Skip to main content
Smartbox.ai

Built for procurement

A platform your security team can sign off.

Engineered for UK regulated buyers — procurement-ready out of the box. Every control on this page maps to a question already asked by NHS DSPT, ISO 27001, Cyber Essentials Plus, and most enterprise security teams.

Certifications and frameworks

What we hold today, and what we're working toward.

  • Cyber Essentials Plus — certified

    UK government-backed cyber security baseline, independently audited.
  • ISO/IEC 27001

    Certified by the British Standards Institution (BSI). Independently audited information security management across the platform.
  • UK GDPR / Data Protection Act 2018

    Aligned by design. The platform is engineered for UK regulatory work.
  • NHS DSPT, Liberty Global GTC

    Past responses to UK public-sector and commercial-enterprise procurement standards available on request.
  • SOC 2 Type II

    On the published roadmap.

Platform facts

The controls behind the certifications.

  • Tenant isolation & data residency

    Logical isolation per tenant on Public Cloud (UK AWS regions). Physical isolation on Private Cloud (single-tenant deployment, dedicated AWS account, per-tenant encryption keys). BYOC (Bring Your Own Cloud) for customers whose data must stay in their own cloud organisation, where the environment is theirs and we have no visibility of it at all.
  • We are not in your data

    No Smartbox employee has standing access to customer content. Our CTO holds access. Support and engineering staff can be granted it only when you actively approve it for that occasion, and every access is logged. Smartbox is software, not a managed service: there is no review team here reading your files.

    Customer-hosted deployments go further still — where you run Smartbox in your own cloud organisation, the environment is yours, we do not operate it, and we have no access to it at all. That is also why the question of SC-cleared personnel does not arise: clearance governs the people who access material, and on a Smartbox deployment those people are yours.

  • Identity, access & audit

    SSO (SAML / OIDC) and enforced MFA. Role-based access control — Reviewer, Redactor, Approver, Admin — with per-matter overrides and matter-level information barriers. Immutable audit log across every user action, exportable for compliance review.
  • Encryption, integrity & malware

    AES-256 at rest, TLS 1.2+ in transit, per-tenant encryption keys on Private Cloud. Antivirus scan on every file at ingestion — reviewers never open an infected attachment. Every file fingerprinted with SHA3-256 at ingest, and every lifecycle event written to an append-only, hash-chained ledger.

FAQ

Frequent procurement questions.

  • Where is data hosted?
    UK AWS regions by default. Private Cloud deployments run in a dedicated AWS account. For customers who need the environment entirely under their own control, Smartbox runs in your own cloud organisation.
  • Will the audit trail stand up at Tribunal?
    Files are fingerprinted with SHA3-256 at ingest. Every lifecycle event — ingestion, classification, redaction, override, disclosure — is then written to an append-only ledger where each row is SHA-256 hash-chained to the one before it, so tampering is detectable by re-verification. Nothing updates or deletes a row. The trail is exportable for ICO submissions and reconstructable at Tribunal.
  • Do your staff need security clearance to handle our data?
    No. Nobody here has standing access to your content: our CTO holds access, and support and engineering staff can be granted it only when you actively approve it for that occasion, with every access logged. Smartbox is software, not a managed service, so there is no review team here handling your files. Customers who need the environment itself under their own control run Smartbox in their own cloud organisation, where we have no access at all.

Request our procurement pack.

Trust & Security overview, DPIA template, sub-processor list — sent within one working day.

Contact us

We use cookies to measure how the site is used, and — if you agree — to measure our advertising. You can accept one without the other, and declining is one click. See our cookie policy.