Smartsheet Technology
- Client Infrastructure
- The Smartsheet client side infrastructure and AJAX engine delivers a rich, easy-to-use experience in a secure on-demand application. It is accessible on a global basis and requires no software to be downloaded.
- Information Access
- Smartsheet employs a proprietary data access layer which ensures that client data is secure and is accessible to authorized users only. In addition, the Data Access Layer enforces your specific data privacy settings. By having critical security features incorporated into our platform, our features are delivered faster and in a consistently secure fashion.
- Application Server
- Smartsheet interfaces prescribe how each system request interacts with the overall system. These interfaces enforce each request to adhere to strict standards of authentication, access control, fault tolerance and scalability.
Scalability and Reliability
In order to promote the highest levels of scalability and reliability, our application is built on commercial grade, redundant open source tools.
All customer accounts are managed within a dedicated Smartsheet environment at Rackspace, a world-class SAS70 certified managed service provider and hosting facility. We also use Amazon's S3 service to store and serve uploaded files and published content.
Security
- Physical security
- Smartsheet is managed at Rackspace, a SAS 70 certified data center. They provide 24-hour physical security which is strictly monitored using keycard protocols, biometric scanning protocols and continuous surveillance. To ensure reliability, we have redundant web and application servers and dedicated hardware, including a Cisco firewall, load balancer and SSL Accelerator.
- Operating System
- Smartsheet protects all customers with strong system-generated passwords. Our password database is not shared and there are a minimal number of access points to all servers.
- Data encryption
- Smartsheet uses 128-bit Verisign SSL certification and 1024-bit RSA public keys to encrypt all data transmissions between your browser and our servers.
- User Authentication
- Users access Smartsheet only with a valid user name and password combination, which is encrypted via SSL while in transmission. For added security, the session key is automatically generated via a non-deterministic random method and is only stored in memory until you close your browser.