Brand protection & fraud notice
Criminals copy the SMERT logo into fake "contracts" and "invoices" and send them from unrelated domains. This page tells you, in one minute, how to separate a genuine SMERT document, email or web address from a forgery β and what to do with the forgery.
app.smert.ai. It was a third-party sales tool, not a SMERT system. The address was removed in September 2026 and no longer resolves. If your browser still reaches it from a cached record, do not enter an email address or password β and tell us at security@smertai.com.Rule one: we never send QR codes
SMERT never asks you to scan a QR code to review a contract, sign a document, make a payment, or log in. Any email showing our logo next to a QR code is fraudulent, no matter how convincing the wording or the reference number looks.
How genuine SMERT documents work
- Every invoice, contract, purchase order and proposal we issue carries a verification code in its footer, in the form
SMERT-VER-XXXX-XXXX, together with the SHA-256 fingerprint of the authentic file. - You can check that code at any time at smert.ai/verify. If it does not verify, it did not come from us.
- Electronic signature always happens on a page hosted at https://smert.ai/sign/β¦ β never through an attachment, a QR code, or a third-party portal you were not told about in advance.
- Payment is made only to the bank details printed on a verified invoice. We never change bank details by email. If you receive a "change of bank details" notice, call us before paying anything.
- SMERT never asks you to sign in, reset a password, or confirm credentials from a link in an unsolicited email. We will never send you a password reset you did not request yourself from an official address listed below.
Our real sending domains
Legitimate SMERT email comes only from these domains:
- smert.ai
- smertai.com
- smertrobotics.com
- smertvending.com
- smertconsulting.com
Commonly used addresses:
- hello@smertai.com
- stefano@smertai.com
- alex@smertrobotics.com
- alex@smertvending.com
- alex@smertconsulting.com
- alex.smert@getsmert.com
Anything else β including lookalike domains with extra words, hyphens or different endings β is not us. Check the true sender address, not the display name: forgeries often show "SMERT" as the name while the address belongs to an unrelated company.
Official web addresses
These are the only web addresses SMERT operates. If you were sent a link to anything else that carries our name or logo, treat it as fraudulent and report it.
- smert.aiMain site, document verification and e-signature
- www.smert.aiMain site
- smertai.comCorporate domain
- smertrobotics.comRobotics division
Known addresses that are not ours
- app.smert.aiDecommissioned. This was a third-party sales tool used briefly under our name; the address was removed in September 2026 and no longer resolves. Any page you still reach there is stale or spoofed β do not enter an email address or password.
A valid HTTPS padlock proves only that the connection is encrypted. It does not prove the site belongs to SMERT. Check the address against the list above before entering anything.
Warning signs we have seen
- A PDF or email titled "Smert Contract" with a reference ID and a large QR code to "review the draft contract".
- Our logo pasted at the top and bottom of a document that has no verification code.
- A confidentiality notice used to discourage you from checking with anyone else.
- An urgent deadline, an "effective date" already in force, or a request to acknowledge immediately.
- A sender domain unrelated to SMERT, with our name only in the display field.
- A sign-in or "forgot password" page carrying the SMERT name on a web address that is not listed above β even if the padlock shows and the certificate is valid.
Report a suspected forgery
Forward the full message, with headers and attachments, to security@smertai.com. Do not scan the QR code, do not open links, and do not pay. We investigate every report and warn affected vendors and clients.