Information Security Policy
DraftSQ-SEC-POL-001
Establishes the overarching information security policy and the operating standard for protecting systems, data, customers, and partners.
Draft — pending owner approval and implementation validation.
The SmartQuotes security policy and plan library, designed to support future SOC 2 readiness. The documents below are in draft and are organized by domain.
This library is designed to support future SOC 2 readiness. SmartQuotes does not claim SOC 2 certification, compliance, or a completed Type I or Type II audit.
These documents describe SmartQuotes security policies and readiness practices. They are not a SOC 2 report. Every document is marked "Draft — pending owner approval and implementation validation" until approval and implementation evidence are confirmed.
SQ-SEC-POL-001
Establishes the overarching information security policy and the operating standard for protecting systems, data, customers, and partners.
Draft — pending owner approval and implementation validation.
SQ-SEC-POL-007
Defines how vendors are selected, reviewed, approved, monitored, and offboarded when they may affect security or trust.
Draft — pending owner approval and implementation validation.
SQ-SEC-POL-014
Defines responsible, secure, and controlled use of AI tools and AI-assisted development, documentation, and business processes.
Draft — pending owner approval and implementation validation.
SQ-SEC-POL-002
Defines how access to systems, data, administrative tools, repositories, and cloud resources is granted, reviewed, changed, and removed.
Draft — pending owner approval and implementation validation.
SQ-SEC-POL-003
Defines baseline authentication, password, multi-factor authentication, and session management requirements.
Draft — pending owner approval and implementation validation.
SQ-SEC-POL-013
Defines requirements for collecting, protecting, reviewing, and using logs and monitoring signals.
Draft — pending owner approval and implementation validation.
SQ-SEC-POL-012
Defines how vulnerabilities are identified, prioritized, remediated, validated, and documented.
Draft — pending owner approval and implementation validation.
SQ-SEC-PLAN-004
Defines the incident response process for suspected or confirmed security events affecting systems, data, customers, and partners.
Draft — pending owner approval and implementation validation.
SQ-SEC-PLAN-006
Defines how essential operations continue during disruptions such as personnel unavailability, vendor outage, or a cloud incident.
Draft — pending owner approval and implementation validation.
SQ-SEC-PLAN-005
Defines how SmartQuotes plans to restore critical technology services, data, and infrastructure after a disruptive event.
Draft — pending owner approval and implementation validation.
SQ-SEC-POL-008
Defines how information is retained, protected, reviewed, and deleted according to business, security, privacy, and legal needs.
Draft — pending owner approval and implementation validation.
SQ-SEC-POL-009
Defines information classification levels and handling rules so data receives protection appropriate to its sensitivity.
Draft — pending owner approval and implementation validation.
SQ-SEC-POL-010
Defines secure development expectations across code handling, dependencies, testing, release readiness, and production operation.
Draft — pending owner approval and implementation validation.
SQ-SEC-POL-011
Defines how changes are evaluated, approved, implemented, verified, and documented.
Draft — pending owner approval and implementation validation.
Enterprise reviewers can reach the SmartQuotes security contact at security@smartquotespartners.com.