SmithRx · Trust Center

Smithrx Trust Center

Trust center

Verbatim page description: "As a radically transparent PBM, our mission is to reduce cost and complexity for employers and their members. We take the security of your data seriously—applying rigorous compliance standards and best-in-class safeguards to protect sensitive information at every step. Learn more about our commitment to privacy, compliance, and operational integrity."

SmithRx maintains a public trust center documenting SOC 2 and HIPAA compliance.

CompanyHealthcarePharmacyPharmacy Benefit ManagementPrescription DrugsEmployee BenefitsClaimsInsuranceHealth Technology
Trust center: https://trust.smithrx.com/

Certifications & Compliance

SOC 2HIPAA

Source

Trust Center

smithrx-trust-center.yml Raw ↑
generated: '2026-08-02'
method: searched
probe: true
url: https://trust.smithrx.com/
name: SmithRx Trust Center
platform: Vanta
platform_evidence: trust.smithrx.com is a CNAME to 63375548372ed4d85b680637.cname.vantatrust.com;
  the page is served by Vanta's trust-report application (assets.vanta.com/static/index-trust-report.*)
description: 'Verbatim page description: "As a radically transparent PBM, our mission
  is to reduce cost and complexity for employers and their members. We take the security
  of your data seriously—applying rigorous compliance standards and best-in-class safeguards
  to protect sensitive information at every step. Learn more about our commitment to
  privacy, compliance, and operational integrity."'
content_machine_readable: false
content_note: The trust center is a client-side rendered single-page app backed by
  an authenticated Vanta API (api.vanta.com returns 401 Unauthorized anonymously).
  The certification list, audit reports and subprocessors are therefore NOT harvestable
  without JavaScript execution or a document request. Presence is verified; the
  specific framework list served by this page is not recorded here rather than guessed.
secondary_page:
  url: https://smithrx.com/security
  name: SmithRx Security Protocols
certifications:
- name: SOC 2
  claim: 'SOC2 Hosting — "Ensures compliance with industry standards"'
  scope: hosting
  evidence: https://smithrx.com/security
  attestation_available: request-via-trust-center
  note: Stated on the public security page as a property of hosting, not as a named
    SmithRx Type I/II report; no auditor is named on the public surface.
- name: HIPAA
  claim: 'Privacy policy states collection and use of personal information "will be
    subject to the requirements of the Health Insurance Portability and Accountability
    Act (\"HIPAA\")" and that identifiable member health data is protected health
    information (PHI).'
  evidence: https://smithrx.com/privacy-policy
  evidence_date: '2026-07-10'
accreditations:
- name: URAC Pharmacy Benefit Management
  body: URAC
  accreditation_id: PBM010015
  url: https://accreditnet.urac.org/directory/#/accreditation/PBM010015/info
  expires: '2029-02-01'
  evidence: https://smithrx.com/security
controls_published:
- control: AES-256 encryption for data at rest and in transit
- control: Role-Based Access Control (RBAC), least privilege
- control: Multi-Factor Authentication (MFA)
- control: Single Sign-On (SSO)
- control: Endpoint security with central management
- control: Full disk encryption with remote wipe
- control: Audit logging and anomaly detection
- control: Security Awareness Training required before access is granted
not_evidenced_on_public_surface:
- ISO 27001
- ISO 27017
- ISO 27018
- HITRUST
- PCI DSS
- FedRAMP
- CSA STAR
- penetration test summary
- subprocessor list
evidence:
- source: https://trust.smithrx.com/
  http_status: 200
  fetched: '2026-08-02'
  matched:
  - SmithRx Trust Center
  - rigorous compliance standards
  - commitment to privacy, compliance, and operational integrity
- source: https://smithrx.com/security
  http_status: 200
  fetched: '2026-08-02'
  keywords:
  - soc2
  - encryption
  - rbac
  - mfa
  - audit logging
  - security vulnerability
- source: https://smithrx.com/privacy-policy
  http_status: 200
  fetched: '2026-08-02'
  keywords:
  - HIPAA
  - protected health information
  last_updated: '2026-07-10'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/smithrx-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.