SMG logo SHEVCHENKO MOBILITY GROUPTrust Center
Security and accountability

SMG Trust Center

How SMG Platform V61 protects case integrity, separates public and private data, controls staff access and keeps high-impact decisions under human responsibility.

Platform controls

Trust by design

Controls apply across public intake, protected Document Automation, case administration and property operations.

Data separation

Private storage

Client records, credentials, passports, generated documents and company vault files are kept outside the public website and outside the source repository.

Access

Role and expiry controls

Protected operations require authenticated access. Temporary staff accounts can be role-limited, expired, disabled and password-reset by authorised management.

Sessions

Protected authentication

Production sessions use secure HttpOnly cookie controls, same-origin protections and a persistent Owner identity rather than browser-local credentials.

Evidence

Audit trail

Operational changes are attributed to users and recorded for review, including case, document, property, booking and access events.

Documents

Identity verification

Critical identity fields require verification before final document generation. Files remain restricted to authorised operational users.

Continuity

Backup and rollback

Production promotion requires a backup, a recorded release identity and a guarded rollback route instead of an untracked overwrite.

Live operational proof

Verify the platform against the production backend.

This read-only diagnostic checks live server responses. It does not create a lead, alter a case, expose private records or treat a failed request as a success.

Backend API

Not checked

Run the live check to verify the production backend.

CRM

Not checked

CRM capability is read from the live backend.

Documents

Not checked

Document Automation capability is read from the live backend.

Client Portal

Not checked

Client Portal capability is read from the live backend.

Jobs API

Not checked

The public catalogue is requested directly from the production API.

Property API

Not checked

The public property catalogue is requested directly from the production API.

Football

Not checked

Football Agency capability is read from the live backend.

CMS

Not checked

CMS capability is read from the live backend.

Media

Not checked

Media Library capability is read from the live backend.

Payments

Not checked

Module presence is verified separately from merchant activation and bank/provider approval.

Live check not yet run.

Human control

No automated legal or commercial decision

AI-assisted routing may organise a request, but it does not approve a visa, employment route, property booking, payment or legal outcome. Authorised staff review the case, and external authorities or providers retain their own decision-making powers.

Report a concern

Security and privacy contact

Report suspected impersonation, altered payment instructions, unauthorised access or privacy concerns to roman@shevchenko-group.com. Do not include passwords, full card data or unnecessary identity documents in the first message.