Shieldoq

Security

How Shieldoq protects your compliance data, credentials, and connected systems.

Last updated May 22, 2025

Our commitment

Shieldoq is built for teams that handle sensitive security posture data. Security is not a checkbox on our roadmap—it is a constraint on every feature we ship.

Encryption

TLS 1.2+ in transit; encrypted storage at rest

Least privilege

Role-based access and scoped integration tokens

Tenant isolation

Logical separation per organization workspace

Audit logging

Administrative and security-relevant events logged

Platform architecture

  • API and web application hosted on hardened cloud infrastructure with network segmentation
  • Secrets and integration credentials encrypted with industry-standard algorithms; keys managed via secure vault patterns
  • Background workers process scans in isolated job queues with retry limits and timeouts
  • Production access restricted to authorized personnel on a need-to-know basis with MFA

Data protection

We collect the minimum data required to assess compliance posture: configuration metadata, policy findings, IAM settings, and evidence artifacts—not bulk source code archives unless a specific feature you enable requires temporary analysis.

  • Customer data is not used to train shared AI models without opt-in
  • Backups are encrypted and tested on a regular schedule
  • Data deletion available on workspace termination per our Privacy Policy

Access controls

  • Admin, Member, and Auditor roles with least-privilege defaults
  • SSO and SCIM available on Enterprise plans
  • Session management and optional IP allowlisting for sensitive deployments
  • API keys scoped to read or write operations with rotation support

Third-party connections

Integrations use OAuth, app installations, or short-lived credentials—never stored in plain text. Cloud connections such as AWS use cross-account IAM roles (AssumeRole) so you control revocation from your side.

See documentation for required permissions per provider and how to scope them narrowly.

Incident response

We maintain an internal incident response plan with defined severity levels, on-call rotation, and customer notification procedures for confirmed breaches affecting your data.

Report a vulnerability: securityshieldoq.com. We acknowledge reports within two business days and coordinate disclosure responsibly.

Our compliance program

Shieldoq operates its own security program aligned with SOC 2 control objectives. We practice what we sell: continuous monitoring, documented policies, and evidence collection through the same engine our customers use.

SOC 2 Type II report and security questionnaire responses are available to customers on Growth and Enterprise plans via the trust center or your account team.