Security & trust
A security company should be able to explain its own controls.
This page describes how we operate the platform, what data we handle, and the boundaries we hold ourselves to.
Platform security
- Encryption in transit using modern TLS for all customer traffic
- Encryption at rest for customer data stored by the platform
- Least-privilege access controls for internal systems
- Separate environments for development, staging, and production
Data handling
- We collect only the data required to deliver the products you subscribe to
- Findings and reports are scoped to your organization
- Customer data is never sold or shared for advertising
- Data deletion is available on request when your account is closed
Scope and authorization
- Monitoring is limited to assets you own or are authorized to submit
- We prefer non-intrusive, agentless collection methods
- We do not perform exploitation or intrusive testing without a written agreement
- Unauthorized scope requests are rejected
Responsible disclosure
- Report suspected vulnerabilities in our services to support@shieldcoresecurityllc.com
- Include enough detail for us to reproduce the issue
- Do not access, modify, or exfiltrate data that is not yours
- We will acknowledge reports and keep you updated on remediation
Compliance certifications are not claimed on this page. If you need a specific attestation or security questionnaire completed, contact us and we will tell you exactly what we can provide today.