Compliance

SOC 1 Type 2
Audit period completed; report issuance pending

SOC 2 Type 2
SmartBarrel has successfully completed its SOC 2 Type II audit.
Resources
SOC 1 Type 2
SmartBarrel is actively working toward SOC 1 Type II compliance
SOC 2 Type 2
SmartBarrel maintains SOC 2 Type II compliance for its security controls and operational practices.
Privacy Policy
SmartBarrel Privacy Policy
Terms and Conditions
Terms governing the use of SmartBarrel products, services, and platform access.
InfoSec
Information Security Policy 10/27/2025
Photo Verification Overview
Overview of SmartBarrel’s facial verification process and data handling practices used to support accurate worker verification and payroll integrity.
Quebec Biometric Compliance (CCQ)
Documentation relative aux pratiques de conformité biométrique, de consentement et de vérification faciale de SmartBarrel pour les déploiements au Québec et auprès de la CCQ.
U.S. Company & Operations Overview
Overview of SmartBarrel’s U.S.-based operations, infrastructure, and support organization.
FAR & NDAA Hardware Compliance
Documentation outlining SmartBarrel’s compliance with FAR 52.204-25 and NDAA Section 889 requirements for hardware and telecommunications equipment.
Subprocessors
Each subprocessor is assessed based on the type of data processed and level of access to SmartBarrel customer data.

Amazon Web Services
Cloud infrastructure provider used to host SmartBarrel applications, databases, and file storage. Processes application data, user data, and system logs.
Microsoft 365 (Teams)
Customer communication and collaboration platform used for meetings, support interactions, onboarding, and ongoing account management.

Hubspot
Customer support and communication platform used to manage support tickets, customer interactions, and service requests.

Altassian
Issue tracking and engineering workflow platform used to manage customer-reported issues, bugs, and feature requests. Processes customer-related issue data, logs, and support context.

Plivo
SMS communication provider used to send notifications and alerts to users. Processes phone numbers and SMS message content.
Google Workspace
Document storage and collaboration platform. Processes customer documents and shared files.
