Information Security Policy
Last Update: June 25, 2026
1.Purpose
At Smart Tech Insurance, protecting customer information, student data, business records, and technology assets is fundamental to our business. As a trusted provider of technology products and services to consumers, educational institutions, businesses, and government organizations, we recognize the importance of maintaining a strong information security program that safeguards the confidentiality, integrity, and availability of information.
This Information Security Policy establishes the principles, administrative safeguards, technical controls, and operational practices that guide Smart Tech Insurance’s approach to information security. Our goal is to reduce cybersecurity risk, support regulatory and contractual compliance, and maintain the trust of our customers through responsible information management.
This policy should be read in conjunction with Smart Tech Insurance’s Privacy Policy, Student Data Privacy Statement, Cookie Policy, Terms of Use, and other applicable company policies.
2.Information Security Highlights
Smart Tech Insurance is committed to protecting customer, student, employee, and business information through a combination of administrative, technical, and physical safeguards. While no security program can eliminate every risk, we continuously evaluate and improve our security practices to help protect the confidentiality, integrity, and availability of the information entrusted to us.
Our information security program includes, where applicable:
Administrative Safeguards
- Employee background checks
- Confidentiality agreements
- Role-based access controls
- Defined onboarding and offboarding procedures
- Security awareness and training
- Vendor management practices
- Written information security policies
Technical Safeguards
- Google Workspace for secure business communications
- Microsoft Defender endpoint protection
- Multi-Factor Authentication (MFA) for applicable accounts
- Secure authentication controls
- Anti-malware protection
- Operating system security updates
- Network firewall protection
- Secure cloud collaboration
- User activity logging where appropriate
- Video-monitored repair and operational areas
- Controlled facility access
- Secure storage of customer equipment
- Restricted access to repair workspaces
- Inventory and asset tracking procedures
- Secure shipping and receiving processes
- Ticket-based repair tracking
- Unique repair identification numbers
- Serial number verification
- Chain-of-custody procedures
- Quality assurance inspections
- Authorized technician access only
- Secure return shipping procedures
- Data minimization practices
- Secure data sanitization using BitRaser when requested or contractually required
- Secure disposal of storage media
- Confidential handling of customer devices
- Privacy-focused repair procedures
Smart Tech Insurance maintains administrative safeguards designed to promote responsible handling of information throughout the organization.
Administrative safeguards include:
- Written security policies and procedures
- Employee confidentiality agreements
- Non-compete and non-solicitation agreements where applicable
- Background checks for employees in accordance with applicable law
- Role-based access authorization
- Employee onboarding and offboarding procedures
- Vendor management practices
- Incident reporting procedures
- Security awareness initiatives
- Periodic policy review
Access to customer information is granted only to employees whose responsibilities require such access.
5.Technical Security Controls
Smart Tech Insurance employs commercially reasonable technical safeguards designed to protect customer information and company systems.
Current security measures include:
- Google Workspace for business communications
- Microsoft Defender endpoint protection
- Multi-Factor Authentication (MFA) for applicable user accounts
- Secure authentication controls
- Anti-malware protection
- Operating system security updates
- Network firewall protection
- Email security controls
- Secure cloud collaboration
- User activity logging where appropriate
As Smart Tech Insurance’s technology environment evolves, additional security controls may be implemented to address changing business and cybersecurity requirements.
6.Physical Security
Smart Tech Insurance maintains physical safeguards designed to protect company facilities, customer equipment, inventory, and confidential information.
Physical safeguards include:
- Controlled facility access
- Video surveillance of designated operational areas
- Restricted access to repair facilities
- Secure storage of customer devices
- Inventory tracking procedures
- Visitor management practices
- Secure shipping and receiving areas
Access to restricted areas is limited to authorized personnel.
7.Identity and Access Management
Smart Tech Insurance limits access to systems and information based on legitimate business need.
Security measures include:
- Unique user accounts
- Role-based permissions
- Password authentication
- Multi-Factor Authentication (where applicable)
- Periodic access reviews
- Prompt removal of access following employee separation or role changes
Employees may not share login credentials or permit unauthorized individuals to access company systems.
8.Endpoint Security
Company systems are protected through layered endpoint security designed to reduce the risk of malware, ransomware, unauthorized software, and other cybersecurity threats.
Current protections include:
- Microsoft Defender
- Anti-malware technologies
- Security updates
- Secure configuration management
- Device authentication controls
Employees are prohibited from disabling security software without authorization.
9.Secure Repair Operations
Customer trust is fundamental to Smart Tech Insurance’s repair operations.
Devices submitted for repair are handled using procedures designed to protect customer property and confidential information throughout the repair process.
Repair procedures include:
- Unique repair ticket assignment
- Serial number verification
- Controlled repair work areas
- Authorized technician access only
- Repair documentation
- Quality assurance inspection
- Shipment verification
Unless necessary to diagnose a reported issue or specifically authorized by the customer, Smart Tech Insurance personnel do not intentionally access customer files, documents, photographs, or other personal information stored on submitted devices.
Customers are encouraged to back up important data before submitting devices for service.
10.Chain of Custody
Smart Tech Insurance maintains documented procedures to track customer devices throughout the repair and asset management lifecycle.
Chain-of-custody practices include:
- Device intake documentation
- Serial number verification
- Repair ticket creation
- Technician assignment
- Status tracking
- Final inspection
- Shipment verification
- Delivery confirmation where available
These procedures help reduce the risk of lost or improperly handled equipment.
11.Data Sanitization
When requested by customers or required by contract, Smart Tech Insurance performs secure data sanitization using proprietary software.
Depending on customer requirements, sanitization services may include:
- Secure data erasure
- SSD sanitization
- Hard drive overwrite
- Verification reporting
- Erasure certificates
- Physical destruction of storage media where required
Sanitization methods may vary based on storage media, customer requirements, contractual obligations, and technical feasibility.
12.Vendor Security
Smart Tech Insurance works with reputable third-party providers that support our operations, including cloud services, payment processors, shipping carriers, manufacturers, and software vendors.
Where appropriate, vendors are evaluated based on:
- Business reputation
- Operational reliability
- Security practices
- Privacy protections
- Contractual obligations
Third-party providers receive only the information reasonably necessary to perform authorized services.
13.Security Awareness
Employees play a critical role in protecting customer information.
Smart Tech Insurance promotes security awareness by requiring employees to:
- Protect confidential information
- Follow company security policies
- Report suspected security incidents
- Protect login credentials
- Exercise caution with email and online communications
- Handle customer information responsibly
Smart Tech Insurance maintains procedures designed to identify, investigate, contain, and recover from suspected information security incidents.
Incident response activities may include:
- Incident identification
- Initial assessment
- Containment
- Investigation
- Recovery
- Documentation
- Corrective actions
Where required by law or contract, Smart Tech Insurance will provide appropriate notification of qualifying security incidents.
15.Business Continuity
Smart Tech Insurance maintains business continuity practices intended to minimize operational disruption and support continued customer service during unexpected events.
Business continuity planning may include:
- Operational contingency planning
- Cloud collaboration tools
- Recovery planning
- Vendor coordination
- Critical business process identification
Information is retained only as long as necessary to fulfill business, contractual, or legal requirements.
When information is no longer required, Smart Tech securely deletes, destroys, or sanitizes information using appropriate methods based on the sensitivity of the information.
Storage media processed through ITAD services may be securely erased using proprietary software or physically destroyed where required.
17.Compliance
Smart Tech Insurance’s information security program is designed to support applicable legal, contractual, and operational requirements, including those relevant to educational institutions and commercial customers.
Nothing in this policy represents certification under any specific security framework unless expressly stated by Smart Tech Insurance.
18.Continuous Improvement
Information security is an ongoing process.
Smart Tech Insurance regularly evaluates its administrative, technical, and physical safeguards to address evolving cybersecurity threats, changes in technology, business operations, and customer expectations.
As our organization grows, we remain committed to strengthening our security posture and adopting additional safeguards where appropriate.
19.Contact Information
Questions regarding this Information Security Policy may be directed to:
Smart Tech
Website: https://www.smarttechins.com
Security & Compliance: info@smarttechins.com
Privacy: info@smarttechins.com
Telephone: (877) 307-6777
Mailing Address:
Smart Tech
255 Primera Blvd Ste 160
Lake Mary, FL 32746