> ## Documentation Index
> Fetch the complete documentation index at: https://docs.smartbills.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

> How Smartbills protects your data

## Our Commitment to Security

Smartbills takes the security of your data seriously. We implement comprehensive security measures to protect your expense data and personal information.

## Certifications & Compliance

| Certification | Status      | Details            |
| ------------- | ----------- | ------------------ |
| SOC 2 Type II | Certified   | Annual audit       |
| GDPR          | Compliant   | EU data protection |
| CCPA          | Compliant   | California privacy |
| ISO 27001     | In Progress | Expected Q2 2025   |

## Infrastructure Security

### Cloud Infrastructure

* **Provider**: Amazon Web Services (AWS)
* **Regions**: US-East, Canada-Central, EU-West
* **Redundancy**: Multi-AZ deployment
* **Backups**: Daily automated backups

### Network Security

* DDoS protection
* Web Application Firewall (WAF)
* Private subnets for sensitive services
* Network segmentation

## Data Protection

### Encryption

| Data State | Encryption         |
| ---------- | ------------------ |
| In Transit | TLS 1.3            |
| At Rest    | AES-256            |
| Backups    | AES-256            |
| API Keys   | Hashed + Encrypted |

### Access Controls

* Role-based access control (RBAC)
* Least privilege principle
* Multi-factor authentication
* Regular access reviews

## Application Security

### Secure Development

* Security training for developers
* Code reviews for all changes
* Static application security testing (SAST)
* Dynamic application security testing (DAST)

### Vulnerability Management

* Regular penetration testing
* Bug bounty program
* Dependency scanning
* Security patches within 24 hours for critical issues

## Operational Security

### Employee Security

* Background checks
* Security awareness training
* Confidentiality agreements
* Limited data access

### Incident Response

* 24/7 monitoring
* Incident response team
* Documented procedures
* Customer notification within 72 hours

## Physical Security

Our data centers (AWS) feature:

* 24/7 security personnel
* Biometric access controls
* Video surveillance
* Environmental controls

## Your Security

### Account Security

Features to protect your account:

* Strong password requirements
* Two-factor authentication (2FA)
* Session management
* Login notifications

### Best Practices

<Tip>
  **Enable 2FA** - Add an extra layer of security to your account.
</Tip>

<Tip>
  **Use strong passwords** - Unique passwords for each service.
</Tip>

<Tip>
  **Review access regularly** - Remove unused users and integrations.
</Tip>

## Reporting Security Issues

### Bug Bounty

Report vulnerabilities responsibly:

* **Email**: [security@smartbills.io](mailto:security@smartbills.io)
* **Response**: Within 24 hours
* **Recognition**: Hall of fame and rewards

### What to Report

* Authentication bypasses
* Data exposure vulnerabilities
* XSS, CSRF, injection attacks
* Authorization flaws

## Security Updates

Subscribe to security advisories:

* Email: [security-advisories@smartbills.io](mailto:security-advisories@smartbills.io)
* Status page: status.smartbills.io

## Contact

For security questions:

* **Email**: [security@smartbills.io](mailto:security@smartbills.io)
* **PGP Key**: Available on request
