Trust
Shieldra Trust Center
Our public commitment to security, privacy, compliance, and transparent data protection practices — where we honestly stand against the frameworks we work toward, and the controls we hold ourselves to.
By the Shieldra Compliance Team · Last updated July 2026
Key takeaways
- Customer data is encrypted with AES-256 at rest and TLS 1.3 in transit.
- RBAC and MFA are enforced across the platform, with SSO available on Enterprise.
- Continuous automated monitoring runs with alerting.
- A documented incident response plan commits to breach notification without undue delay and within 72 hours per our DPA.
Our compliance posture
Statuses are stated honestly: "Self-Attested" means we have mapped our controls to the framework without a third-party audit; "In Progress" means we are actively working toward external certification.
| Framework | Status | What it covers |
|---|
| HIPAA | Self-Attested | Health Insurance Portability and Accountability Act — healthcare data protection |
| HITRUST CSF | In Progress | Health Information Trust Alliance Common Security Framework — risk-based certification |
| SOC 2 Type II | In Progress | Service Organization Controls — security, availability, and confidentiality |
| NIST CSF | Self-Attested | National Institute of Standards and Technology Cybersecurity Framework |
| GDPR | Self-Attested | General Data Protection Regulation — EU data privacy law |
| ISO 27001 | In Progress | International standard for information security management systems |
Our security practices
- AES-256 encryption at rest and TLS 1.3 in transit for all data
- Role-based access control and multi-factor authentication enforced across the platform, with SSO available on Enterprise
- Continuous automated monitoring with alerting
- A documented incident response plan, with breach notification without undue delay and within 72 hours per our DPA
Transparency documents
Our data protection commitments are published rather than available on request. The Privacy Policy sets out what we collect and how it is used, the Data Processing Addendum covers GDPR, UK GDPR, and CCPA/CPRA processing terms, and the sub-processor list names every third party involved in delivering the service, with their location and role.
The standard platform is a No-PHI service. It is designed for compliance documentation, policies, risk assessments, and audit evidence rather than protected health information; PHI processing requires Shieldra’s express written authorization under a BAA.
Frequently asked questions
How does Shieldra protect customer data?
Data is encrypted with AES-256 at rest and TLS 1.3 in transit. Role-based access control and multi-factor authentication are enforced across the platform, with SSO available on Enterprise plans, and continuous automated monitoring runs with alerting.
Is Shieldra certified against SOC 2 or ISO 27001?
Not yet — and we say so plainly. SOC 2 Type II, HITRUST CSF, and ISO 27001 are In Progress; HIPAA, NIST CSF, and GDPR are Self-Attested, meaning we have mapped our controls to those frameworks without a third-party audit. The platform itself supports HIPAA, SOC 2, HITRUST, NIST CSF, ISO/IEC 42001, and NIST AI RMF for customers, plus EU AI Act and US state AI-law regulatory intelligence.
How quickly does Shieldra notify customers of a breach?
Without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Data, per our Data Processing Addendum.