Trust Center

Your security, compliance, and data privacy requirements don't shrink as your business grows — they multiply. Smartsheet is built to meet them — with the governance controls, certifications, auditability, and reliability your organization requires.

85% of Fortune 500 companies trust Smartsheet

thermo_fisher_scientific_logo
Nasa JPL logo
Alaska Airlines Logo
Lego Logo
Dominos Logo

Smartsheet Compliance

Spend less time worrying about compliance and more time running your business. Smartsheet supports compliance with leading regulatory and industry standards. 

Enterprise Security FAQ

Smartsheet stores customer data on AWS infrastructure across dedicated regional environments. By default, customers are hosted in AWS East, with regional options available via Smartsheet Regions.

Based on the environment you’re using, here’s where your data resides:

  • Smartsheet Commercial environment: AWS East regions (Virginia/Ohio)
  • Smartsheet Gov environment: AWS GovCloud West region (Oregon)
  • Smartsheet EU environment: AWS EU regions (Germany/Ireland)
  • Smartsheet AU environment

Smartsheet's Business Continuity/Disaster Recovery implementation maintains current data through the use of three availability zones - essentially, data is backed up to separate AWS regions to ensure business continuity. The punchline? Smartsheet provides a 99.9% Availability SLA.

All data is encrypted in transit using TLS 1.2/1.3 encryption and at rest using AES-256 bit encryption. Smartsheet manages encryption keys by default using AWS issued certificates, enhanced by a private Certificate Authority (CA). 

Smartsheet also offers Customer Managed Encryption Keys (CMEK), as a premium capability for organizations that require direct control over their encryption keys. 

Smartsheet enforces least-privilege access by default. What each user can see and do is determined both by the permission level they're granted on a given item — Viewer, Commenter, Editor, Admin, or Owner — and by their role in the system. Account-level roles include System Admins (who manage users, account settings, and security controls), Group Admins, paid Members, and external Guests.


For authentication, Smartsheet supports SSO via Google, Microsoft, Apple, and SAML 2.0 — compatible with major identity providers including Okta, Microsoft Entra ID, and PingIdentity. Admins can enforce a single SSO method across the organization, or require a designated provider for specific email domains.


Smartsheet recommends enforcing MFA through your identity provider alongside SSO. For non-SSO users, we offer authenticator-app-based MFA, which Enterprise admins can require at the plan or domain level.

Smartsheet provides exportable logs covering user login history, sheet access, and asset-level activity, with  cell-level history available within each asset.  

Smartsheet also offers Event Reporting as an advanced capability, providing visibility into over 100 types of security and user activity events for a comprehensive audit trail across the platform.

Smartsheet adheres to leading security and compliance frameworks, including SOC 2, ISO 27001, ISO 27701, and FedRAMP. We are also actively pursuing ISO 42001 certification for AI management. Enterprise Plan customers in healthcare can use Smartsheet to receive, maintain, or transmit certain types of Protected Health Information (PHI) after executing a Business Associate Agreement (BAA) with Smartsheet. 

No. Smartsheet does not use customer data to train AI models. .

Our AI Security whitepaper states it clearly: Your data never mixes with other customers' data. We never allow a third party to train foundation models on your data. It never leaves your control. Every AI action or recommendation can be explained, audited, and traced back to its source. Data security and privacy are foundational to every area of the Smartsheet platform, including AI.