# SmishAlert for Audit-grade record of social engineering reports

Audit-grade. Time-stamped. Classified. Correlated. The record your SOC didn’t have for the messaging-channel attack surface.

GRC and SecOps teams who need a defensible record of social engineering reaching the workforce, for SOC 2, HITRUST, FFIEC, or internal audit.

## FAQ

### What is a system of record for social engineering reports?

It’s a single, audit-grade, time-stamped, classified, and correlated record of every suspicious message your employees report in messaging channels. SmishAlert provides this record for the messaging-channel attack surface that email tools and SOC dashboards don’t cover.

### Is the record defensible for SOC 2, HITRUST, or FFIEC audits?

Yes. SmishAlert produces exportable evidence packs, configurable retention, and role-based access control aligned to your IAM so GRC teams can defend coverage in an audit or regulator review.

### Can data be kept in the EU?

EU data residency and configurable retention are available on Enterprise.

Full page: https://www.smishalert.ai/use-cases/system-of-record
