← Back to home

Security & trust

Built to be handed to a security team.

Shadowguard is a governance product, so we hold ourselves to the standard we help you reach. Here is exactly how your data is protected today — and, honestly, what we're still building.

Last reviewed 6 July 2026

In place today

How your data is protected

Encryption everywhere

Traffic is encrypted in transit with TLS and data at rest is encrypted by our infrastructure providers. Secrets live in the platform's encrypted environment — never in the client bundle, never in logs.

Authentication & MFA

Sign-in, sessions and multi-factor authentication are handled by Clerk, a SOC 2 Type II-certified identity provider. MFA can be required for owner and admin accounts.

Tenant isolation at the database

Every table enforces Postgres row-level security. A company's queries can only ever return that company's rows — cross-tenant access is blocked in the database, not just hidden in the UI.

Least data by design

The survey has no “who said what”, and directory discovery is aggregated to the app level. We collect what governance needs and deliberately nothing that would let us surveil a person.

AI data handling

Document drafting uses the Anthropic API, which does not train on your data. Prompts contain only the profile and inventory you enter. We log token counts and the model — never the content of a prompt.

Append-only audit trail

Security-relevant events — sign-ins, role changes, policy approvals, exports and survey-token creation — are written to an audit log scoped to your company.

Least-privilege access

The key that can bypass row-level security is server-only and never reaches the browser. Application code reads your data through the tenant-scoped client, nothing wider.

Managed, monitored infrastructure

Shadowguard runs on Supabase and Vercel — established providers with their own security programs, provider-managed backups and platform monitoring.

The line we won't cross

Discovery, never surveillance

Shadowguard is built on “amnesty, no blame.” Discovery exists to map the AI your company uses — never to police the people who use it.

The AI Amnesty Survey stores responses by tool, never by respondent.
OAuth directory discovery is read-only and admin-consented, and we store only that an app is in use — never which employee authorized it.
We will never ship browser-extension tracking, network monitoring or DLP. Those betray the promise, and we've ruled them out permanently.

Where we are, honestly

Security maturity, without the theatre

We're an early-stage company. We'd rather show you our real posture than imply certifications we don't hold yet.

01 · Today

In place now

  • TLS in transit + encryption at rest
  • Row-level security on every table
  • Clerk authentication with optional enforced MFA
  • Append-only audit logging
  • Metadata-only AI logging

02 · Next

In progress

  • Formal Data Processing Agreement (DPA) on request
  • Subprocessor-change notifications
  • EU data-residency option
  • SOC 2 Type II readiness

03 · Later

On the roadmap

  • SOC 2 Type II attestation
  • Independent penetration testing on a regular cadence
  • ISO 27001 alignment

Subprocessors

Who processes data on our behalf

The third parties Shadowguard relies on to run the service. Each is an established provider with its own security and compliance program.

  • ClerkAuthentication, organizations and MFA
  • SupabasePrimary database and file storage (Postgres + row-level security)
  • VercelApplication hosting and content delivery
  • InngestBackground job processing (survey ingestion, document generation)
  • AnthropicAI document drafting — does not train on your data
  • ResendTransactional email (invites, notifications)

Contact

Talk to us like a security team.

Running a vendor review? Need a DPA signed, or an architecture walkthrough? Reporting a vulnerability? We answer security questions the way we'd want ours answered.

We aim to acknowledge vulnerability reports within one business day.