Smart Metrics

Smart Metrics assurance

Trust Center

A clear view of how Smart Metrics approaches security, privacy, resilience, and responsible operations across its enterprise platform.

Defense in depthPreventive, detective, and recovery controls
Access governanceLeast privilege and accountable access
Data protectionEncryption and lifecycle safeguards
Operational resilienceMonitoring, backup, and recovery practices
Our approach

Trust is an operating discipline.

Smart Metrics uses a risk-based security and privacy program designed for an enterprise platform handling workforce, operational, financial, and HSE information. Controls are reviewed as the platform, threat landscape, and regulatory environment evolve.

Transparent status: Framework references on this page describe control alignment and program direction. They do not represent third-party certification or an audit opinion unless a current certificate or report is explicitly provided.
Control framework

Built around recognized standards.

Our control library maps technical and organizational safeguards to leading international and industry frameworks.

ISO/IEC 27001Aligned

Information security governance, risk treatment, control ownership, and continual improvement.

ISO 27017 & 27018Aligned

Cloud security practices and protection of personally identifiable information in cloud environments.

SOC 2Mapped

Controls mapped to Security, Availability, Confidentiality, Processing Integrity, and Privacy criteria.

NIST CSF 2.0Mapped

Govern, Identify, Protect, Detect, Respond, and Recover functions inform program structure.

CIS Controls v8Mapped

Prioritized safeguards support asset, identity, vulnerability, logging, and recovery practices.

OWASPPractices

Application security is informed by OWASP Top 10, ASVS, and secure development guidance.

GDPR principlesSupported

Privacy controls support lawful processing, minimization, transparency, security, and data-subject rights.

ISO 22301Aligned

Business continuity concepts guide impact analysis, response planning, and recovery exercises.

WCAG 2.2Target

Product experiences target accessible interaction, perception, navigation, and understandable content.

Security controls

Protection across the service lifecycle.

Safeguards are layered across identity, applications, infrastructure, data, monitoring, people, and response processes.

Identity and access

Role-based access, least privilege, authentication controls, session protection, and periodic access review.

Secure development

Change control, peer review, dependency hygiene, security testing, and separation of environments.

Encryption and secrets

Encrypted transport, protected cloud storage, and controlled handling of credentials and service secrets.

Logging and monitoring

Security-relevant events, operational health signals, audit trails, alerting, and investigation support.

Vulnerability management

Risk-based assessment, dependency updates, remediation tracking, and coordinated vulnerability intake.

People and process

Confidentiality expectations, security awareness, accountable ownership, and documented operating procedures.

Incident response

Triage, containment, investigation, recovery, stakeholder communication, and lessons-learned review.

Auditability

Business actions and administrative changes are designed to support traceability and accountability.

Privacy and data governance

Data handled with purpose and restraint.

Smart Metrics applies privacy-by-design principles and provides configurable controls that help customers govern enterprise records according to their obligations.

01
Purpose limitationData is collected and used for defined service, support, security, and legal purposes.
02
Data minimizationCollection and access are limited to information appropriate for the configured business process.
03
Customer controlCustomers govern user access, submitted records, retention choices, and authorized use within their tenancy.
04
Retention and deletionLifecycle practices support retention, archival, export, and deletion subject to contractual and legal requirements.
05
Rights supportProcesses are designed to assist customers responding to access, correction, deletion, and portability requests.
Availability and continuity

Designed to recover and adapt.

Service resilience combines cloud-platform capabilities with operational monitoring, protected backups, incident management, and recovery planning.

Operational resilience program
Service monitoringHealth signals and alerts support timely investigation.
Backup controlsProtected recovery mechanisms reduce data-loss risk.
Recovery planningDocumented priorities guide restoration and communication.
Third-party risk

Trust extends through the supply chain.

Service providers are evaluated according to the sensitivity of data and service dependency involved. Reviews consider security posture, privacy terms, access, resilience, contractual safeguards, and changes in risk.

Due diligence

Risk-tiered assessment before introducing material technology and data-processing providers.

Contractual safeguards

Security, confidentiality, privacy, breach, and data-handling expectations where applicable.

Responsible disclosure

Report a security concern.

Help us protect Smart Metrics users.

Send a clear description, affected URL or component, reproduction steps, impact, and supporting evidence. Do not access data that is not yours, disrupt services, use social engineering, or publicly disclose an unresolved issue. We will acknowledge valid reports and coordinate remediation in good faith.

Security and privacy contact info@dreamexdatalab.com Subject: Security Report
Assurance information

Need more for your review?

Customers and qualified prospects may request available security, privacy, architecture, or vendor-risk information. Materials can be subject to confidentiality and availability.

Start an assurance request

Tell us what your security, privacy, legal, or procurement team needs.

Request information