Trust, plainly stated.
The controls that exist today, the standards we align to, and the ones we are still preparing for. No certification claim we do not hold.
Row-level security on every table. Cross-tenant reads go through security-definer functions, never loosened policies.
AI provider keys live in a sealed table with no client policies. The client sees a label and last four characters, nothing else.
TLS for every request. Data at rest is encrypted by the managed backend.
Every AI call is server-side and logged. Organizations can plug their own providers, including on-prem or local endpoints.
- METPrivacy notice and lawful basisPrivacy policy published at /legal/privacy.
- METData Processing AgreementDPA available at /legal/dpa.
- METSubprocessors disclosedSubprocessors list at /legal/subprocessors.
- METData subject exportOne-tap GDPR data export in the app.
- METRight to erasureAccount and data deletion supported.
- METTenant isolation and data minimizationRow-level security on every table, owner or team-member scope only.
- PARTIALDocumented breach responseProcess being formalized.
- METRisk classificationLimited-risk system. Not a high-risk use under the Act.
- METArticle 4 AI literacyARK is an AI-literacy tool by design.
- METTransparency, Articles 13 and 50AI-generated content is labeled; every model call is logged in the MODELS USED report.
- METHuman oversightGuest-first, human verifies output, no autonomous action on user systems.
- METNo prohibited practicesNo manipulation, scoring of persons, or biometric use.
- PARTIALTechnical documentationBeing assembled from existing controls.
- PARTIALAccess control and least privilegeRLS owner-only by default, model keys sealed server-side.
- METEncryption in transit and at restTLS in transit, encrypted at rest via the managed backend.
- PARTIALAudit loggingai_call_log and events tables; coverage expanding.
- PARTIALChange managementFull commit and edit history.
- PARTIALVendor managementSubprocessors disclosed.
- PLANNEDSecurity policiesFormal policy set to be written.
- PLANNEDContinuous monitoring and incident responseMonitoring tooling and IR plan to be adopted (e.g. a compliance automation platform).
- PLANNEDAI management system policyTo be established.
- PARTIALAI system inventory and risk classificationModel gateway and call log provide the inventory basis.
- PARTIALData governance for AIIntegrity rules and no-fabrication guards enforced in prompts; provider config controls where data goes.
- METModel and provider governanceCapability-based gateway, per-org provider chains, BYO keys including local endpoints, full call log.
- METTransparency to usersAI-generated content labeled.
- METHuman oversightHuman in the loop throughout.
- PLANNEDAI impact assessmentTo be conducted.
- PARTIALContinuous evaluationRep scoring and pattern verification provide evaluation signals.
Status reflects current alignment. It is not a certification claim.
One-tap export of every record tied to your account, as JSON, from the app settings panel.
Delete your account and its data at any time. Deletion is honoured within 30 days.
Report a vulnerability: security@shift.studio. Response within 48 hours.