How does Smovin protect my data?
Encryption of data at rest with the AES-256 algorithm.
Encryption of data in transit via TLS 1.2 or higher.
Secure APIs: external integrations use OAuth 2.0 or API keys with restricted access.
Access management through role-based access control (RBAC).
Where is my data stored?
Your data is hosted in the AWS data centres in Frankfurt (Germany), in compliance with the GDPR.
What does Smovin do to prevent data loss?
Automatic daily backups.
Point-in-Time Recovery (PITR) to restore the database to a precise moment.
PostgreSQL replication to ensure availability in the event of an outage.
Does Smovin detect suspicious activity?
Yes, through continuous monitoring and detection tools: Sentry (error tracking), Scout APM (application performance) and Cloudflare (DDoS protection). Critical incidents are analysed by the technical team.
Is my Smovin account secure?
Sessions are encrypted and protected.
Tokens expire automatically after a period of inactivity.
Access to certain features is limited according to roles.
Are integrations with other tools safe?
Yes. Smovin integrates only with trusted services via secure REST APIs; connections (for example Exact Online, Twilio, Intercom) are strictly controlled and no unnecessary data exchange is allowed.
Are security audits carried out?
Yes: continuous vulnerability scans, automated code audits via the CI/CD pipeline, and regular review of internal policies.
Is Smovin GDPR-compliant?
Yes: data stored in Europe, no misuse or unauthorised transfer, and a clear privacy policy.
Questions?
Contact us via the chat.
