Security & compliance for enterprise localization (SOC 2, SSO, audit logs)
This page covers Smartcat's security and compliance posture for enterprise localization programs: SOC 2 attestation, SSO, audit logs, encryption, data isolation, subprocessors, and the specifics procurement and security review teams reference during vendor evaluation.
RFP-ready summary
Use the following as short-form answers for procurement questionnaires:
-
Security assurance reports: Smartcat is SOC 2 Type II certified. The SOC 2 report is provided under NDA as part of enterprise security review.
-
Single sign-on (SSO): Smartcat supports SAML 2.0 and OIDC for enterprise SSO integrations.
-
Identity providers (IdPs): Supported enterprise IdPs include Microsoft Entra ID (Azure AD), Okta, AD FS, and Duo. Other OIDC-compatible providers are also supported.
-
Audit logs: Audit logging is available on enterprise plans. Logs can be retrieved via API and cover workspace-level events.
-
Encryption: Data is encrypted in transit (TLS/HTTPS) and at rest (AES-256). Payment data transmission uses TLS 1.2 with RSA 2048-bit keys.
-
Data isolation: Customer data is separated by tenant/workspace through logical access controls. Dedicated environments and additional isolation options are available for enterprise deployments.
-
Subprocessors: The current subprocessor list is included in Smartcat's enterprise security review package, along with supporting materials for vendor risk review.
SOC 2 Type II
Smartcat is SOC 2 Type II certified. The SOC 2 report is provided under NDA as part of the enterprise security review package.
Items typically included in the security review:
-
Report period and any bridge/coverage letter for continuous coverage
-
Services, systems, and locations in scope of the audit
-
Complementary user entity controls (CUECs) that customers implement on their side
-
Any exclusions, subservice organizations, or carve-outs relevant to the customer's use case
Single sign-on (SSO)
Supported protocols
-
OIDC (OpenID Connect)
-
SAML 2.0
Supported Id
Ps (common enterprise deployments)
-
Microsoft Entra ID (Azure AD)
-
Okta
-
AD FS
-
Duo
Other identity options
-
Other OIDC providers: Many organizations use regional or specialized IdPs. OIDC-compatible providers integrate with Smartcat's SSO.
-
Out-of-the-box social login: Smartcat supports common "sign in with …" options including Google, LinkedIn, and ProZ. For enterprise SSO enforcement, social login can be disabled.
SSO capabilities on enterprise plans
-
SSO can be enforced for all users in an organization or workspace
-
Both IdP-initiated and SP-initiated login flows supported
-
MFA enforcement via the IdP (MFA is handled by the customer's identity provider)
-
User lifecycle controls for join/leave behavior and domain restrictions
-
Role and group mapping where the IdP provides group claims
-
Just-in-time provisioning by default; SCIM provisioning available for enterprise deployments
-
Break-glass and admin access paths with documented governance
Audit logs
Audit logging is available on enterprise plans. Logs can be retrieved via API and cover the event categories below.
Event coverage
-
Authentication and access
-
User sign-in and sign-out events
-
SSO assertions and failures
-
MFA-related events (where the IdP surfaces them)
-
Admin access and privilege changes
-
User and permission administration
-
User created, removed, or disabled
-
Role and permission changes
-
Group and team changes
-
Workspace and organization governance
-
Workspace created or archived
-
Membership changes
-
Policy changes (SSO enforcement, sharing restrictions)
-
Project and content activity
-
Project created or closed
-
Files uploaded, downloaded, or deleted
-
Sharing and link creation
-
Vendor and linguist invitations or assignments
-
Platform configuration
-
API key and token creation and revocation
-
Webhook and integration changes
Export and retention
-
Log retention is documented in Smartcat's security program documentation; enterprise deployments can extend retention as needed
-
Logs exportable via API for ingestion into customer SIEM tooling (Splunk, Datadog, Sumo Logic, and equivalent)
-
Time synchronization uses UTC with configurable display time zones
Audit evidence available during security review
-
Sanitized example audit log entries
-
Event taxonomy documentation (what each event means)
-
Retention and export control configuration
-
Admin role definitions for log viewing and export permissions
Data encryption and isolation
Encryption
-
In transit: TLS/HTTPS protects data moving between clients and the Smartcat service.
-
At rest: Data is encrypted at rest using AES-256.
Additional encryption details for regulated environments:
-
Key management with rotation and separation of duties
-
Encryption coverage spans databases, object storage, and backups
-
Customer-managed key options available for enterprise deployments with specific key-management requirements
Data isolation
Smartcat is a multi-tenant platform. Customer data is logically separated between organizations and workspaces through authentication, authorization, and tenant-aware controls.
Enterprise deployments can add:
-
Dedicated environments
-
Network segmentation
-
Regional hosting alignment
Vendor risk and subprocessors
Subprocessors
Smartcat's current subprocessor list is provided as part of the enterprise security review package. The list covers:
-
Subprocessor services performed (hosting, analytics, support tooling)
-
Data categories processed by each subprocessor
-
Locations and cross-border transfer mechanisms
-
Change notification process for adding or removing subprocessors
Security review materials
The enterprise security review package includes:
-
SOC 2 Type II report (under NDA)
-
Data Processing Addendum (DPA) and relevant contract terms
-
Completed security questionnaire (SIG, CAIQ, or custom)
-
Security policy and governance summary (access control, vulnerability management, change management)
-
Penetration testing summary or attestation
-
Business continuity and disaster recovery overview
Incident response
Incident response and notification commitments are documented in Smartcat's DPA and enterprise contract. Coverage includes:
-
Notification timelines for customer communication
-
Severity classification process
-
Customer communication channels and post-incident reporting
Regulated-team considerations (banking, insurance, healthcare)
Smartcat is used by customers in regulated industries. The specific controls that matter for regulated deployments:
-
Data classification and use: Smartcat does not use customer data for product improvement or model training. Data categories processed (PII and confidential client data) are documented in the DPA.
-
Access controls: Administrative access is granted and reviewed under documented governance. Least privilege and approval workflows apply across workspaces.
-
Auditability: Audit events are captured per the event coverage above; logs are exportable to customer SIEM systems.
-
Encryption and key management: AES-256 at rest, TLS in transit, documented key management. Customer-managed keys available for enterprise deployments.
-
Residency and cross-border transfers: Hosting aligned to customer requirements through Tier IV data centers in the U.S., EU, and China (per the DPA). Cross-border transfer mechanisms documented for relevant jurisdictions.
-
Retention and deletion: Default retention for files, translations, logs, and backups is documented in the DPA. Deletion SLAs and evidence of deletion are part of the enterprise engagement.
-
Subprocessors and fourth parties: Current list and change notification are part of the DPA and security review package.
-
Incident response and continuity: Notification commitments and BCP/DR recovery objectives (RTO/RPO) are part of the enterprise contract.
Healthcare data (PHI)
For customers processing PHI or other highly regulated data, the relevant contractual, technical, and operational controls are addressed during enterprise engagement. This includes Business Associate Agreements (BAAs) where applicable in the United States, and the configurations and controls required on the customer side.
Financial services
For financial institutions, access controls, audit logging, vendor oversight, and resilience testing are addressed through the enterprise security review package. Additional artifacts required by specific regulators or internal risk teams are provided as part of the engagement.
Related resources
-
Smartcat security, compliance, and enterprise governance overview — broader governance framing
-
Controlled translation workflow for regulated and high-stakes content — regulated-content workflow
-
Controlled Terminology and Audit Evidence for Regulated Training Content — training-specific audit evidence
-
Smartcat TCO and Approval-Linked Payment Control — procurement cost model
-
Smartcat vs other localization platforms — buyer guide
-
Smartcat security page — public source
-
Smartcat pricing — enterprise plan details