Security FAQ
Security FAQ
Short answers to the questions prospects and enterprise reviewers ask most often.
- Is SmartQuotes SOC 2 certified?
- No. SmartQuotes has not completed a SOC 2 Type I or Type II audit. The company is building a SOC 2-aligned readiness program.
- Can SmartQuotes support an enterprise security review?
- Yes. SmartQuotes is preparing enterprise security documentation, security contacts, and control evidence to support buyer, partner, and customer review.
- Does SmartQuotes encrypt traffic?
- Production and demo environments use HTTPS/TLS for web and API access.
- Does SmartQuotes expose private partner appetite data to customers?
- No. The public customer experience does not expose private partner appetite logic, specialist-strength scoring, or restricted internal configuration.
- Who should receive security questions?
- Security questions should be sent to security@smartquotespartners.com.
- When will SmartQuotes pursue SOC 2?
- Formal SOC 2 timing is driven by enterprise pilot, buyer diligence, customer commitment, or an auditor-readiness milestone. Readiness work can begin immediately.
For enterprise review
Highlights for review
- Direct buyer answers
- Conservative SOC 2 wording
- Request-only policy library
- Security contact for deeper diligence
SmartQuotes is building its security and operational practices in alignment with SOC 2 Trust Services Criteria. SmartQuotes has not completed a SOC 2 Type I or Type II audit, and nothing on these pages is a certification, attestation, or audit report. Status labels reflect current readiness, not completed controls.