Smart Manager
SecurityPrivacyTerms

Help

Security

The short version of our Security page, focused on what you can do. We hold no security certifications yet.

Last reviewed September 27, 2026

Your own data storeEncryptionSign-in and two-factor authenticationSessionsAI providersReport a vulnerabilityMore detailMore help

Your own data store

Your workspace data lives in its own database deployment, not in tables shared with other customers. A shared control plane holds only what's needed to route requests: account identity, which data store is yours, entitlements, and usage and billing records. File storage is shared, with a separate folder for each account.

Encryption

  • All traffic uses TLS, and browsers are told to connect over HTTPS only.
  • File storage is encrypted at rest.
  • The tokens that let us read from services you connect are sealed with AES-256-GCM.
  • Searchable workspace content doesn't yet have application-level encryption; it's planned.

Sign-in and two-factor authentication

  • Sign-in runs through our identity provider, WorkOS.
  • For a sign-in protected by a second factor, use a passkey, single sign-on, or a work account whose provider enforces two-step verification.
  • Two-factor authentication is required for administrator accounts and accounts in HIPAA mode, and optional for everyone else.

Sessions

  • Standard sessions end after 7 days without activity or 30 days in total.
  • Administrator and HIPAA-mode sessions end after 15 minutes without activity or 12 hours in total.
  • Settings, Account has Sign out everywhere to end every session at once.

AI providers

We use each AI provider's business API. Under those terms, providers don't use API data to train their models by default. Every provider is named on our subprocessor list.

Report a vulnerability

Email jonathan@smartmanager.ai with the subject "Security report". We aim to acknowledge within 3 business days. Our full responsible disclosure policy and security.txt have the details.

More detail

Our Security page lists every control with its real status, including what is still in progress.

More help

  • Getting startedYour first ten minutes: setup, three questions, your first brief.→
  • Connecting accountsWhat connecting reads, what it never does, and how to disconnect.→
  • Privacy and data controlsExport your data, choose what's kept, pause processing, delete your account.→
  • BillingThe free trial, plans, storage and how to cancel.→
  • ContactHow to reach a person for support, privacy, security or legal questions.→
  • Manage YouTube dataWhat Smart Manager reads from YouTube and how to disconnect and delete it.→
© 2026 SmartManager LLC
PrivacyTermsSecurityCookiesSubprocessorsLegal updatesHelpStatusChangelogContact
Smart Manager
SecurityPrivacyTerms

Help

Security

The short version of our Security page, focused on what you can do. We hold no security certifications yet.

Last reviewed September 27, 2026

Your own data storeEncryptionSign-in and two-factor authenticationSessionsAI providersReport a vulnerabilityMore detailMore help

Your own data store

Your workspace data lives in its own database deployment, not in tables shared with other customers. A shared control plane holds only what's needed to route requests: account identity, which data store is yours, entitlements, and usage and billing records. File storage is shared, with a separate folder for each account.

Encryption

  • All traffic uses TLS, and browsers are told to connect over HTTPS only.
  • File storage is encrypted at rest.
  • The tokens that let us read from services you connect are sealed with AES-256-GCM.
  • Searchable workspace content doesn't yet have application-level encryption; it's planned.

Sign-in and two-factor authentication

  • Sign-in runs through our identity provider, WorkOS.
  • For a sign-in protected by a second factor, use a passkey, single sign-on, or a work account whose provider enforces two-step verification.
  • Two-factor authentication is required for administrator accounts and accounts in HIPAA mode, and optional for everyone else.

Sessions

  • Standard sessions end after 7 days without activity or 30 days in total.
  • Administrator and HIPAA-mode sessions end after 15 minutes without activity or 12 hours in total.
  • Settings, Account has Sign out everywhere to end every session at once.

AI providers

We use each AI provider's business API. Under those terms, providers don't use API data to train their models by default. Every provider is named on our subprocessor list.

Report a vulnerability

Email jonathan@smartmanager.ai with the subject "Security report". We aim to acknowledge within 3 business days. Our full responsible disclosure policy and security.txt have the details.

More detail

Our Security page lists every control with its real status, including what is still in progress.

More help

  • Getting startedYour first ten minutes: setup, three questions, your first brief.→
  • Connecting accountsWhat connecting reads, what it never does, and how to disconnect.→
  • Privacy and data controlsExport your data, choose what's kept, pause processing, delete your account.→
  • BillingThe free trial, plans, storage and how to cancel.→
  • ContactHow to reach a person for support, privacy, security or legal questions.→
  • Manage YouTube dataWhat Smart Manager reads from YouTube and how to disconnect and delete it.→
© 2026 SmartManager LLC
PrivacyTermsSecurityCookiesSubprocessorsLegal updatesHelpStatusChangelogContact