Documentation
Data protection, RBAC, authentication, and audit tracking as implemented in the product.
Last updated 31 August 2026
The Privacy Policy states that Smart Business System implements industry-standard security measures and that you can request access, correction, deletion, or portability via privacy@smartbusiness.com.
This page does not claim specific encryption algorithms, SOC/ISO certifications, or data-center regions unless those appear in official legal/security documents. None are invented here.
Business data is stored in the application database and is company-scoped (CompanyId). Users should only see data for companies they are allowed to access.
The Privacy Policy states that Smart Business System implements industry-standard security measures. Users should access the hosted application over HTTPS.
This documentation does not specify encryption algorithms, key-management design, backup frequency, retention periods, RPO, RTO, or disaster-recovery guarantees — those details are not published in the product UI or customer-facing legal pages reviewed for this article.
Verified placeholder for operations teams: Document confirmed at-rest encryption, backup schedule, and recovery objectives in your internal runbook or customer contract annex when available.
Integration credentials (Twilio, SMTP, OAuth tokens) are stored in company-scoped API configuration — protect System Settings access accordingly.
Permissions use Module.Resource.Action keys with optional record scopes. Administrative user activity logging records events such as authentication and module actions available to your role.
Feasibility studies, automation rules, and financial reports each enforce company scope and permission checks on their controllers.
Permissions use Module.Resource.Action keys, groups, and record scopes. See the Permission Model and RBAC governance pages.
Users authenticate through the Account module (login, registration, password reset). The mobile API uses JWT Bearer tokens. Keep credentials private and disable unused users.
User activity logging exists in the application (for example registration and authentication events). Use administrative activity views available to your role when investigating access issues.
Open the Security area from the main navigation and use the screens referenced in this article.
Your role may lack the required permission, or the module may not be enabled for your company. Contact an administrator.
Contact the Smart Business 360 team if you cannot find the right guide.