Security & Trust
This page describes the safeguards we have in place today to protect your data. It's written to be accurate and honest about both what we do and what we haven't done yet.
Local-first by default
SMRTscan is built so your data stays on your device unless you choose otherwise. Receipts, accounting records, mileage, and payroll data are stored locally in an on-device database by default. Data leaves your device only when you use a feature that requires it — AI scanning, optional cloud backup, team workspaces, mileage geocoding, or analytics — and we send only what that feature needs.
How we protect your data
- Encryption in transit. All communication between the app and our services uses HTTPS/TLS.
- Sensitive data on your device. Highly sensitive fields — employee SIN/SSN and bank details — are stored in your device's hardware-backed secure storage (Apple Keychain on iOS, Android Keystore on Android). Our on-device database holds only a placeholder value, not the secret itself. You can also lock the app with Face ID / Touch ID.
- Sensitive identifier protection. For text fields, we redact or mask sensitive identifiers (full SIN/SSN, complete bank-account numbers) where feasible before sending them to an AI provider. For images and PDFs, those identifiers may be visible to the provider; we add server-side instructions and post-processing so that full SIN/SSN or bank-account numbers are not returned to, or stored by, SMRTscan.
- AI providers don't train on your data. We do not use your content to train SMRTscan models. Receipt and document scanning is powered by AI providers (Anthropic, OpenAI, Google Gemini), which process each request under their business/API terms only to return your result; under those terms API data is not used to train their models, and processing is transient.
- Your cloud, not ours. If you turn on cloud backup, your data goes to your own iCloud or Google Drive account. We never receive your cloud credentials and don't store your backups on our servers.
- Access controls for shared workspaces. Team Workspace data is protected with row-level security so members only see what they're authorized to. Secrets and keys are held as platform-managed secrets, never embedded in the app.
- Payments stay with the stores. Subscriptions are billed by the Apple App Store or Google Play. We never see or store your card details.
Our security program
We maintain a written information-security program with administrative, technical, and physical safeguards appropriate to the sensitivity of the data we handle, including access controls, encryption in transit, sensitive-field secure storage, and periodic review. We have a documented Security Incident Response Plan and maintain an incident register. If a breach ever creates a real risk of significant harm, we will notify affected users and the appropriate regulators — in Canada, the Office of the Privacy Commissioner; in Quebec, the Commission d'accès à l'information — as required by law.
Privacy & compliance
SMRTscan is a Canadian company and we design for Canadian privacy law:
- PIPEDA (federal) and Quebec Law 25 — including a named Privacy Officer, breach notification, data portability (in-app export), and privacy impact assessments before transferring data outside Quebec.
- U.S. state privacy laws (CCPA/CPRA and others) — disclosure of sensitive-data categories, no sale or cross-context-advertising "sharing," and consumer rights to access, delete, correct, and limit.
- CASL — promotional messages only with your opt-in.
See our Privacy Policy and Terms of Service for full detail. Business customers can request our Data Processing Addendum (DPA) and sub-processor list at privacy@smrtscan.app.
Sub-processors
We use a small set of vetted third parties to operate the Service. The current list is maintained in our Privacy Policy §4 and includes our AI providers (Anthropic, OpenAI, Google Gemini), Supabase (backend), RevenueCat (subscriptions), PostHog (analytics), Resend (email), Cloudflare and Vercel (web), Apple/Google (cloud backup, maps), and Google AdMob (free-tier ads). We give advance notice before adding a new sub-processor that handles personal information.
Reporting a vulnerability
Found a security issue? We want to know. Email security@smrtscan.app. We won't pursue legal action against good-faith research conducted under this policy.
Scope
In scope: the SMRTscan iOS and Android apps, smrtscan.app and services we operate, and our Supabase backend and Edge Functions as reached through the app.
Out of scope: our third-party providers' own infrastructure (report those to the provider); findings needing physical access to an unlocked device; social engineering or phishing; denial-of-service / volumetric testing; and automated-scanner output with no demonstrated impact.
How to report
Email security@smrtscan.app with a description of the issue, steps to reproduce (a proof-of-concept is appreciated), the impact you believe it has, and how you'd like to be credited. Please report promptly and give us a reasonable chance to fix it before any public disclosure.
Rules of engagement (safe harbor)
When you act in good faith under this policy, you may test only against accounts you own or have permission to test, and you must stop and report immediately if you encounter data that is not yours rather than accessing, copying, or modifying it. You must not access, alter, or delete data that isn't yours, degrade the service, or use a finding beyond demonstrating it. If you follow these rules, we treat your research as authorized and will work with you in good faith. This safe harbor applies only to claims by SMRTscan and does not bind third parties or cover conduct that violates applicable law.
What to expect from us
- Acknowledgement within 5 business days.
- A triage and severity assessment, with status updates.
- A good-faith effort to remediate valid issues promptly, prioritized by severity.
- Credit for your discovery, with your permission, once resolved.
We don't currently run a paid bug-bounty program, but we're grateful for responsible disclosure and will recognize valid reports.
Honest status — what we have and haven't done
We believe in being straight about our security maturity:
- ✅ Local-first storage, TLS, hardware-backed secure storage for payroll PII, sensitive-data masking, no-training AI terms, row-level security for workspaces, documented incident response, and a privacy program aligned to PIPEDA and Quebec Law 25.
- ⏳ In progress / planned as we grow: an independent third-party security assessment (penetration test) and formal SOC 2 attestation.
We are not SOC 2 certified, ISO 27001 certified, or HIPAA compliant today, and we don't claim to be. SMRTscan is not designed to handle healthcare PHI. We'll update this page as we complete each step.
Questions about security or privacy? Email security@smrtscan.app or privacy@smrtscan.app.