Enterprise Readiness

Enterprise readiness

A status matrix for buyers, CTOs, CISOs, and diligence teams. Status labels are conservative and reflect current readiness, not completed controls or any certification.

CapabilityCurrent positionStatus
TLS / HTTPSProduction and demo environments use encrypted transport for web and API traffic.Evidenced
Encryption at restApplication data is held on durable, encrypted storage.Evidenced
Access controlAdministrative access is limited and separated from public experiences. A formal access-control policy is being documented.Designed / In Progress
Audit loggingAppend-only application audit logging exists. Broader security logging and periodic review are being built into the readiness program.Designed / In Progress
Security policiesPhase 1 executive trust summary and Trust Center content are complete. Detailed control policies are next.Designed / In Progress
Incident responseAn incident response plan will define severity levels, escalation, communications, and post-incident review.Planned
Business continuityA BC/DR summary will document backups, recovery expectations, and critical dependency handling.Planned
Vendor managementA vendor inventory and critical-vendor review process will be documented.Planned
SOC 2 auditNo SOC 2 Type I or Type II report has been issued. A SOC 2-aligned readiness program is being built.Not Claimed

How to read the status labels

  • Evidenced — in place today and verifiable.
  • Evidence Needed — practiced, but supporting evidence is still being collected.
  • Designed / In Progress — designed and actively being implemented or documented.
  • Planned — on the roadmap, not yet started in earnest.
  • Not Claimed — SmartQuotes makes no claim here today.

SmartQuotes uses "SOC 2-aligned" and "SOC 2 readiness program" only. It does not use "SOC 2 compliant," "SOC 2 certified," or "SOC 2 audited" until an independent CPA firm completes an engagement.

For enterprise review

Highlights for review

  • Readiness status labels are conservative
  • SOC 2 readiness program shown as in progress
  • Draft policies clearly marked as drafts
  • Detailed policy library is request-only
  • Evidence checklist maintained internally
SmartQuotes is building its security and operational practices in alignment with SOC 2 Trust Services Criteria. SmartQuotes has not completed a SOC 2 Type I or Type II audit, and nothing on these pages is a certification, attestation, or audit report. Status labels reflect current readiness, not completed controls.