Enterprise Readiness
Enterprise readiness
A status matrix for buyers, CTOs, CISOs, and diligence teams. Status labels are conservative and reflect current readiness, not completed controls or any certification.
| Capability | Current position | Status |
|---|---|---|
| TLS / HTTPS | Production and demo environments use encrypted transport for web and API traffic. | Evidenced |
| Encryption at rest | Application data is held on durable, encrypted storage. | Evidenced |
| Access control | Administrative access is limited and separated from public experiences. A formal access-control policy is being documented. | Designed / In Progress |
| Audit logging | Append-only application audit logging exists. Broader security logging and periodic review are being built into the readiness program. | Designed / In Progress |
| Security policies | Phase 1 executive trust summary and Trust Center content are complete. Detailed control policies are next. | Designed / In Progress |
| Incident response | An incident response plan will define severity levels, escalation, communications, and post-incident review. | Planned |
| Business continuity | A BC/DR summary will document backups, recovery expectations, and critical dependency handling. | Planned |
| Vendor management | A vendor inventory and critical-vendor review process will be documented. | Planned |
| SOC 2 audit | No SOC 2 Type I or Type II report has been issued. A SOC 2-aligned readiness program is being built. | Not Claimed |
How to read the status labels
- Evidenced — in place today and verifiable.
- Evidence Needed — practiced, but supporting evidence is still being collected.
- Designed / In Progress — designed and actively being implemented or documented.
- Planned — on the roadmap, not yet started in earnest.
- Not Claimed — SmartQuotes makes no claim here today.
SmartQuotes uses "SOC 2-aligned" and "SOC 2 readiness program" only. It does not use "SOC 2 compliant," "SOC 2 certified," or "SOC 2 audited" until an independent CPA firm completes an engagement.
For enterprise review
Highlights for review
- Readiness status labels are conservative
- SOC 2 readiness program shown as in progress
- Draft policies clearly marked as drafts
- Detailed policy library is request-only
- Evidence checklist maintained internally
SmartQuotes is building its security and operational practices in alignment with SOC 2 Trust Services Criteria. SmartQuotes has not completed a SOC 2 Type I or Type II audit, and nothing on these pages is a certification, attestation, or audit report. Status labels reflect current readiness, not completed controls.