Trust & Security Centre
Last updated:
A summary of how Smart One Holding Limited and the SmartOne group approach security, compliance and transparency, including for government programmes. It is for information only and is not itself a certificate, audit report, or contractual commitment.
Security principles
We apply security-by-design principles, including defence in depth, least privilege, and segregation of duties in production deployments. We use encryption in transit (TLS) and encryption at rest where applicable to the deployment, under the terms of the relevant contract, together with a security-aware development lifecycle, change control, and incident-response procedures.
Marketing site vs. product infrastructure
smartoneworld.com is a public marketing website hosted on shared infrastructure in the United States. Sovereign, air-gapped or on-premises deployments for government customers are delivered under separate statements of work and are not hosted on this marketing infrastructure. Where a deployment is contracted to keep operational data within a defined jurisdiction or environment, the data is designed to remain within that environment as set out in the applicable contract.
Sub-processors, data residency and reporting
Website processors are listed in our Privacy Policy; product sub-processors are listed in the applicable customer Data Processing Agreement. For where data is hosted, see our Data Residency & Sovereignty Statement. For ethics and anti-bribery, see our Code of Conduct & ABAC Policy. Report a vulnerability to security@smartoneworld.com.
Certifications and attestations
We publish only verified statuses. Our current certification position is set out below.
ISO/IEC 27001
Certificate no. 33926IS00014R053, issued 03-02-2026. The certified scope covers information security management for the production of mobile terminal devices (POS machines and tablet PCs). This certificate relates to the manufacture of terminal hardware; it does not, by itself, certify our GovTech software, platforms or managed services, for which separate certification is not currently held. The certificate is available on request.
SOC 2 Type II
Not currently held.
ISO/IEC 27017 & 27018
Not currently held.