Answers to the questions teams ask most — getting set up, how AI governance and the EU AI Act are handled, how compliance scoring works across every framework you adopt, how scanning and evidence collection work, and how your data is handled.
Getting started
What to do first
After signing up, the onboarding wizard covers naming your organization, choosing the frameworks that apply to you (EU AI Act, ISO 42001, NIST AI RMF, SOC 2, HIPAA, and more), designating compliance owners, inviting team members, and connecting a first integration. The recommended order after that is: complete the dashboard onboarding checklist, adopt your frameworks, upload or connect existing policies, run a first compliance scan, then review findings and start remediation.
Roles and access
Team members are invited from Settings → Team Members → Invite, and each gets a role: Owner (full access), Admin (manage settings and users), Compliance Officer (manage compliance workflows), or Viewer (read-only). No technical expertise is required — the platform uses plain-language explanations and guided workflows, and an IT team can connect technical integrations for deeper automation if you have one.
How compliance scoring works
Each framework you adopt gets its own score: earned weight divided by total catalog weight, times 100. Every requirement in the catalog — EU AI Act obligations, ISO/IEC 42001 clauses, NIST AI RMF subcategories, SOC 2 criteria, HIPAA safeguards — is weighted by severity, with Critical counting 3×, High 2×, Medium 1×, and Low 0.5×, and earns its full weight once validated evidence is attached.
That weighting is deliberate: a flat percentage would let an organization look compliant while missing the controls that actually carry enforcement risk. It also means the fastest way to move the score is to close Critical gaps first.
Frequently asked questions
Which frameworks does Shieldra support?
Shieldra leads with AI governance — the EU AI Act (including Article 50 transparency), ISO/IEC 42001, the NIST AI Risk Management Framework, and US state AI laws — and supports SOC 2, HIPAA, HITRUST, and NIST CSF in the same workspace. Adopt the frameworks that apply to you in Settings; each gets its own requirement catalog, score, and roadmap, and you can add or remove them at any time.
How does Shieldra handle the EU AI Act?
A deterministic questionnaire classifies each AI system’s risk tier and produces the obligations that apply, each with its official citation and deadline. Article 50 transparency duties have been enforceable with penalties since 2 August 2026, and Shieldra continuously re-verifies your disclosure surfaces and flags drift.
How long does it take to get set up?
Most teams reach a baseline score within 2–4 weeks. The timeline depends on your starting point — if you already have some policies in place it can be faster. The roadmap breaks the work into prioritized stages per framework.
What counts as Protected Health Information (PHI)?
For HIPAA-adopted organizations: any individually identifiable health information held or transmitted by a covered entity — patient names, dates of birth, Social Security numbers, medical record numbers, diagnoses, treatment information, billing records, and any combination of data that could identify a patient.
How often do I need to do a risk assessment?
HIPAA requires periodic risk assessments without specifying an exact frequency. Industry best practice is annually, plus whenever there is a significant change — new systems, staff changes, security incidents, or new business relationships.
What HIPAA training do my employees need?
Every workforce member who handles PHI must be trained on what PHI is and how to protect it, your privacy and security policies, how to report incidents, and the consequences of violations. Training is required at hiring and periodically thereafter, and records must be documented.
Do I need a BAA with every vendor?
You need one with any vendor that creates, receives, maintains, or transmits PHI on your behalf — EHR providers, cloud hosting, billing companies, IT support, shredding companies, and email providers used for PHI.
What is the difference between Required and Addressable safeguards?
Required safeguards must be implemented with no exceptions. Addressable safeguards require you to assess whether the safeguard is reasonable and appropriate for your organization — if it is, you must implement it; if not, you must document why and what you did instead.
What happens if I am not 100% compliant?
OCR evaluates whether you made good-faith efforts to comply. A documented risk assessment, an active remediation plan, and evidence of ongoing improvement demonstrate good faith, which is why continuous documentation matters more than a perfect score at any single moment.
Can I use Shieldra without any integrations?
Yes. Integrations automate evidence collection but are not required. You can manually upload evidence, run document-based scans, manage your compliance program, and prepare for audits entirely within the platform.
Where is my data stored?
Application data lives on Railway (application hosting) and Neon (managed PostgreSQL), both US-based providers; uploaded document files are stored in Cloudflare R2 object storage. Data is encrypted at rest using AES-256.
How does Shieldra handle AI and my data?
AI features run through Shieldra-managed providers — currently Anthropic, OpenAI, and Google — under terms that exclude training their models on your data, with automated redaction applied where applicable. Prompts and responses are stored in your workspace for history and auditability and are deleted with your tenant data. Prefer your own provider terms? Add your own API key in Settings (bring your own key) and those calls run under your agreement with that provider. Your data is never used to train AI models.
Is Shieldra itself HIPAA compliant?
We have mapped our controls to HIPAA’s administrative, physical, and technical safeguards — self-attested, as our Trust Center states honestly. The standard Shieldra service is a No-PHI service: you must not upload PHI unless we expressly authorize that processing in writing, in which case a Business Associate Agreement governs it.
Can I get a refund?
Fees are non-refundable except where required by law, per our Terms of Service. Monthly plans can be cancelled at any time, and you retain access until the end of your billing period.
What happens to my data if I cancel?
After cancellation your workspace becomes read-only and you can export your data for 30 days. Your data is then retained until you request deletion — we delete or anonymize it within 90 days of your request, except for records we must keep, including certain compliance and incident records retained for up to six years, per our Terms of Service.
How do I report a security vulnerability?
Email security@shieldra.ai with the details. We take all reports seriously and respond promptly, and we ask that you not publicly disclose the vulnerability until it has been addressed. We acknowledge researchers who report responsibly.