Security

Encryption, RLS, audit & incident response

Security is foundational to Smartclocksystems. Every layer — from the database row to the edge function — is designed to keep your workforce data isolated, encrypted, and auditable.

Secure data center server racks

AES-256 at rest

Database, file storage, backups and encrypted secret columns.

TLS 1.2+ in transit

All API and web traffic terminated with modern ciphers.

SOC 2 aligned

Our controls follow the SOC 2 framework. Built on SOC 2 certified infrastructure (Supabase, Vercel).

SSO / SAML

Enterprise SSO with SCIM provisioning for Okta, Azure AD, Google.

Row-Level Security

Tenant isolation enforced at the database, not the API.

72-hour incident SLA

Confirmed incidents reported to tenant owners within 72 h.

Security operations team monitoring incidents
Incident Response

Three steps, every time

A repeatable playbook so a security event never becomes an outage.

01

Detect & contain

Automated alerts, on-call rotation paged within 5 minutes, blast radius isolated via RLS and key rotation.

02

Investigate & remediate

Root-cause analysis written to system_incidents, patches deployed across all tenants, audit log preserved.

03

Notify & report

Affected tenant owners receive a written notice within 72 hours including scope, cause and remediation.

Need our SOC 2 report or DPA?

Request documents