Trust

Security at Shieldra

What Shieldra does today to protect customer data, and what it has not done yet. Questions go to security@shieldra.ai.

Key takeaways

  • Customer records are scoped to their workspace in application queries; a CI lint fails the build on unscoped queries.
  • HTTPS everywhere with HSTS preload on www.shieldra.ai; integration credentials are additionally encrypted at the application layer.
  • MFA for every user, with an MFA-required policy on new workspaces; SAML SSO on Enterprise.
  • Audit-log entries are hash-chained with SHA-256.
  • Shieldra has not completed a third-party audit yet.

Tenant isolation

Customer records are scoped to their workspace in application queries. A lint in CI fails the build when a new query on tenant data is not scoped, and regression tests seed two workspaces and check that one cannot read or change the other’s data.

Encryption

All traffic is served over HTTPS, with HSTS (including preload) on www.shieldra.ai. Stored data is encrypted at rest by our database and object-storage providers, listed on the sub-processors page. Integration credentials and API keys are additionally encrypted at the application layer.

Access control

Role-based access control inside each workspace. MFA is available to every user (authenticator app, email codes and backup codes). New workspaces start with an MFA-required policy, which workspace admins can adjust. SAML SSO is available on Enterprise.

Audit log

Security-relevant actions are written to an audit log. Each entry stores the SHA-256 hash of the previous one, so an edited or removed entry breaks the chain, and admins can run an integrity check from the app.

Incidents

Automated probes check the production site, API and database on a schedule. If a personal-data breach affects you, we notify you without undue delay and within 72 hours, as our Data Processing Addendum commits.

Vulnerability reports

We accept responsible disclosure at security@shieldra.ai and publish a security.txt file.

Compliance posture

Shieldra has not completed a third-party audit. When we engage an audit firm, we will name it and the observation-window dates here.

FrameworkStatus
SOC 2 Type IINot yet audited
ISO 27001Not yet audited
HITRUST CSFNot yet audited
HIPAANo-PHI service by default; BAA only by separate written agreement
GDPRDPA available, with Standard Contractual Clauses

Frequently asked questions

How is customer data kept separate between customers?

Customer records are scoped to their workspace in application queries. A CI lint fails the build on new unscoped queries, and two-tenant regression tests check that one workspace cannot read or change another’s data.

Does Shieldra support SSO and MFA?

MFA is available to every user, and new workspaces start with an MFA-required policy that admins can adjust. SAML SSO is available on Enterprise plans.

How do I report a security vulnerability?

Email security@shieldra.ai with steps to reproduce. Please do not test against other customers’ data.

Is Shieldra SOC 2 certified?

No. Shieldra has not completed a third-party audit; SOC 2 Type II, ISO 27001 and HITRUST CSF are not yet audited.