administrative opt-in with the assigned Customer Success Manager and are not enabled by default.

We utilize various third-party, open source and proprietary models that are approved for use based on our Risk Management program and any applicable Data Processing or Sub Processor agreements.

By default, we do not allow training of third-party models on Smart Access data, and any fine-tuning or training of proprietary Smart Access models require explicit opt-in by an organization administrator.

We inform our end users the first time they are about to leverage AI to deliver a product feature in Smart Access and all Smart Access employees that work with customer data are continuously evaluated for compliance with the relevant Data Management and Acceptable Use policies.

For more detailed information on our approach to leveraging AI, please speak with your assigned Customer Success Manager or Account Executive.

### Where can I find information about Smart Access uptime and downtimes?

We recommend checking out our [Status Page](https://status.smartaccess.io/). This will give you the ability to subscribe for updates, view uptimes, be informed of any outages, and view historical data.

### Does Smart Access encrypt data at rest?

All datastores with customer data are encrypted at rest. Sensitive collections and tables also use row-level encryption.

This means the data is encrypted even before it hits the database so that neither physical access, nor logical access to the database, is enough to read the most sensitive information.

### How does Smart Access encrypt data in-transit?

Smart Access uses TLS 1.2 or higher everywhere data is transmitted over potentially insecure networks. We also use features such as HSTS (HTTP Strict Transport Security) to maximize the security of our data in transit. Server TLS keys and certificates are managed by GCP and deployed via Application Load Balancers.

### Do you support Single Sign-On (SSO)?

Smart Access supports federation via SAML 2.0 and OAuth 2.0. Compatible Identity Providers (IdPs) include, but are not limited to Microsoft Azure AD, Okta, Google Identity Platform, OneLogin, PingFederate and ADFS (Active Directory Federation Services).

Compatibility is ensured for any IdP adhering to SAML 2.0 or OAuth 2.0/OIDC standards.

### Where are your servers located?

Smart Access servers are located in Google Cloud Platform, with multi-site data residency and high availability in the US regions.

### Does Smart Access conduct penetration tests?

Smart Access engages with an external penetration testing firm in the industry at least annually.

All areas of the Smart Access product and cloud infrastructure are in-scope for these assessments, and code is made available to the testers in order to maximize the effectiveness and coverage.
