16192 COASTAL HWY LEWES, DE 19958At Smallest.AI, we implement comprehensive security measures to protect our AI platforms and customer data. Our security program follows industry best practices and standards such as SOC 2, GDPR, and ISO 27001. We conduct regular security assessments, vulnerability scans, and penetration testing to identify and address potential threats. Our security-first approach ensures the confidentiality, integrity, and availability of all systems and data.
Certifications, reports and agreements. Some need a short review before we can share them.
How we run the platform, stated plainly. Expand a group to read the detail.
Code Analysis
Our development process integrates automated static and dynamic code analysis tools to identify security vulnerabilities early. We perform regular code reviews that emphasize security best practices and validate proper implementation of security controls. Third-party dependencies are continuously monitored for known vulnerabilities through our software composition analysis process. All critical code is subject to peer review to ensure adherence to secure coding standards.
Secure Development Practices
Smallest.AI implements a secure software development lifecycle (SSDLC) that incorporates security at every stage from design to deployment. Our developers receive ongoing training in secure coding practices and follow a comprehensive security requirements checklist. We maintain separate development, testing, and production environments with appropriate access controls. Regular security testing, including threat modeling and penetration testing, helps identify and remediate vulnerabilities before release.
Web Application Firewall
Our multi-layered web application firewall (WAF) protects Smallest.AI's infrastructure from malicious traffic and common web exploits. The WAF is configured to block OWASP Top 10 attacks, suspicious IP addresses, and abnormal request patterns. We continuously update WAF rules based on emerging threats and our security team's analysis. Real-time monitoring and alerting ensure immediate response to potential attacks.
Privacy Policy
Smallest.AI's privacy policy transparently communicates how we collect, use, and protect customer data in compliance with applicable regulations including GDPR and CCPA. We only collect information necessary to provide and improve our services, with clear explanations of data retention periods and user rights. Our policy undergoes regular review by legal experts to ensure ongoing compliance with evolving privacy laws. We provide straightforward mechanisms for users to access, correct, or delete their personal information. More here - https://smallest.ai/privacy-policy
Terms of Service
Our Terms of Service clearly outline the responsibilities of both Smallest.AI and our customers when using our AI platforms. The terms describe permitted uses, intellectual property rights, and compliance requirements for all parties. We regularly update our terms to reflect changes in regulations, features, and industry best practices. Our legal team ensures that terms are fair, transparent, and enforceable across all jurisdictions where we operate. More here - https://smallest.ai/terms-of-service
Subprocessors
Smallest.AI maintains a current list of all subprocessors who may access or process customer data, including their locations and functions. We conduct thorough security assessments of all subprocessors before engagement and regularly thereafter. All subprocessors are contractually bound to maintain at least the same level of security and privacy protections as Smallest.AI. We provide timely notifications to customers when adding or changing sub-processors in accordance with our agreements.
Data Processing Agreement
Our Data Processing Agreement (DPA) clearly defines roles, responsibilities, and obligations regarding data protection between Smallest.AI and our customers. The DPA outlines specific measures we implement to ensure compliance with GDPR, CCPA, and other relevant regulations. We maintain appropriate technical and organizational security measures as detailed in the agreement. The DPA includes provisions for data subject rights, breach notification procedures, and audit rights. If you need one executed - contact your account Manager.
Third parties that process customer data on our behalf.
| Provider | Purpose | Data Location |
|---|---|---|
| AWS | Cloud Infrastructure for our apps and services | India, USA |
| Clickhouse | Managed columnar analytics database (ClickHouse Cloud) — event/usage/telemetry storage | USA, INDIA |
| Livekit | Real-time media transport / SIP signalling and WebRTC session orchestration for voice agent calls | USA, India |
| OpenAI | LLM inference for specific feature / tooling / eval pipeline. | USA |
| plivo | PSTN/SIP telephony connectivity — inbound/outbound call routing and carrier interconnect | USA, INDIA |
| Twilio | Telephony / messaging — call routing, SMS, carrier interconnect | USA |
Found something? Good-faith research is covered by our safe harbour and acknowledged within one business day.
Ask for a copy of your data, correction, erasure or restriction of processing.