Smartbox helps you review large sets of documents for data-protection and compliance work. You organise documents into Boxes, let Smartbox automatically flag sensitive information, cut down the volume you need to read, redact what needs hiding, and run compliance Workflows such as data subject access requests. It is a powerful assistant — but one that still needs a human to review its results before anything is deleted or disclosed.
This page is a quick tour of the main areas. Each section points you to the detailed article where you can go deeper.
Boxes
A Box is a top-level workspace that holds your documents and folders — the starting point for almost everything you do. You can create one with a Default configuration, which uses all of your organisation's term and pattern lists, or with Advanced settings, where you choose which categories and lists apply, set sharing and download permissions, and cap the number of pages per box. A new box starts empty; counts and analytics appear once you have uploaded documents and they have finished processing. Box names must be unique.
See Working with Boxes and Uploading documents for the full picture.
Detecting sensitive data
Once documents are processed, Smartbox automatically scans the extracted text for sensitive information and groups what it finds — for example Addresses, Names, Identifiers, Locations, Numbers, Organisations and Time. It combines a language engine, pattern matching for shaped types such as phone numbers, emails, postcodes and card numbers, and image face-detection (which spots the presence of a face, not who it is). Detection is a strong assist rather than a guarantee: it is only as good as the text that could be extracted, works best in English, catches names conservatively, and can occasionally miss or mis-match items — so human review still matters. Because a document always proceeds even if one check could not finish, a partial result can look clean. You can also add your own dictionary terms and pattern rules.
See Detecting sensitive data for how each technique works and its limits.
Reducing volume (culling)
Culling helps you shrink a large box down to the documents that actually need attention. Smartbox can group exact duplicates, group near-duplicates, set aside shorter emails that are fully quoted inside longer ones (email threading), and clear out clutter and empty folders. Culling always produces a report to review before anything is deleted — so you stay in control of what goes.
See Reducing volume with culling for how each type of match is made and what can break it.
Redaction
Redaction lets you hide sensitive content before disclosure. You mark items — drawing over them manually, or bulk-redacting whole detected categories — then finalise. Finalising flattens each redacted page to an image with the box baked in, so the hidden text is genuinely removed, while your original file is preserved separately. It is irreversible, so review carefully first. Because bulk redaction only covers items that were detected, a human check is still essential, and you should always verify the exported PDF by trying to select or search the hidden text.
See Redacting documents for the full workflow, colour and exemption codes, and the important verification step.
Workflows
Workflows are reusable templates for handling repeatable processes such as data subject access requests. A template combines a form, email templates and an ordered set of steps, and each run becomes a ticket that moves from Open to Complete to Archive. Workflows are strictly linear — there is no branching or automation — which keeps each case predictable and auditable. A dashboard lets you track and filter tickets by owner, workflow and time.
See Running Workflows for step types, tickets and the dashboard.
Connectors and data sources
You can import documents directly from Microsoft 365 — SharePoint, OneDrive and Exchange. Import is one-time and read-only: you pick a site and folder, and Smartbox brings in a copy. It is not a live sync, so you re-run the import to refresh. Alongside connectors, you can maintain a Source Mapping data register and record Business Processes that describe your processing activities.
See Connectors and data sources for setup and refresh.
Users and account
Administrators invite users and control access with role-based permissions — administrator, standard, and specialist roles. Everyone secures their sign-in with an authenticator app: you enrol by scanning a QR code and sign in with a one-time code, and an administrator can reset it if a device is lost. You can also manage company settings and branding here.
See Managing users and your account for roles, invitations and sign-in security.
The API
Smartbox offers an external API with scoped access tokens, so you can connect it to your own systems. Each token is limited to specific permissions, and tokens are issued per account. Treat them like passwords.
See Using the API for tokens and scopes.
Security
Access is role-based and enforced by the server, and each account is isolated — another account's records simply return "not found". Sign-in is protected by authenticator-app MFA, and audit trails record who did what and when across many actions.
For formal assurances beyond what is described in the product, please contact Customer Success.
See Security overview for how access and isolation work.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article