Personal Information Policy
We capture only the limited information needed to complete prescreening requirements. Guest access is pseudo-anonymous and no personal contact information or medical information is captured. All data entries are fully protected and encrypted. No information is shared, unless required to by government officials, for contact tracing purposes. Information is strictly confidential and shared with authorised personal only.
Data Center Security & Redundancy
We work with top-tier hosting partners to ensure that you can deliver services to your organization confidently on a platform you can trust. We have multi-site data redundancy, hosting at Equinix and AWS facilities, and our facilities are ICPA SOC 1 examined and tested as well as ISO 27001 certified Our monitoring includes biometric scanning protocols, continuous surveillance, and 24 X 7 production environment management.
Data Security
We build security into our product to ensure that your most valuable asset—your data—is protected. We contract with third-party security professionals to conduct annual security assessments. Our internal security includes third-party assessments by an external security firm and quarterly administrative access audits. Our multi-layer data access permissions enables partner security and includes policy and procedure review.
Encryption
Encryption serves as the last and strongest line of defense in a multilayered data security strategy. Smartsheet uses encryption to safeguard your data and help you maintain control over it. Here’s what you can rely on from Smartsheet: all data durably stored with NIST approved ciphers, proven transport layer security (TLS) technology from the most trusted providers, AES 256 at-rest encryption, Amazon’s S3 service to store and serve uploaded files.
Operational Management
We have implemented policies and procedures designed to ensure that your data is secure and backed up to multiple physical locations. Our team is continually evaluating new security threats and implementing updated countermeasures designed to prevent unauthorized access to or unplanned downtime of the Subscription Service. Access to all Smartsheet production systems and data is limited to authorized members of the Smartsheet Technical Operations team.