Login Start Free Trial
Security

Security

Data protection, RBAC, authentication, and audit tracking as implemented in the product.

Last updated 31 August 2026

Data protection

The Privacy Policy states that Smart Business System implements industry-standard security measures and that you can request access, correction, deletion, or portability via privacy@smartbusiness.com.

Warning

This page does not claim specific encryption algorithms, SOC/ISO certifications, or data-center regions unless those appear in official legal/security documents. None are invented here.

Privacy Policy

Data storage

Business data is stored in the application database and is company-scoped (CompanyId). Users should only see data for companies they are allowed to access.

Encryption and backups

The Privacy Policy states that Smart Business System implements industry-standard security measures. Users should access the hosted application over HTTPS.

Warning

This documentation does not specify encryption algorithms, key-management design, backup frequency, retention periods, RPO, RTO, or disaster-recovery guarantees — those details are not published in the product UI or customer-facing legal pages reviewed for this article.

Note

Verified placeholder for operations teams: Document confirmed at-rest encryption, backup schedule, and recovery objectives in your internal runbook or customer contract annex when available.

Integration credentials (Twilio, SMTP, OAuth tokens) are stored in company-scoped API configuration — protect System Settings access accordingly.

Permissions and audit tracking

Permissions use Module.Resource.Action keys with optional record scopes. Administrative user activity logging records events such as authentication and module actions available to your role.

Permission model

Feasibility studies, automation rules, and financial reports each enforce company scope and permission checks on their controllers.

Role-based access

Permissions use Module.Resource.Action keys, groups, and record scopes. See the Permission Model and RBAC governance pages.

Permission model

RBAC governance

Authentication

Users authenticate through the Account module (login, registration, password reset). The mobile API uses JWT Bearer tokens. Keep credentials private and disable unused users.

Audit tracking

User activity logging exists in the application (for example registration and authentication events). Use administrative activity views available to your role when investigating access issues.

FAQ

Where do I find Security in Smart Business 360?

Open the Security area from the main navigation and use the screens referenced in this article.

Why can I not access this feature?

Your role may lack the required permission, or the module may not be enabled for your company. Contact an administrator.

Was this article helpful?

Need help?

Contact the Smart Business 360 team if you cannot find the right guide.

Contact support