Trust centre
What we do with your data, in plain terms
Secure Shield Labs is early. This page says exactly what is in place today, what is in progress and what is still a plan — because you are going to check.
Status — updated August 2026
Certifications and assurance
- Not yetSOC 2 Type IIIn progress — target Q2 2027
- Not yetISO 27001Planned — after SOC 2
- Not yetISO 42001Planned — 2027
- Not yetPenetration testScheduled before general availability
- In placeData processing agreementAvailable on request today
- In placeSub-processor listPublished and versioned today
Nothing above is claimed before it is true. If a row says planned, there is no certificate behind it yet — ask and we will tell you where it actually stands.
Data handling
Six answers you are going to ask for anyway
What we read
Read-only metadata: identities, entitlements, model and agent configuration, control state. We do not read the contents of your datasets, prompts or model outputs.
Where it lives
Single-region hosting, EU or US, chosen at contract. Data is never replicated across regions. Backups stay in the same region.
How long we keep it
Evidence is retained for the period your framework requires, configurable per control. Deleted within 30 days of contract end, with a certificate on request.
Training
Your data is never used to train models — ours or anyone else’s. There is no exception for aggregated or anonymised data.
Encryption
TLS 1.3 in transit, AES-256 at rest, customer-managed keys available for enterprise contracts.
Sub-processors
A short list, published with the purpose and region of each, versioned so you can diff it. Thirty days notice before any addition.
Practices in place today
How we run our own estate
- SSO and MFA enforced on every internal system
- Least-privilege access, reviewed monthly
- All infrastructure defined as code and peer-reviewed
- Dependency and container scanning on every build
- Centralised audit logging with 12-month retention
- Documented incident response with a named owner
- Background checks on everyone with production access
- Annual third-party penetration test from general availability
Reporting a vulnerability
Disclosure policy
Write to the address below with steps to reproduce. You will get a human reply within one working day and a fix timeline within five.
security@secureshieldlab.comWe will not pursue legal action against good-faith research that respects customer data and stays within the scope above.