Trust
Shieldra Trust Center
Shieldra is a compliance product, so you should be able to check our own claims. Everything here links to the document or page that backs it.
Key takeaways
- Shieldra has not completed a third-party audit: SOC 2 Type II, ISO 27001 and HITRUST CSF are not yet audited.
- The standard service is a No-PHI service; PHI requires separate written authorization under a BAA.
- AI sub-processors (Anthropic, OpenAI, Google) are engaged under terms that exclude training on customer data.
- Language models help review documents and draft text; AI-law classification is a deterministic rules engine.
Compliance posture
Shieldra has not completed a third-party audit. When we engage an audit firm, we will name it and the observation-window dates here.
| Framework | Status |
|---|---|
| SOC 2 Type II | Not yet audited |
| ISO 27001 | Not yet audited |
| HITRUST CSF | Not yet audited |
| HIPAA | No-PHI service by default; BAA only by separate written agreement |
| GDPR | DPA available, with Standard Contractual Clauses |
Data handling
- Where data lives: the application, database and uploaded files run on the providers listed on the sub-processors page; we give at least 30 days’ notice before adding or replacing a sub-processor
- Protected health information: the standard service is a No-PHI service; do not upload PHI unless authorized in writing under a Business Associate Agreement
- AI sub-processors: Anthropic, OpenAI and Google are engaged under agreements or service terms that exclude using customer data to train their models
- Retention and deletion: set out in the Terms of Service and the Data Processing Addendum
How Shieldra uses AI
Language models are used for reviewing uploaded policies and documents against framework requirements, drafting remediation and incident-response text that your team reviews before use, and the in-app assistant.
Language models are not used to classify AI systems under the EU AI Act and the US AI-law packs. That is a deterministic rules engine: the same answers always give the same tier and obligations, with the rule trace saved.
Frequently asked questions
Is Shieldra certified against SOC 2 or ISO 27001?
No. Shieldra has not completed a third-party audit; SOC 2 Type II, ISO 27001 and HITRUST CSF are not yet audited. When an audit firm is engaged we will name it and the observation window on this page. The platform itself supports HIPAA, SOC 2, HITRUST, NIST CSF, ISO/IEC 42001 and the NIST AI RMF for customers.
How quickly does Shieldra notify customers of a breach?
Without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Data, per our Data Processing Addendum.
Does Shieldra use AI to classify my AI systems?
No. EU AI Act and US AI-law classification is a deterministic rules engine over versioned content packs. Language models are used for document review, drafting and the assistant.