Security & compliance

Your plant data, protected

Security-minded design across the product — so you can focus on uptime. We state what we do today, what is on the roadmap, and what we do not claim without proof.

SSL / TLS in transit
HTTPS on production (modern TLS)
SOC 2 Type II
Roadmap — in progress (target Q4 2026)
Privacy / GDPR tools
Export & privacy-oriented controls
Plant backups
Admin snapshots + scheduled options

How we protect your data

Encryption

Production traffic is encrypted in transit with HTTPS/TLS via our edge/hosting platform. Data at rest is protected by our managed database provider using industry-standard encryption (typically AES-256 class).

Infrastructure

The app is hosted on Netlify with a managed Postgres database (not a self-run rack). Live health is published at our status page. We do not publish a contractual multi-region AWS SLA on this page.

Access control

Role-based permissions (Administrator, Team Leader, Technician, and others). Sessions are cookie-based with server-side invalidation. Optional MFA/2FA exists in the product and can be enabled for plants that require it.

Audit trail

Audit-friendly logging for important plant actions. Certification history and Equipment Card activity are designed to be time-stamped and reviewable. Export options support compliance packages.

Data ownership & retention

You own your plant data. Administrators can export Equipment Cards, people, parts, and related records (CSV/Excel and plant packages where enabled). Deletion and retention follow product privacy tools and our Privacy Policy — not indefinite vendor lock-in.

Vulnerability handling

We take security reports seriously. Contact us for responsible disclosure. We do not advertise a public bug-bounty program or annual third-party pen-test summary on this page unless documents are available on request.

Compliance status

SOC 2 Type II
Security, availability, confidentiality (roadmap)
In progress — target Q4 2026
ISO 27001
Information security management (roadmap)
Planned — 2027
GDPR
EU data-protection oriented product tools
Controls available*
CCPA / privacy rights
Privacy Policy + export/delete workflows where enabled
Process supported*
ITAR awareness
No ITAR-controlled data should be uploaded
Policy published

* “Controls / process available” means product features and policies exist to support privacy programs. It is not a legal certification that every customer deployment is automatically compliant — that depends on how your organization uses the product.

Important: ITAR-controlled data

Do not upload, paste, photograph, record, store, transmit, or send ITAR-controlled technical data, drawings, files, images, specifications, or any other ITAR-controlled content into this application or to its AI assistant. This application is not authorized for ITAR-controlled data. If you are unsure whether information is ITAR-controlled, stop and contact your plant export compliance officer before uploading or sending it.

app.smartuptimepro.com/legal/itar →

Questions about security?

Contact us for a security questionnaire, vendor review call, or responsible disclosure. Use help@ for plant support; put “Security” in the subject line for security reviews.

Contact security / support System status Privacy Policy