generated: '2026-08-02' method: searched probe: true url: https://trust.smithrx.com/ name: SmithRx Trust Center platform: Vanta platform_evidence: trust.smithrx.com is a CNAME to 63375548372ed4d85b680637.cname.vantatrust.com; the page is served by Vanta's trust-report application (assets.vanta.com/static/index-trust-report.*) description: 'Verbatim page description: "As a radically transparent PBM, our mission is to reduce cost and complexity for employers and their members. We take the security of your data seriously—applying rigorous compliance standards and best-in-class safeguards to protect sensitive information at every step. Learn more about our commitment to privacy, compliance, and operational integrity."' content_machine_readable: false content_note: The trust center is a client-side rendered single-page app backed by an authenticated Vanta API (api.vanta.com returns 401 Unauthorized anonymously). The certification list, audit reports and subprocessors are therefore NOT harvestable without JavaScript execution or a document request. Presence is verified; the specific framework list served by this page is not recorded here rather than guessed. secondary_page: url: https://smithrx.com/security name: SmithRx Security Protocols certifications: - name: SOC 2 claim: 'SOC2 Hosting — "Ensures compliance with industry standards"' scope: hosting evidence: https://smithrx.com/security attestation_available: request-via-trust-center note: Stated on the public security page as a property of hosting, not as a named SmithRx Type I/II report; no auditor is named on the public surface. - name: HIPAA claim: 'Privacy policy states collection and use of personal information "will be subject to the requirements of the Health Insurance Portability and Accountability Act (\"HIPAA\")" and that identifiable member health data is protected health information (PHI).' evidence: https://smithrx.com/privacy-policy evidence_date: '2026-07-10' accreditations: - name: URAC Pharmacy Benefit Management body: URAC accreditation_id: PBM010015 url: https://accreditnet.urac.org/directory/#/accreditation/PBM010015/info expires: '2029-02-01' evidence: https://smithrx.com/security controls_published: - control: AES-256 encryption for data at rest and in transit - control: Role-Based Access Control (RBAC), least privilege - control: Multi-Factor Authentication (MFA) - control: Single Sign-On (SSO) - control: Endpoint security with central management - control: Full disk encryption with remote wipe - control: Audit logging and anomaly detection - control: Security Awareness Training required before access is granted not_evidenced_on_public_surface: - ISO 27001 - ISO 27017 - ISO 27018 - HITRUST - PCI DSS - FedRAMP - CSA STAR - penetration test summary - subprocessor list evidence: - source: https://trust.smithrx.com/ http_status: 200 fetched: '2026-08-02' matched: - SmithRx Trust Center - rigorous compliance standards - commitment to privacy, compliance, and operational integrity - source: https://smithrx.com/security http_status: 200 fetched: '2026-08-02' keywords: - soc2 - encryption - rbac - mfa - audit logging - security vulnerability - source: https://smithrx.com/privacy-policy http_status: 200 fetched: '2026-08-02' keywords: - HIPAA - protected health information last_updated: '2026-07-10'