At Smovin, data protection is a top priority. Here are the most common questions we get about how we keep your information secure.
🛡️ How does Smovin protect my data?
- Data at rest encryption: All stored data is encrypted using AES-256, one of the most secure standards. 
- Data in transit encryption: All communication is secured with TLS 1.2 or higher. 
- Secured APIs: Integrations use OAuth 2.0 or API keys with limited access. 
- Access control: Only authorized users can access data through Role-Based Access Control (RBAC). 
📍 Where is my data stored?
Your data is hosted in AWS data centers in Frankfurt (Germany), ensuring full compliance with GDPR and European privacy regulations.
🔄 How does Smovin prevent data loss?
- Daily automated backups of all data. 
- Point-in-Time Recovery (PITR) allows us to restore the database to any specific moment. 
- PostgreSQL replication ensures availability even in case of failure. 
👁️ Does Smovin detect suspicious activity?
Yes. We use several tools for continuous monitoring and threat detection:
- Sentry for real-time error tracking. 
- Scout APM for performance monitoring. 
- Cloudflare for DDoS protection and traffic security. 
All critical events are logged and reviewed by our technical team.
📲 Is my Smovin account access secure?
- All sessions are encrypted and protected. 
- Token expiration policies ensure inactive sessions are closed. 
- Role-based permissions restrict access to sensitive features. 
🔗 Are integrations with other tools safe?
Absolutely. Smovin integrates only with trusted services through secure REST APIs:
- Connections to tools like Exact Online, Twilio, or Intercom are fully secured. 
- Data sharing is limited to what’s necessary and nothing more. 
🔄 Does Smovin perform regular security checks?
Yes:
- Continuous vulnerability scanning. 
- Automated code audits through our CI/CD pipeline. 
- Regular internal security policy reviews. 
✅ Is Smovin GDPR compliant?
Yes. Smovin is fully GDPR compliant:
- Data hosted in Europe. 
- No unauthorized data sharing or misuse. 
- Transparent and responsible data handling. 
