Security & trust
Built to be handed to a security team.
Shadowguard is a governance product, so we hold ourselves to the standard we help you reach. Here is exactly how your data is protected today — and, honestly, what we're still building.
Last reviewed 6 July 2026
In place today
How your data is protected
Encryption everywhere
Traffic is encrypted in transit with TLS and data at rest is encrypted by our infrastructure providers. Secrets live in the platform's encrypted environment — never in the client bundle, never in logs.
Authentication & MFA
Sign-in, sessions and multi-factor authentication are handled by Clerk, a SOC 2 Type II-certified identity provider. MFA can be required for owner and admin accounts.
Tenant isolation at the database
Every table enforces Postgres row-level security. A company's queries can only ever return that company's rows — cross-tenant access is blocked in the database, not just hidden in the UI.
Least data by design
The survey has no “who said what”, and directory discovery is aggregated to the app level. We collect what governance needs and deliberately nothing that would let us surveil a person.
AI data handling
Document drafting uses the Anthropic API, which does not train on your data. Prompts contain only the profile and inventory you enter. We log token counts and the model — never the content of a prompt.
Append-only audit trail
Security-relevant events — sign-ins, role changes, policy approvals, exports and survey-token creation — are written to an audit log scoped to your company.
Least-privilege access
The key that can bypass row-level security is server-only and never reaches the browser. Application code reads your data through the tenant-scoped client, nothing wider.
Managed, monitored infrastructure
Shadowguard runs on Supabase and Vercel — established providers with their own security programs, provider-managed backups and platform monitoring.
The line we won't cross
Discovery, never surveillance
Shadowguard is built on “amnesty, no blame.” Discovery exists to map the AI your company uses — never to police the people who use it.
Where we are, honestly
Security maturity, without the theatre
We're an early-stage company. We'd rather show you our real posture than imply certifications we don't hold yet.
01 · Today
In place now
- TLS in transit + encryption at rest
- Row-level security on every table
- Clerk authentication with optional enforced MFA
- Append-only audit logging
- Metadata-only AI logging
02 · Next
In progress
- Formal Data Processing Agreement (DPA) on request
- Subprocessor-change notifications
- EU data-residency option
- SOC 2 Type II readiness
03 · Later
On the roadmap
- SOC 2 Type II attestation
- Independent penetration testing on a regular cadence
- ISO 27001 alignment
Subprocessors
Who processes data on our behalf
The third parties Shadowguard relies on to run the service. Each is an established provider with its own security and compliance program.
- ClerkAuthentication, organizations and MFA
- SupabasePrimary database and file storage (Postgres + row-level security)
- VercelApplication hosting and content delivery
- InngestBackground job processing (survey ingestion, document generation)
- AnthropicAI document drafting — does not train on your data
- ResendTransactional email (invites, notifications)
Contact
Talk to us like a security team.
Running a vendor review? Need a DPA signed, or an architecture walkthrough? Reporting a vulnerability? We answer security questions the way we'd want ours answered.
We aim to acknowledge vulnerability reports within one business day.