Shieldoq
Security
How Shieldoq protects your compliance data, credentials, and connected systems.
Last updated May 22, 2025
Our commitment
Shieldoq is built for teams that handle sensitive security posture data. Security is not a checkbox on our roadmap—it is a constraint on every feature we ship.
Encryption
TLS 1.2+ in transit; encrypted storage at rest
Least privilege
Role-based access and scoped integration tokens
Tenant isolation
Logical separation per organization workspace
Audit logging
Administrative and security-relevant events logged
Platform architecture
- API and web application hosted on hardened cloud infrastructure with network segmentation
- Secrets and integration credentials encrypted with industry-standard algorithms; keys managed via secure vault patterns
- Background workers process scans in isolated job queues with retry limits and timeouts
- Production access restricted to authorized personnel on a need-to-know basis with MFA
Data protection
We collect the minimum data required to assess compliance posture: configuration metadata, policy findings, IAM settings, and evidence artifacts—not bulk source code archives unless a specific feature you enable requires temporary analysis.
- Customer data is not used to train shared AI models without opt-in
- Backups are encrypted and tested on a regular schedule
- Data deletion available on workspace termination per our Privacy Policy
Access controls
- Admin, Member, and Auditor roles with least-privilege defaults
- SSO and SCIM available on Enterprise plans
- Session management and optional IP allowlisting for sensitive deployments
- API keys scoped to read or write operations with rotation support
Third-party connections
Integrations use OAuth, app installations, or short-lived credentials—never stored in plain text. Cloud connections such as AWS use cross-account IAM roles (AssumeRole) so you control revocation from your side.
See documentation for required permissions per provider and how to scope them narrowly.
Incident response
We maintain an internal incident response plan with defined severity levels, on-call rotation, and customer notification procedures for confirmed breaches affecting your data.
Report a vulnerability: securityshieldoq.com. We acknowledge reports within two business days and coordinate disclosure responsibly.
Our compliance program
Shieldoq operates its own security program aligned with SOC 2 control objectives. We practice what we sell: continuous monitoring, documented policies, and evidence collection through the same engine our customers use.
SOC 2 Type II report and security questionnaire responses are available to customers on Growth and Enterprise plans via the trust center or your account team.