Security & Data Architecture
SmartEPT is built so that your operational data stays where you decide. This page explains, in plain terms, where data lives, how it moves, and what Ametecs can and cannot see, for both deployment models. Items marked ⚑ to confirm are being verified with Ametecs engineering and will be finalised before they are presented as guarantees.
1. Client Hosted — your infrastructure
Screenshots, activity records, camera events and productivity data remain within your organisation’s own server or private cloud. Ametecs receives only the licence and support metadata needed to keep the product activated.
SmartEPT Agent
on your infrastructure
your disk, your control
2. Managed Cloud — hosted by Ametecs
For organisations that prefer Ametecs to host and manage the platform, operational data is stored in the SmartEPT Managed Cloud under controlled, per-tenant access. You remain the owner and controller of the data.
SmartEPT Agent
HTTPS/TLS in transit
per-tenant isolation
3. What we cover
- Data location — Client Hosted: your own server or private cloud. Managed Cloud: Ametecs-managed, isolated per tenant.
- Encryption in transit — the client portal and the licence-server API run over HTTPS/TLS. Managed Cloud connections are encrypted in transit.
- Encryption at rest — ⚑ to confirm per deployment; we will only state at-rest encryption where it is enabled and verifiable.
- Authentication — portal passwords are stored hashed; one-time verification codes are hashed and short-lived; portal access is rate-limited.
- Role-based access — administrative functions are separated by role (for example super-admin and sales), so staff see only what their role permits.
- Audit logs — sensitive administrative and billing actions are written to an audit log.
- Tenant separation — on Managed Cloud, each customer’s data is isolated per tenant.
- Backups — Managed Cloud includes standard managed backups. On Client Hosted, backups are your responsibility. Backup schedule and geography: ⚑ to confirm.
- Retention — standard SmartEPT Managed Cloud retention is configurable up to a maximum of three months.
- Data deletion — Managed Cloud data may be deleted according to employer policy, service termination and legal obligations. Trial data is scheduled for deletion within 14 days after trial expiry unless a paid service is activated.
- Licence-server communication — SmartEPT product servers phone home to the Ametecs licence API for validation and device activation only. This is licence metadata, not employee-activity content.
- Support access controls — Ametecs staff access to Managed Cloud tenant data is limited to what is required to provide support and is audit-logged.
- Customer responsibilities — defining lawful monitoring policies, informing employees, keeping licence keys confidential, and (on Client Hosted) securing and backing up your own server.