TRUST · SECURITY · COMPLIANCE

Trust, plainly stated.

The controls that exist today, the standards we align to, and the ones we are still preparing for. No certification claim we do not hold.

HOW YOUR DATA IS PROTECTED
Tenant isolation by default.

Row-level security on every table. Cross-tenant reads go through security-definer functions, never loosened policies.

Model keys never leave the server.

AI provider keys live in a sealed table with no client policies. The client sees a label and last four characters, nothing else.

Encrypted in transit and at rest.

TLS for every request. Data at rest is encrypted by the managed backend.

AI runs server-side. Bring your own.

Every AI call is server-side and logged. Organizations can plug their own providers, including on-prem or local endpoints.

STANDARDS POSTURE
GDPR
ALIGNED
93% · MET 6 · PARTIAL 1 · PLANNED 0
European data protection law for personal data.
  • MET
    Privacy notice and lawful basis
    Privacy policy published at /legal/privacy.
  • MET
    Data Processing Agreement
    DPA available at /legal/dpa.
  • MET
    Subprocessors disclosed
    Subprocessors list at /legal/subprocessors.
  • MET
    Data subject export
    One-tap GDPR data export in the app.
  • MET
    Right to erasure
    Account and data deletion supported.
  • MET
    Tenant isolation and data minimization
    Row-level security on every table, owner or team-member scope only.
  • PARTIAL
    Documented breach response
    Process being formalized.
EU AI Act
ALIGNED
92% · MET 5 · PARTIAL 1 · PLANNED 0
European regulation on AI systems.
  • MET
    Risk classification
    Limited-risk system. Not a high-risk use under the Act.
  • MET
    Article 4 AI literacy
    ARK is an AI-literacy tool by design.
  • MET
    Transparency, Articles 13 and 50
    AI-generated content is labeled; every model call is logged in the MODELS USED report.
  • MET
    Human oversight
    Guest-first, human verifies output, no autonomous action on user systems.
  • MET
    No prohibited practices
    No manipulation, scoring of persons, or biometric use.
  • PARTIAL
    Technical documentation
    Being assembled from existing controls.
SOC 2
IN PREPARATION
43% · MET 1 · PARTIAL 4 · PLANNED 2
Trust Services Criteria for service organizations.
  • PARTIAL
    Access control and least privilege
    RLS owner-only by default, model keys sealed server-side.
  • MET
    Encryption in transit and at rest
    TLS in transit, encrypted at rest via the managed backend.
  • PARTIAL
    Audit logging
    ai_call_log and events tables; coverage expanding.
  • PARTIAL
    Change management
    Full commit and edit history.
  • PARTIAL
    Vendor management
    Subprocessors disclosed.
  • PLANNED
    Security policies
    Formal policy set to be written.
  • PLANNED
    Continuous monitoring and incident response
    Monitoring tooling and IR plan to be adopted (e.g. a compliance automation platform).
ISO 42001
PLANNED
56% · MET 3 · PARTIAL 3 · PLANNED 2
AI management system standard.
  • PLANNED
    AI management system policy
    To be established.
  • PARTIAL
    AI system inventory and risk classification
    Model gateway and call log provide the inventory basis.
  • PARTIAL
    Data governance for AI
    Integrity rules and no-fabrication guards enforced in prompts; provider config controls where data goes.
  • MET
    Model and provider governance
    Capability-based gateway, per-org provider chains, BYO keys including local endpoints, full call log.
  • MET
    Transparency to users
    AI-generated content labeled.
  • MET
    Human oversight
    Human in the loop throughout.
  • PLANNED
    AI impact assessment
    To be conducted.
  • PARTIAL
    Continuous evaluation
    Rep scoring and pattern verification provide evaluation signals.

Status reflects current alignment. It is not a certification claim.

THE TRUST PACK
YOUR DATA RIGHTS
EXPORT

One-tap export of every record tied to your account, as JSON, from the app settings panel.

DELETION

Delete your account and its data at any time. Deletion is honoured within 30 days.

Report a vulnerability: security@shift.studio. Response within 48 hours.