SmartSimple applies security features and certifications across every level of the system to protect data and control access down to the field level. These capabilities include role-based permissions, applicant screening against international tax authorities, maintenance mode for restricting login access during updates or incidents, forensic auditing of system usage, field change tracking, and two-factor authentication. Together, these features support organizations conducting security assessments, configuring access controls, or evaluating additional protections for an instance.
Who: Global administrators
When to Use SmartSimple Security Features
Use SmartSimple security features when:
- Your organization is completing a security assessment or vendor due diligence review and needs documentation of SmartSimple's certifications and protections.
- User access controls need to be configured, and the available security settings at the role, field, and manager levels need to be understood.
- Additional security features, such as two-factor authentication or forensic auditing, are being evaluated for an instance.
- A security incident has occurred, and the lockdown and audit capabilities available in SmartSimple need to be understood.
What Are SmartSimple Security Features
SmartSimple's security capabilities span role-based permissions, applicant screening, maintenance mode, forensic auditing, field change tracking, and two-factor authentication.
Role-Based Permissions
Role-based permissions are a central feature of SmartSimple. User roles define levels of access, ensuring information is accessible only to authorized individuals. Field-level security is also role-based. Access policies can be configured to the level of granularity required by an organization.
Applicant Screening
SmartSimple includes applicant screening options through OFAC and GuideStar. SmartSimple also integrates with the following international tax authorities to verify charitable status:
- The Internal Revenue Service (IRS).
- The Canadian Revenue Agency (CRA).
- The Australian Business Register.
- Ireland Companies Registration Office.
- Charity Commission for England and Wales.
- United Kingdom Companies House.
- United States National Center for Education Statistics (NCES).
Maintenance Mode
Global administrators can toggle Maintenance Mode on to restrict login access to specific roles during configuration changes, large data imports, testing, system updates, or a data breach. Standard users see a custom message and are temporarily unable to log in while Maintenance Mode is enabled.
Forensic Auditing
With an organization's consent, SmartSimple can monitor system usage and provide detailed access reports. This can help identify unauthorized access resulting from issues such as shared passwords and malicious data manipulation.
Reader Log and Field Change Tracking
All field changes in SmartSimple can be tracked and are subject to audit. Track Changes can be enabled on each field as required. It is not recommended to have Track Changes enabled for every field.
Two-Factor Authentication
Two-factor authentication enhances security by requiring an additional layer of user verification beyond a username and password. This significantly reduces the risk of online identity theft and fraud.
Resources
For more information about SmartSimple Security Features, see: