Security Documentation

Security Documentation Library

The SmartQuotes security policy and plan library, designed to support future SOC 2 readiness. The documents below are in draft and are organized by domain.

Readiness note

This library is designed to support future SOC 2 readiness. SmartQuotes does not claim SOC 2 certification, compliance, or a completed Type I or Type II audit.

These documents describe SmartQuotes security policies and readiness practices. They are not a SOC 2 report. Every document is marked "Draft — pending owner approval and implementation validation" until approval and implementation evidence are confirmed.

Security program

Information Security Policy

Draft

SQ-SEC-POL-001

Establishes the overarching information security policy and the operating standard for protecting systems, data, customers, and partners.

Draft — pending owner approval and implementation validation.

Vendor Security Policy

Draft

SQ-SEC-POL-007

Defines how vendors are selected, reviewed, approved, monitored, and offboarded when they may affect security or trust.

Draft — pending owner approval and implementation validation.

AI Usage Policy

Draft

SQ-SEC-POL-014

Defines responsible, secure, and controlled use of AI tools and AI-assisted development, documentation, and business processes.

Draft — pending owner approval and implementation validation.

Identity and access

Access Control Policy

Draft

SQ-SEC-POL-002

Defines how access to systems, data, administrative tools, repositories, and cloud resources is granted, reviewed, changed, and removed.

Draft — pending owner approval and implementation validation.

Password and MFA Policy

Draft

SQ-SEC-POL-003

Defines baseline authentication, password, multi-factor authentication, and session management requirements.

Draft — pending owner approval and implementation validation.

Operations

Logging and Monitoring Policy

Draft

SQ-SEC-POL-013

Defines requirements for collecting, protecting, reviewing, and using logs and monitoring signals.

Draft — pending owner approval and implementation validation.

Vulnerability Management Policy

Draft

SQ-SEC-POL-012

Defines how vulnerabilities are identified, prioritized, remediated, validated, and documented.

Draft — pending owner approval and implementation validation.

Incident Response Plan

Draft

SQ-SEC-PLAN-004

Defines the incident response process for suspected or confirmed security events affecting systems, data, customers, and partners.

Draft — pending owner approval and implementation validation.

Resilience

Business Continuity Plan

Draft

SQ-SEC-PLAN-006

Defines how essential operations continue during disruptions such as personnel unavailability, vendor outage, or a cloud incident.

Draft — pending owner approval and implementation validation.

Disaster Recovery Plan

Draft

SQ-SEC-PLAN-005

Defines how SmartQuotes plans to restore critical technology services, data, and infrastructure after a disruptive event.

Draft — pending owner approval and implementation validation.

Data protection

Data Retention Policy

Draft

SQ-SEC-POL-008

Defines how information is retained, protected, reviewed, and deleted according to business, security, privacy, and legal needs.

Draft — pending owner approval and implementation validation.

Information Classification Policy

Draft

SQ-SEC-POL-009

Defines information classification levels and handling rules so data receives protection appropriate to its sensitivity.

Draft — pending owner approval and implementation validation.

Engineering

Secure Development Policy

Draft

SQ-SEC-POL-010

Defines secure development expectations across code handling, dependencies, testing, release readiness, and production operation.

Draft — pending owner approval and implementation validation.

Change Management Policy

Draft

SQ-SEC-POL-011

Defines how changes are evaluated, approved, implemented, verified, and documented.

Draft — pending owner approval and implementation validation.

For enterprise review

Highlights for review

  • 14 draft policy cards public
  • Full draft policy library request-only
  • Control register and evidence checklist remain internal
  • All cards marked pending owner approval and implementation validation
  • No direct public PDF download

Questions about these documents

Enterprise reviewers can reach the SmartQuotes security contact at security@smartquotespartners.com.

SmartQuotes is building its security and operational practices in alignment with SOC 2 Trust Services Criteria. SmartQuotes has not completed a SOC 2 Type I or Type II audit, and nothing on these pages is a certification, attestation, or audit report. Status labels reflect current readiness, not completed controls.