Encryption, RLS, audit & incident response
Security is foundational to Smartclocksystems. Every layer — from the database row to the edge function — is designed to keep your workforce data isolated, encrypted, and auditable.
AES-256 at rest
Database, file storage, backups and encrypted secret columns.
TLS 1.2+ in transit
All API and web traffic terminated with modern ciphers.
SOC 2 aligned
Our controls follow the SOC 2 framework. Built on SOC 2 certified infrastructure (Supabase, Vercel).
SSO / SAML
Enterprise SSO with SCIM provisioning for Okta, Azure AD, Google.
Row-Level Security
Tenant isolation enforced at the database, not the API.
72-hour incident SLA
Confirmed incidents reported to tenant owners within 72 h.
Three steps, every time
A repeatable playbook so a security event never becomes an outage.
Detect & contain
Automated alerts, on-call rotation paged within 5 minutes, blast radius isolated via RLS and key rotation.
Investigate & remediate
Root-cause analysis written to system_incidents, patches deployed across all tenants, audit log preserved.
Notify & report
Affected tenant owners receive a written notice within 72 hours including scope, cause and remediation.