top of page

Security & Data Handling Statement: SMP 365

Effective Date: 9 May 2026

This Security & Data Handling Statement applies to all SMP 365 software products, services, applications, and Microsoft Marketplace offerings provided by SMP 365 SAAS Pty Ltd.

Systems Covered

This statement governs the security protocols for our entire suite, including:

  • Operations: Permit to Work, LMS, Contractor Management, Travel Management.

  • Risk & Safety: ICAM + AI Assisted Investigations, Risk Management, Incident Management, EMS, Psychosocial Risk Management.

  • Analytics: Hazardous Goods Management, Action Management, Dashboards & Analytics, Safety Mobile Applications.

1. Microsoft-Native Security Architecture

SMP 365 is designed as a Microsoft-integrated business application. Our systems operate primarily within your existing customer-controlled Microsoft environments, including Microsoft 365, SharePoint Online, Microsoft Azure, and Microsoft Entra ID. This allows you to leverage your existing enterprise security investments and compliance controls.

2. Customer-Controlled Tenancy

You retain full control over your data environment. SMP 365 systems respect your internal policies regarding:

  • User permissions and authentication.

  • Data retention and Microsoft Purview settings.

  • Audit logging and tenant governance.

3. SharePoint-Native Architecture

By utilizing SharePoint and Microsoft 365 technologies, SMP 365 solutions inherit world-class platform capabilities, including role-based permissions, comprehensive audit histories, and Microsoft identity integration.

4. Customer Ownership of Data

You own your data. SMP 365 does not claim ownership over any operational records, investigations, permits, training records, or uploaded evidence stored within your Microsoft environment.

5. Configurable AI Services

Customers have the power to enable or disable AI-assisted functionality. When active, we utilize Azure AI Services (OpenAI, Speech, Document Intelligence) to provide insights, transcriptions, and summarizations within your environment.

6. AI-Assisted Output Disclaimer

AI-generated outputs are assistive tools only.

  • They may contain inaccuracies and require human verification.

  • They do not constitute legal advice or regulatory certification.

  • Final operational decisions remain the sole responsibility of the customer.

7. Microsoft Security Inheritance

Our architecture allows customers to apply enterprise-grade tools directly to their SMP 365 data, including:

  • Microsoft Entra ID & MFA

  • Conditional Access & Microsoft Defender

  • Microsoft Purview & Sentinel

8. Security Controls

SMP 365 employs commercially reasonable security practices, including:

  • Encrypted HTTPS communications.

  • Role-based access controls (RBAC).

  • Secure API authentication and Azure infrastructure.

9. Data Processing & Hosting

Data is processed within your Microsoft 365 environment or customer-selected Microsoft Azure regions. This ensures you maintain control over data residency and jurisdictional compliance.

10. Third-Party Services

SMP 365 integrates seamlessly with Microsoft 365, SharePoint Online, Microsoft Graph, Azure AI Services, and the Microsoft Power Platform.

11. Security Incident Reporting

Security is a shared responsibility. Please promptly report any suspected unauthorized access or platform misuse to our team:

12. Regulatory Considerations

While our systems support ISO-aligned frameworks, customers are responsible for ensuring their own compliance with local workplace safety legislation, privacy laws, and operational regulations.

13. Changes to This Statement

SMP 365 may update this statement periodically to reflect new platform enhancements or changes in the Microsoft ecosystem.

14. Contact Information

SMP 365 SAAS Pty Ltd Global Microsoft-Integrated Safety & Risk Software Provider

Address: Level 2, 1 Prowse Street West Perth WA 6005 Australia

Email: support@smp365.com Web: www.smp365.com

bottom of page